Skip to content

Open nowPosted 67 days ago

Security Operations Specialist

GCash143 open roles

Where
NCR - WGC
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSecurity Operations SpecialistGCash · NCR - WGC
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on GCash's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.3% of postings close within 7 days. Measured by our own scanner across the market. GCash postings stay open a median of 6 days.

Share of postings closed within
  1. 1.9%1 day
  2. 4.0%3 days
  3. 8.3%7 days
  4. 15.3%14 days
  5. 34.2%30 days
This job: posted 67 days ago

GCash median: 6 days open

The posting

Do you want to take the first step in making Filipinos’ lives better everyday? Here in GCash we want to stay at the forefront of the FinTech industry by creating innovative, meaningful, and convenient financial solutions for the nation! G ka ba? Join the G Nation today!

Key Responsibilities

1. Alert Monitoring and Triage

  • Monitor and respond to security alerts from SIEM or from various security tools or instrumentation such as endpoint security, secure email gateway, firewalls, IDS, DLP, etc.
  • Acknowledge new alerts promptly and begin meaningful triage based on severity, context, and available evidence.
  • Review alerts using established SOC triage playbooks and standard case disposition guidance.
  • Determine whether activity is true positive, benign positive, false positive, or requires further investigation.

2. Investigation and Analysis

  • Perform advanced incident response activities including discovery, threat analysis and correlation, response, remediation, and containment, at times involving network and endpoint forensics.
  • Apply investigative logic using frameworks such as the Cyber Kill Chain and MITRE ATT&CK to understand attacker behavior, scope incidents, and assess likely impact.
  • Validate whether reported activity is benign, expected, suspicious, or malicious before closure, escalation, or containment recommendation.
  • Correlate evidence from SIEM, EDR, cloud, email, and network sources where applicable.

3. Case Documentation and Escalation

  • Document investigations clearly and completely so that work can be reviewed, continued, or audited without repeating prior analysis.
  • Produce escalation notes that include alert summary, affected assets, investigative steps performed, evidence gathered, and analyst hypothesis.
  • Escalate cases when deeper response, stakeholder coordination, or containment approval is required.
  • Ensure escalations are actionable and complete enough for immediate continuation by senior analysts, leads, or partner teams.
  • Contribute to overall SOC processes, documentation, metrics, and reporting.

4. Containment and Response Support

  • Support containment and response actions by validating risk, recommending next steps, and coordinating with leads, system owners, and supporting teams as needed.
  • Participate in the investigation lifecycle from alert handling through validation, communication, and closure.
  • Contribute to timely incident scoping and prioritization to improve mean time to detect, respond, and contain.
  • Support or drive the remediation or closure of control gaps, risks, and findings from audits and certification activities.

5. Detection and Operational Improvement

  • Identify recurring false positives, noise patterns, and weak detections, then recommend tuning opportunities to improve SOC efficiency.
  • Contribute to SOC initiatives that enhance analyst productivity, detection quality, and operational maturity.
  • Help translate observed attack patterns and investigative learnings into improved rules, playbooks, dashboards, and use cases.

Core Deliverables

  • Accurate and timely handling of security alerts and cases.
  • Well-documented investigations and escalation artifacts.
  • High-quality incident analysis aligned to SOC playbooks and threat frameworks.
  • Recommendations for detection tuning, false-positive reduction, and process improvement.

Minimum Qualifications

  • Experience in security monitoring, incident response, or security operations center work.
  • Working knowledge of SIEM, EDR, email security, cloud security, and related security monitoring tools.
  • Ability to analyze logs, investigate suspicious activity, and form evidence-based conclusions.
  • Familiarity with MITRE ATT&CK, attacker behavior mapping, or comparable investigative frameworks.
  • Strong technical documentation and case-writing skills.
  • Ability to balance speed, accuracy, and sound judgment in a high-volume operational environment.

Preferred Qualifications

  • At least 2 years of SOC or IR experience.
  • Bachelor’s degree in computer science, IT, or directly related field, or equivalent work experience.
  • Strong understanding of SIEM platforms and hands-on experience with security technologies such as SIEM, IDS, DLP, vulnerability scanning, firewalls, endpoint security, or email security systems.
  • Exposure to threat hunting, detection engineering feedback loops, or SOAR-oriented process design.
  • Experience coordinating with application owners, infrastructure teams, or supporting functions during incident review and response.
  • Willingness to cover 24/7 working hours following a sustainable rotation schedule and at times cover on-call duties.
  • Practical experience in reverse engineering, malware forensics, or penetration testing, particularly within finance and fintech operations, is highly advantageous.
  • Advanced security certifications (e.g., CC, GCIH, CDSA, CompTia Sec+, SANS/GIAC, CEH) are highly advantageous.

Competencies

  • Investigative reasoning
  • Threat analysis and contextual decision-making
  • Technical writing and case documentation
  • Tool fluency across SOC platforms
  • Pattern recognition and false-positive identification
  • Stakeholder coordination during investigations
  • Technical security project support and collaboration
  • Cross-functional team collaboration
  • Continuous improvement mindset

Success Measures

A successful Security Operations Specialist consistently demonstrates strong alert handling coverage, high triage quality, timely acknowledgement of alerts, complete escalation documentation, active identification of false positives, delivery of SOC improvement initiatives, and continuous development of technical capability.

What We Offer

Opportunity for career growth and development in the #1 FinTech company in the country Working with a dynamic and highly collaborative team who want to change the game A company that values their people with highly competitive and flexible compensation and benefits package

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against GCash's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on GCash's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    GCash's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.