Your White Label Enterprise Support Company.
SOC Analyst, Level 1
Location
Philippines
Posted
2 days ago
Salary
0
Seniority
Junior
Job Description
SOC Analyst, Level 1
CallTek
• Monitor security events and alerts in SIEM and defensive tools; perform initial triage and classification (benign / false positive / suspicious / incident). • Collect and review basic evidence: endpoint telemetry, Windows/Linux logs, firewall/IDS, DNS/proxy; perform initial correlation (host/user/IP/IOC/process). • Execute runbooks/playbooks (e.g., password reset request, IOC block request, host isolation request) when authorized and aligned with procedures. • Create and maintain high-quality tickets with a clear narrative: what happened, supporting evidence, potential impact, actions taken, recommended next steps. • Escalate to L2/L3/IR when there is evidence of compromise, material risk, lateral movement, or uncertainty that requires deeper investigation. • Deliver structured shift handovers (case status, findings, hypotheses, next steps, blockers). • Meet operational SLAs and documentation of quality standards.
Job Requirements
- 0–2 years in SOC/NOC/IT Security operations or equivalent hands-on experience demonstrated via labs/casework.
- Solid fundamentals in networking: TCP/IP, DNS, HTTP/S, VPN, NAT.
- Basic working knowledge of Windows and Linux (processes, authentication, logging concepts).
- Ability to interpret log fields (source/destination, user, process, hash, URL, action, result).
- Strong spoken and written English (minimum B2) — must be able to join technical calls and write clear tickets and summaries in English.
- Strong attention to detail, structured thinking, prioritization, and ability to work under pressure and repetitive workflows without quality loss.
- Experience with SIEM/EDR/IDS tools (e.g., Wazuh, Splunk, Sentinel, QRadar; Defender/CrowdStrike; Suricata/Snort). (Nice to have )
- Basic query skills (KQL/SPL/Lucene/DQL) and familiarity with MITRE ATT&CK concepts. (Nice to have )
- Entry-level certifications (e.g., Security+, BTL1, CySA+) or equivalent proof of competence. (Nice to have )
Related Guides
Related Categories
Related Job Pages
More Security Operations Jobs
• Administer and configure AI tools and platforms • Configure and review security settings for AI tools • Own the platform layer for AI context at scale • Monitor AI tool health and support cloud operations • Own AI transformation analytics and reporting • Partner with Engineering and IT for cloud resource deployment • Develop and maintain AI governance documentation.
OT Security Operation Engineer
SwisscomTop quality I Ground-breaking innovations I Connected to people and the environment
Role Description As an OT Security Operation Engineer with a focus on Claroty or Nozomi, you will be responsible for setting up, operating and further developing our OT security services. Your area of responsibility includes: - Monitoring, analyzing and securing operational technology (OT) systems and industrial networks. - Implementing and operating OT security solutions to detect and defend against threats. - Analyzing events and supporting the continuous improvement of the OT security architecture. - Identifying OT cyber threats and vulnerabilities and investigating their causes. - Co-designing and setting up the new OT Security service. - Processing customer inquiries about the security services. - Supporting exciting service portfolios. - Change management (planning and implementation). - Work location in Zurich, Bern or Geneva. Qualifications - Practical experience from OT. - Good German (at least B1 level) and English (at least B1 level); French is an advantage. - Sound knowledge of the operation of Claroty or Nozomi. - Know-how in routing/switching. - Experience with agile working methods such as DevOps or Scrum. - Advantageous knowledge of firewall, proxy, cloud security, VPN. - Willing to work on-call sporadically. Benefits - Opportunity to work in one of our offices in Switzerland or in your home office. - Contact with agile working methods and the latest technologies. - Flexible working hours to meet your personal needs. - A pleasant working environment. - Financial benefits. - Exciting opportunities for professional development. Contact Person Sören Bergmann Talent Acquisition Manager +41 (58) 2230451 Your Homebase Swisscom (Schweiz) AG Binzring 17, 8045 Zürich
