749,455open jobs
45,073companies
109,575added this week
Browse all
Salary
≈ $13k – $30k per year (Estimated)
Location
In office (Philippines)
Seniority
Junior · 2+ years exp
Employment
Full-Time

Confirmed on the employer's own hiring board on Sep 24, 2026. First seen by Alion on Aug 4, 2026. GCash scores B on the Alion truth index.

Overview
Company
Impact
Profile match
GCash is a mobile wallet and financial services provider based in Taguig, Philippines, and was launched in 2004. The platform offers a comprehensive suite of digital services including peer-to-peer money transfers, bill payments, mobile airtime top-ups, savings accounts, insurance products, and investment tools. Operated by G-Xchange, a subsidiary of Mynt, the company serves over 94 million users and millions of merchants primarily in the Philippines while expanding its reach to international markets.

Do you want to take the first step in making Filipinos’ lives better everyday? Here in GCash we want to stay at the forefront of the FinTech industry by creating innovative, meaningful, and convenient financial solutions for the nation! G ka ba? Join the G Nation today!

Key Responsibilities

1. Alert Monitoring and Triage

  • Monitor and respond to security alerts from SIEM or from various security tools or instrumentation such as endpoint security, secure email gateway, firewalls, IDS, DLP, etc.

  • Acknowledge new alerts promptly and begin meaningful triage based on severity, context, and available evidence.

  • Review alerts using established SOC triage playbooks and standard case disposition guidance.

  • Determine whether activity is true positive, benign positive, false positive, or requires further investigation.

2. Investigation and Analysis

  • Perform advanced incident response activities including discovery, threat analysis and correlation, response, remediation, and containment, at times involving network and endpoint forensics.

  • Apply investigative logic using frameworks such as the Cyber Kill Chain and MITRE ATT&CK to understand attacker behavior, scope incidents, and assess likely impact.

  • Validate whether reported activity is benign, expected, suspicious, or malicious before closure, escalation, or containment recommendation.

  • Correlate evidence from SIEM, EDR, cloud, email, and network sources where applicable.

3. Case Documentation and Escalation

  • Document investigations clearly and completely so that work can be reviewed, continued, or audited without repeating prior analysis.

  • Produce escalation notes that include alert summary, affected assets, investigative steps performed, evidence gathered, and analyst hypothesis.

  • Escalate cases when deeper response, stakeholder coordination, or containment approval is required.

  • Ensure escalations are actionable and complete enough for immediate continuation by senior analysts, leads, or partner teams.

  • Contribute to overall SOC processes, documentation, metrics, and reporting.

4. Containment and Response Support

  • Support containment and response actions by validating risk, recommending next steps, and coordinating with leads, system owners, and supporting teams as needed.

  • Participate in the investigation lifecycle from alert handling through validation, communication, and closure.

  • Contribute to timely incident scoping and prioritization to improve mean time to detect, respond, and contain.

  • Support or drive the remediation or closure of control gaps, risks, and findings from audits and certification activities.

5. Detection and Operational Improvement

  • Identify recurring false positives, noise patterns, and weak detections, then recommend tuning opportunities to improve SOC efficiency.

  • Contribute to SOC initiatives that enhance analyst productivity, detection quality, and operational maturity.

  • Help translate observed attack patterns and investigative learnings into improved rules, playbooks, dashboards, and use cases.

Core Deliverables

  • Accurate and timely handling of security alerts and cases.

  • Well-documented investigations and escalation artifacts.

  • High-quality incident analysis aligned to SOC playbooks and threat frameworks.

  • Recommendations for detection tuning, false-positive reduction, and process improvement.

Minimum Qualifications

  • Experience in security monitoring, incident response, or security operations center work.

  • Working knowledge of SIEM, EDR, email security, cloud security, and related security monitoring tools.

  • Ability to analyze logs, investigate suspicious activity, and form evidence-based conclusions.

  • Familiarity with MITRE ATT&CK, attacker behavior mapping, or comparable investigative frameworks.

  • Strong technical documentation and case-writing skills.

  • Ability to balance speed, accuracy, and sound judgment in a high-volume operational environment.

Preferred Qualifications

  • At least 2 years of SOC or IR experience.

  • Bachelor’s degree in computer science, IT, or directly related field, or equivalent work experience.

  • Strong understanding of SIEM platforms and hands-on experience with security technologies such as SIEM, IDS, DLP, vulnerability scanning, firewalls, endpoint security, or email security systems.

  • Exposure to threat hunting, detection engineering feedback loops, or SOAR-oriented process design.

  • Experience coordinating with application owners, infrastructure teams, or supporting functions during incident review and response.

  • Willingness to cover 24/7 working hours following a sustainable rotation schedule and at times cover on-call duties.

  • Practical experience in reverse engineering, malware forensics, or penetration testing, particularly within finance and fintech operations, is highly advantageous.

  • Advanced security certifications (e.g., CC, GCIH, CDSA, CompTia Sec+, SANS/GIAC, CEH) are highly advantageous.

Competencies

  • Investigative reasoning

  • Threat analysis and contextual decision-making

  • Technical writing and case documentation

  • Tool fluency across SOC platforms

  • Pattern recognition and false-positive identification

  • Stakeholder coordination during investigations

  • Technical security project support and collaboration

  • Cross-functional team collaboration

  • Continuous improvement mindset

Success Measures

A successful Security Operations Specialist consistently demonstrates strong alert handling coverage, high triage quality, timely acknowledgement of alerts, complete escalation documentation, active identification of false positives, delivery of SOC improvement initiatives, and continuous development of technical capability.

