IT Security Analyst
On-siteCebu City, Central Visayas, Philippines
Job Summary
Review assigned security alerts from Wazuh, Bitdefender, and other approved tools; validate context, inspect affected endpoints, and gather evidence using structured checklists. Perform initial incident analysis by reviewing logs, ticket history, and asset records before applying the severity matrix for classification. Execute only approved containment actions and report business interruptions or tool failures immediately. Confirm remediation steps such as patches, quarantines, and policy corrections to ensure expected results. Maintain accurate, factual records in the incident-management system, distinguishing confirmed facts from assessments. Identify inactive agents, logging gaps, or policy mismatches to support tool coverage reviews. Submit improvement recommendations regarding repeat alerts or confusing runbooks to the security team. Work under the direction of the IT Security Manager while adhering to least-privilege principles and confidentiality requirements.
Required Qualifications
- Associate's or bachelor's degree in Information Technology, Cybersecurity, Computer Science, Information Systems, or a related discipline, or equivalent technical education, laboratory training, certification study, internship, or practical experience.
- Zero to two years of experience in IT support, desktop support, system administration, networking, NOC, SOC, managed services, cybersecurity operations, or a related technical environment; qualified entry-level candidates are encouraged.
- Basic IT knowledge is required, including Windows endpoints, computer hardware, applications, user accounts, permissions, file systems, services, remote support, software installation, patching, IP addressing, DNS, and common network concepts.
- Basic security knowledge is required, including malware, phishing, endpoint protection, event logs, indicators of compromise, vulnerabilities, patching, least privilege, account security, data protection, and incident-response fundamentals.
- Ability to read alerts and logs, follow written procedures, perform careful equipment inspection, document technical findings clearly, and escalate when evidence is incomplete or risk is uncertain.
- Strong attention to detail, professional judgment, confidentiality, integrity, and willingness to work with sensitive company, employee, client, or system information under approved access controls.
- Ability to communicate clearly with security, help desk, infrastructure, network, managed services, operations, and non-technical users while remaining factual, respectful, and calm during incidents.
Desired Qualifications
- Exposure to Wazuh, Bitdefender GravityZone, or comparable SIEM, XDR, EDR, antivirus, endpoint-management, vulnerability, or ticketing tools.
- CompTIA A+, Network+, Security+, Microsoft, Linux, Cisco, or comparable entry-level technical training or certification.
- Basic experience with PowerShell, Windows command-line tools, Linux commands, event logs, browser troubleshooting, packet or connection information, hashes, and common security research methods.
- Experience or internship in a BPO, MSP, NOC, SOC, service desk, contact center, multi-site company, or remote-work support environment.
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.