Who we are Samsara (NYSE: IOT) is the pioneer of the Connected Operations™ Cloud, which is a platform that enables organizations that depend on physical operations to harness Internet of Things (IoT) data to develop actionable insights and improve their operations. At Samsara, we are helping improve the safety, efficiency and sustainability of the physical operations that power our global economy. Representing more than 40% of global GDP, these industries are the infrastructure of our planet, including agriculture, construction, field services, transportation, and manufacturing — and we are excited to help digitally transform their operations at scale. Working at Samsara means you’ll help define the future of physical operations and be on a team that’s shaping an exciting array of product solutions, including Video-Based Safety, Vehicle Telematics, Apps and Driver Workflows, and Equipment Monitoring. As part of a recently public company, you’ll have the autonomy and support to make an impact as we build for the long term. About the role: As a member of our Security Operations Team, you will collaborate with a global team of engineers to monitor and respond to security events, lead security incidents as Incident Commander, and lead digital forensic investigations in support of Employee Relations, Legal, Compliance, or Information Security cases. Although you will be focused on security incident response, you will also have the opportunity to create and maintain runbooks, and automated workflows, and assist in process refinement and implementation. You will collaborate with a diverse team of analysts, engineers, and key stakeholders on security initiatives across the company. Above all, your focus is bringing Security expertise to the table in a collaborative, humble, and practical manner. This is a remote position open to candidates residing in Canada. You should apply if: - You want to impact the industries that run our world: Your efforts will result in real-world impact—helping to keep the lights on, get food into grocery stores, reduce emissions, and most importantly, ensure workers return home safely. - You are the architect of your own career: If you put in the work, this role won’t be your last at Samsara. We set up our employees for success and have built a culture that encourages rapid career development, and countless opportunities to experiment and master your craft in a hyper-growth environment. - You’re energized by our opportunity: The vision we have to digitize large sectors of the global economy requires your full focus and best efforts to bring forth creative, ambitious ideas for our customers. - You want to be with the best: At Samsara, we win together, celebrate together and support each other. You will be surrounded by a high-caliber team that will encourage you to do your best. In this role, you will: - Monitor security events and provide technical analysis on alerts - Lead information security incidents and employee investigations by developing the incident response strategy, lead the execution through incident closure, while providing incident updates to key stakeholders throughout the incident - Deliver security guidance clearly and concisely for incident response and insider threat initiatives - Coordinate the building of services, capabilities, integrations, and implementations of technologies to support security operations, incident response, and insider threat - Champion, role model, and embed Samsara’s cultural principles (Focus on Customer Success, Build for the Long Term, Adopt a Growth Mindset, Be Inclusive, Win as a Team) as we scale globally and across new offices Minimum requirements for the role: - 5+ years of experience in Security Incident Response - Ability to communicate investigative findings and strategies to technical staff, executive leadership, and legal - Ability to build scripts or tools to support Samsara’s investigation processes, with proficiency in Python - Mentor and train security operation engineers on data collection, analysis, and reporting technical analysis - Practical experience acting as a lead during security incident response, including monitoring and triaging alerts, and coordinating across teams - Understanding of analysis and forensics techniques on macOS, Windows, and Linux - Experience utilizing SIEM tools to perform log reviews - Experience in cloud architecture and security (AWS, GCP) and cloud-based services - Must reside in the Pacific Time Zone, Mountain Time Zone or Central Time Zone of the United States An ideal candidate also has: - 3+ years of experience working on insider threat initiatives or employee investigations - Bachelor’s or Master’s degree in Computer Science, Information Security, or a related field - or relevant industry experience - GIAC Certified Incident Handler (GCIH) Certification - Familiarity with common security frameworks and standards, including NIST Cybersecurity Framework, ISO 27001, FedRAMP The range of annual base salary for full-time employees for this position is below. Please note that base pay offered may vary depending on factors including your city of residence, job-related knowledge, skills, and experience. This role is also eligible for an initial RSU grant with no vesting cliff, and ongoing refresh opportunities tied to performance, subject to