Skip to content

Open nowPosted 74 days ago

IT Security Analyst

Workable (global search)108,016 open roles

Where
Cebu City, Cebu, Philippines
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowIT Security AnalystWorkable (global search) · Cebu City, Cebu, Philippines
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Workable (global search)'s own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.9% of postings close within 7 days. Measured by our own scanner across the market. Workable (global search) postings stay open a median of 7 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 7.9%7 days
  4. 14.9%14 days
  5. 34.0%30 days
This job: posted 74 days ago

Workable (global search) median: 7 days open

The posting

The Entry-Level IT Security Analyst provides first-line review and analysis of alerts generated by Wazuh, Bitdefender, and other approved security or IT management tools. The analyst validates alert context, reviews relevant logs, inspects affected computers or devices, gathers evidence, follows approved response procedures, and records findings in the designated ticketing or incident-management system.

This role works under the direction of the IT Security Manager or assigned senior security resource. The analyst is expected to use sound basic IT and security knowledge, remain within approved access and response boundaries, escalate uncertainty promptly, protect confidential information, and avoid making unsupported conclusions or high-risk production changes without authorization.

Requirements

  • Alert Queue Monitoring: Review assigned security alerts and notifications consistently, acknowledge them promptly, and prevent unresolved events from aging without ownership.
  • Initial Incident Analysis: Gather relevant facts from Wazuh, Bitdefender, operating-system logs, ticket history, asset records, and approved supporting tools before forming an assessment.
  • Affected Equipment Inspection: Perform structured remote or physical inspection of affected endpoints and related equipment using approved checklists, access methods, and safety precautions.
  • Evidence Collection and Preservation: Capture sufficient evidence to support escalation, investigation, remediation, audit, and possible root-cause review while protecting integrity and confidentiality.
  • Incident Classification and Escalation: Apply the approved severity matrix and escalate suspected malware, unauthorized access, data exposure, policy violations, repeated detections, or uncertain findings to the designated incident lead.
  • Authorized Containment Support: Carry out only approved containment actions and immediately report any business interruption, tool failure, unexpected behavior, or unsuccessful response action.
  • Remediation Verification: Confirm that scans, updates, quarantine actions, policy corrections, patches, credential actions, or other assigned remediation steps were completed and produced the expected result.
  • Tool Coverage and Health Review: Identify inactive agents, outdated components, missed check-ins, policy mismatches, logging gaps, duplicate assets, and other conditions that weaken security visibility or protection.
  • Ticketing and Reporting: Maintain accurate, factual, and timely incident records; avoid speculation and clearly distinguish confirmed facts, working assessments, pending validation, and required decisions.
  • Policy, Privacy, and Access Compliance: Use assigned privileges only for authorized work, follow least-privilege principles, protect credentials and confidential information, and comply with evidence-retention and acceptable-use requirements.
  • Process Improvement Support: Identify repeat alerts, confusing runbook steps, missing data, common false positives, and training needs, then submit improvement recommendations to the security team.

Qualifications:

  • Associate's or bachelor's degree in Information Technology, Cybersecurity, Computer Science, Information Systems, or a related discipline, or equivalent technical education, laboratory training, certification study, internship, or practical experience.
  • Zero to two years of experience in IT support, desktop support, system administration, networking, NOC, SOC, managed services, cybersecurity operations, or a related technical environment; qualified entry-level candidates are encouraged.
  • Basic IT knowledge is required, including Windows endpoints, computer hardware, applications, user accounts, permissions, file systems, services, remote support, software installation, patching, IP addressing, DNS, and common network concepts.
  • Basic security knowledge is required, including malware, phishing, endpoint protection, event logs, indicators of compromise, vulnerabilities, patching, least privilege, account security, data protection, and incident-response fundamentals.
  • Ability to read alerts and logs, follow written procedures, perform careful equipment inspection, document technical findings clearly, and escalate when evidence is incomplete or risk is uncertain.
  • Strong attention to detail, professional judgment, confidentiality, integrity, and willingness to work with sensitive company, employee, client, or system information under approved access controls.
  • Ability to communicate clearly with security, help desk, infrastructure, network, managed services, operations, and non-technical users while remaining factual, respectful, and calm during incidents.

Preferred Certifications and Experience

  • Exposure to Wazuh, Bitdefender GravityZone, or comparable SIEM, XDR, EDR, antivirus, endpoint-management, vulnerability, or ticketing tools.
  • CompTIA A+, Network+, Security+, Microsoft, Linux, Cisco, or comparable entry-level technical training or certification.
  • Basic experience with PowerShell, Windows command-line tools, Linux commands, event logs, browser troubleshooting, packet or connection information, hashes, and common security research methods.
  • Experience or internship in a BPO, MSP, NOC, SOC, service desk, contact center, multi-site company, or remote-work support environment.

Core Competencies

  • Attention to Detail: Notices inconsistencies in alerts, logs, timestamps, users, assets, processes, and documentation before reaching conclusions.
  • Analytical Thinking: Connects related facts, tests reasonable explanations, and distinguishes evidence from assumptions.
  • Procedure Discipline: Follows approved playbooks, access controls, checklists, and escalation paths consistently.
  • Escalation Judgment: Recognizes uncertainty, potential impact, and personal authority limits, then seeks help early.
  • Communication: Writes clear incident notes and provides concise factual updates appropriate to the audience.
  • Learning Agility: Builds practical skill through training, supervised investigations, review feedback, and repeated use of tools.
  • Integrity and Teamwork: Protects confidentiality, reports mistakes promptly, supports shared ownership, and treats users and colleagues professionally.
From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Workable (global search)'s own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Workable (global search)'s form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Workable (global search)'s answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.