What We Offer

Opportunity for career growth and development in the #1 FinTech company in the country Working with a dynamic and highly collaborative team who want to change the game A company that values their people with highly competitive and flexible compensation and benefits package

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
749,455 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
Philippines
≈ $15k – $36k per year (Estimated) • Remote (Philippines) • Full-Time • 3+ years exp
Python
PowerShell
DevOps
Splunk
Cybersecurity
Crowdstrike
Wazuh
Microsoft Sentinel
ISO 27001
SentinelOne
SOC 2
GDPR
HIPAA
NIST 800-53
NIST 800-171
FedRAMP
Sumo Logic
SIEM
Apply
Security Engineer 1 day ago
≈ $15k – $35k per year (Estimated) • Hybrid • Full-Time • 4+ years exp • Associate's Degree • Makati
Python
PowerShell
Cybersecurity
NIST CSF
SIEM
Management
Microsoft Office
Apply
≈ $15k – $35k per year (Estimated) • In office • 5+ years exp • Bachelor's Degree • Mandaluyong
PowerShell
DevOps
Azure
Windows
Cybersecurity
Microsoft Defender
Microsoft Defender for Cloud
Active Directory
Analytics
Power BI
Management
Power Apps
OneDrive
Service Desk
Microsoft Office
Apply
≈ $21k – $46k per year (Estimated) • Hybrid • Full-Time • 5+ years exp • Bachelor's Degree • Manila
AI/ML
AI Agents
Mobile
Material Design
DevOps
GCP
Azure
AWS
Kubernetes
Cybersecurity
MITRE ATT&CK
STRIDE
Threat Modeling
OWASP
Management
Agile
Apply
≈ $63k – $142k per year (Estimated) • In office • Full-Time • 6+ years exp • Seoul
Apply
$90k – $158k per year • In office • Full-Time • Bachelor's Degree • Quincy
Python
SQL
DevOps
Splunk
Azure
AWS
Cybersecurity
Crowdstrike
Qualys Cloud Platform
MITRE ATT&CK
Tanium
SIEM
Analytics
Tableau
Power BI
Microsoft Excel
Apply
$120k – $179k per year • In office • TS/SCI • 1+ year exp • McLean
Cybersecurity
MITRE ATT&CK
SIEM
Apply
≈ $73k – $138k per year (Estimated) • Hybrid • Full-Time • 7+ years exp • Bachelor's Degree • Toronto
Python
Go
JavaScript
Rust
TypeScript
PowerShell
Databases
Snowflake
Databricks
Delta Lake
Apache Kafka
AI/ML
LangGraph
AutoGen
LangChain
Spark
Embeddings
AI Agents
Semantic Kernel
CrewAI
LLM
RAG
Semantic Search
LLMOps
Context Engineering
Semantic Search
LLM Guardrails
Agentic Workflows
Tool Use
Machine Learning
DevOps
GCP
Azure
CI/CD
ArgoCD
Jenkins
AWS
Kubernetes
Spinnaker
Cybersecurity
SIEM
Apply
Security Engineer 1 day ago
≈ $15k – $35k per year (Estimated) • Hybrid • Full-Time • 4+ years exp • Associate's Degree • Makati
Python
PowerShell
Cybersecurity
NIST CSF
SIEM
Management
Microsoft Office
Apply
≈ $36k – $96k per year (Estimated) • Hybrid • Full-Time • Bachelor's Degree • Lisbon
DevOps
Azure
Cybersecurity
ISO 27001
Microsoft Defender
Microsoft Entra ID
SIEM
Apply
≈ $21k – $46k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • Philippines
Python
JavaScript
DevOps
CI/CD
Cybersecurity
OWASP Top 10
OWASP
Apply
≈ $21k – $53k per year (Estimated) • In office • Full-Time • Philippines
Apply
≈ $22k – $56k per year (Estimated) • In office • Full-Time • 1+ year exp • Philippines
AI/ML
Red Teaming
Cybersecurity
MITRE ATT&CK
Apply
≈ $16k – $39k per year (Estimated) • In office • Full-Time • 3+ years exp • Philippines
AI/ML
Red Teaming
Cybersecurity
MITRE ATT&CK
Apply
Security Architect 10 months ago
≈ $24k – $57k per year (Estimated) • In office • Full-Time • 7+ years exp • Philippines
DevOps
Terraform
Kubernetes
Service Mesh
Cybersecurity
ISO 27001
MITRE ATT&CK
CIS Benchmarks
PCI DSS
NIST 800-53
Zero Trust
Least Privilege
Threat Modeling
Management
Agile
Apply
≈ $19k – $42k per year (Estimated) • In office • Full-Time • 15+ years exp • Bachelor's Degree • Philippines
Apply
In office • Full-Time • Philippines
Apply
≈ $9k – $23k per year (Estimated) • Hybrid • Full-Time • 2+ years exp • Philippines
DevOps
SLI/SLO/SLA
Management
Microsoft Office
Apply
Remote (Philippines) • Full-Time • 3+ years exp • Bachelor's Degree • Philippines
Apply
≈ $15k – $38k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Philippines
Python
MATLAB
MATLAB
Simulink
Apply
See all jobs
This is one of many
749,455 more open roles from verified company boards, updated every day.