plan terms and conditions. Learn more about our total rewards and benefits below. Annual Base Salary $132,600—$171,600 CAD Total Rewards At Samsara, we build for the people who keep the global economy moving. We want owners, not passengers, which is why our rewards are designed to fuel high-impact builders. Our compensation program delivers above-market total compensation through a combination of base salary, performance-based bonus/variable pay, and equity (for eligible roles) in a high-growth public company. We meaningfully differentiate pay for our top performers, who have the opportunity to earn above-market compensation that can outpace the broader market over time. Beyond compensation, we provide the foundations that enable long-term success: a flexible, employee-led remote model, a professional development stipend, comprehensive health and parental leave plans, and more. If you’re ready to build for the long term and own the outcome, your journey starts here. Flexible Working At Samsara, we embrace a flexible working model that caters to the diverse needs of our teams. Our offices are open for those who prefer to work in-person and we also support remote work where it aligns with our operational requirements. For certain positions, being close to one of our offices or within a specific geographic area is important to facilitate collaboration, access to resources, or alignment with our service regions. In these cases, the job description will clearly indicate any working location requirements. Our goal is to ensure that all members of our team can contribute effectively, whether they are working on-site, in a hybrid model, or fully remotely. All offers of employment are contingent upon an individual’s ability to secure and maintain the legal right to work at the company and in the specified work location, if applicable. Belonging at Samsara At Samsara, we welcome everyone regardless of their background. All qualified applicants will receive consideration for employment without regard to race, color, religion, national origin, sex, gender, gender identity, sexual orientation, protected veteran status, disability, age, and other characteristics protected by law. We depend on the unique approaches of our team members to help us solve complex problems and want to ensure that Samsara is a place where people from all backgrounds can make an impact. Accommodations Samsara is an inclusive work environment, and we are committed to ensuring equal opportunity in employment for qualified persons with disabilities. Please email accessibleinterviewing@samsara.com or click here if you require any reasonable accommodations throughout the recruiting process. Our Commitment to Authenticity We use Tofu, a fraud detection tool, to validate the authenticity of applications and protect against identity fraud. This ensures we are connecting with real people and allows us to prioritize genuine candidates. Please see Samsara’s Candidate Privacy Notice for more information. Fraudulent Employment Offers Samsara is aware of scams involving fake job interviews and offers. Please know we do not charge fees to applicants at any stage of the hiring process. Official communication about your application will only come from emails ending in @samsara.com, @us-greenhouse-mail.io or @mail3.guide.co. For more information regarding fraudulent employment offers, please visit our blog post here.
• Administrar y operar la plataforma de seguridad de endpoints (servidores y workstations), asegurando que todos los dispositivos de la compañía cuenten con protección activa, configuraciones correctas y visibilidad centralizada. • Gestionar la solución de antivirus y EDR (Endpoint Detection & Response), incluyendo la respuesta ante alertas, la investigación de incidentes y la mejora continua de las reglas de detección. • Construir y mantener APIs internas que permiten a otros equipos de Cybersecurity y áreas de negocio consumir capacidades de seguridad de forma programática, sin depender de procesos manuales. • Automatizar tareas operativas repetitivas del equipo de Cyber: onboarding y offboarding de usuarios, rotación de credenciales, respuesta automática ante alertas, generación de reportes de cumplimiento, entre otras. • Integrar las herramientas de seguridad con los sistemas internos de la compañía (ticketing, comunicaciones, pipelines de deployment) para crear flujos de trabajo que reduzcan la intervención manual. • Detectar y responder a incidentes de seguridad en endpoints, coordinando la contención y el análisis forense cuando sea necesario. • Mantener visibilidad del inventario de activos tecnológicos de la compañía y el estado de seguridad de cada uno. • Definir y hacer cumplir las políticas de seguridad en endpoints: encriptación de discos, control de accesos, gestión de parches y configuración de sistemas operativos.




