{"id":1145060,"url":"https://alion.io/job/gcash-security-operations-specialist-2","title":"Security Operations Specialist","company":{"id":8370,"name":"GCash","domain":"gcash.com","url":"https://alion.io/company/gcash","size_band":null,"is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Workday","truth_index":{"grade":"B","score":75,"open_postings":113,"ghost_share":0.416,"stale_share":0,"repost_share":0,"time_to_fill_p50_days":59,"computed_at":"2026-09-25T05:45:01Z"}},"role":"Security","role_family":"Security","seniority":"junior","employment_type":"full_time","work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Taguig, Philippines"],"countries":["PH"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":12500,"max_usd":30000,"period":"year","method":"global_role_cell_scaled_by_country","sample_n":227},"experience_years_min":2,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Cyber Kill Chain","optional":false},{"name":"DLP","optional":false},{"name":"MITRE ATT&CK","optional":false},{"name":"SIEM","optional":false}],"status":"live","first_seen_at":"2026-08-04T00:00:00Z","employer_posted_date":"2026-08-04","last_verified_at":"2026-09-25T11:41:51Z","board_verified":true,"closed_at":null,"days_open":53,"trust":{"level":"ok","repost_count":0,"flags":["company_stale"],"days_open":52},"description":"Do you want to take the first step in making Filipinos’ lives better everyday? Here in GCash we want to stay at the forefront of the FinTech industry by creating innovative, meaningful, and convenient financial solutions for the nation! G ka ba? Join the G Nation today!\nKey Responsibilities\n1. Alert Monitoring and Triage\nMonitor and respond to security alerts from SIEM or from various security tools or instrumentation such as endpoint security, secure email gateway, firewalls, IDS, DLP, etc.\n\nAcknowledge new alerts promptly and begin meaningful triage based on severity, context, and available evidence.\n\nReview alerts using established SOC triage playbooks and standard case disposition guidance.\n\nDetermine whether activity is true positive, benign positive, false positive, or requires further investigation.\n\n2. Investigation and Analysis\nPerform advanced incident response activities including discovery, threat analysis and correlation, response, remediation, and containment, at times involving network and endpoint forensics.\n\nApply investigative logic using frameworks such as the Cyber Kill Chain and MITRE ATT&CK to understand attacker behavior, scope incidents, and assess likely impact.\n\nValidate whether reported activity is benign, expected, suspicious, or malicious before closure, escalation, or containment recommendation.\n\nCorrelate evidence from SIEM, EDR, cloud, email, and network sources where applicable.\n\n3. Case Documentation and Escalation\nDocument investigations clearly and completely so that work can be reviewed, continued, or audited without repeating prior analysis.\n\nProduce escalation notes that include alert summary, affected assets, investigative steps performed, evidence gathered, and analyst hypothesis.\n\nEscalate cases when deeper response, stakeholder coordination, or containment approval is required.\n\nEnsure escalations are actionable and complete enough for immediate continuation by senior analysts, leads, or partner teams.\n\nContribute to overall SOC processes, documentation, metrics, and reporting.\n\n4. Containment and Response Support\nSupport containment and response actions by validating risk, recommending next steps, and coordinating with leads, system owners, and supporting teams as needed.\n\nParticipate in the investigation lifecycle from alert handling through validation, communication, and closure.\n\nContribute to timely incident scoping and prioritization to improve mean time to detect, respond, and contain.\n\nSupport or drive the remediation or closure of control gaps, risks, and findings from audits and certification activities.\n\n5. Detection and Operational Improvement\nIdentify recurring false positives, noise patterns, and weak detections, then recommend tuning opportunities to improve SOC efficiency.\n\nContribute to SOC initiatives that enhance analyst productivity, detection quality, and operational maturity.\n\nHelp translate observed attack patterns and investigative learnings into improved rules, playbooks, dashboards, and use cases.\n\nCore Deliverables\nAccurate and timely handling of security alerts and cases.\n\nWell-documented investigations and escalation artifacts.\n\nHigh-quality incident analysis aligned to SOC playbooks and threat frameworks.\n\nRecommendations for detection tuning, false-positive reduction, and process improvement.\n\nMinimum Qualifications\nExperience in security monitoring, incident response, or security operations center work.\n\nWorking knowledge of SIEM, EDR, email security, cloud security, and related security monitoring tools.\n\nAbility to analyze logs, investigate suspicious activity, and form evidence-based conclusions.\n\nFamiliarity with MITRE ATT&CK, attacker behavior mapping, or comparable investigative frameworks.\n\nStrong technical documentation and case-writing skills.\n\nAbility to balance speed, accuracy, and sound judgment in a high-volume operational environment.\n\nPreferred Qualifications\nAt least 2 years of SOC or IR experience.\n\nBachelor’s degree in computer science, IT, or directly related field, or equivalent work experience.\n\nStrong understanding of SIEM platforms and hands-on experience with security technologies such as SIEM, IDS, DLP, vulnerability scanning, firewalls, endpoint security, or email security systems.\n\nExposure to threat hunting, detection engineering feedback loops, or SOAR-oriented process design.\n\nExperience coordinating with application owners, infrastructure teams, or supporting functions during incident review and response.\n\nWillingness to cover 24/7 working hours following a sustainable rotation schedule and at times cover on-call duties.\n\nPractical experience in reverse engineering, malware forensics, or penetration testing, particularly within finance and fintech operations, is highly advantageous.\n\nAdvanced security certifications (e.g., CC, GCIH, CDSA, CompTia Sec+, SANS/GIAC, CEH) are highly advantageous.\n\nCompetencies\nInvestigative reasoning\n\nThreat analysis and contextual decision-making\n\nTechnical writing and case documentation\n\nTool fluency across SOC platforms\n\nPattern recognition and false-positive identification\n\nStakeholder coordination during investigations\n\nTechnical security project support and collaboration\n\nCross-functional team collaboration\n\nContinuous improvement mindset\n\nSuccess Measures\nA successful Security Operations Specialist consistently demonstrates strong alert handling coverage, high triage quality, timely acknowledgement of alerts, complete escalation documentation, active identification of false positives, delivery of SOC improvement initiatives, and continuous development of technical capability.\nWhat We Offer\nOpportunity for career growth and development in the #1 FinTech company in the country Working with a dynamic and highly collaborative team who want to change the game A company that values their people with highly competitive and flexible compensation and benefits package","description_format":"text","description_chars":5909,"description_truncated":false,"requirements":{"experience_years_min":2,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Payment Processing & Gateways","Digital Banks & Neobanks"],"lifecycle":[{"event":"open","at":"2026-09-23T14:35:07Z"}],"liveness":{"score":34,"band":"fade","label":"Fading","p_open":1,"p_active":0.568,"p_room":0.6,"age_days":52,"expected_fill_days":59,"reasons":["conf:11","velocity","win:late","crowd:junior,brand"],"computed_at":"2026-09-25T05:45:01Z"},"pay":null,"html_url":"https://alion.io/job/gcash-security-operations-specialist-2","json_url":"https://alion.io/job/gcash-security-operations-specialist-2.json","meta":{"generated_at":"2026-09-26T02:43:46Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":2881,"day_limit":5000,"remaining_today":2119,"minute_limit":60,"resets_at":"2026-09-27T00:00:00Z"}}}