Talent.com
Xerox
Security Operations Center (SOC) Analyst, Level 2Xerox • Mandaue City, Philippines
Security Operations Center (SOC) Analyst, Level 2

Security Operations Center (SOC) Analyst, Level 2

Xerox • Mandaue City, Philippines
30+ days ago
Job description

Purpose:

Ensure the security and integrity of organizational information systems by proactively monitoring, detecting, and investigating security threats. By maintaining a vigilant and responsive security posture, the SOC Analyst helps protect sensitive data, supports business continuity, and improves detection and response outcomes. The analyst uses AI-assisted capabilities to accelerate triage and investigations, while independently validating model outputs against authoritative telemetry and established procedures.

Scope:

As an L2 SOC Analyst you will primarily focus on deeper analysis of security alerts and incidents that require cross-source correlation, hypothesis-driven investigation, and risk-based decisioning (e.g., monitor vs contain). You will execute response actions that are pre-approved in playbooks, verify outcomes, and escalate exceptions (critical assets, high business impact, ambiguous root cause, or destructive/high-blast-radius actions) to senior SOC/Incident Response resources. You will produce investigation artifacts (timeline, evidence, and queries used) suitable for peer review and audit and contribute to continuous improvement through structured feedback to detection engineering.

Influence:

As a member of Xerox Cyber Security (XCS), the SOC Analyst actively influences the security culture through operational rigor, clear documentation, and disciplined escalation. You will share investigation insights to improve detections, reduce recurring false positives, and strengthen the organization’s overall security posture. You will also participate in security awareness and end-user engagement activities as needed to reinforce secure behaviors and reporting practices.

What You Will Do:

Incident Monitoring, Investigation, and Response:

  • Monitor and triage security alerts and events using security tools and technologies (e.g., SIEM, EDR/XDR, IAM/IdP telemetry, email security, cloud audit logs).
  • Investigate medium-to-complex alerts to determine scope, impact, and likely root cause; build defensible incident narratives grounded in evidence.
  • Perform cross-source correlation and create timelines across endpoint, identity, network, and cloud/SaaS telemetry to validate detections and identify related activity.
  • Use hypothesis-driven investigation techniques: generate competing hypotheses, design targeted tests, and update conclusions as evidence changes.
  • Make risk-based decisions aligned to runbooks (e.g., contain vs monitor); document rationale, confidence level, and next steps.

AI-Augmented Investigation and Verification (Key 90-Day Expectation):

  • Leverage AI-assisted investigation capabilities (e.g., summarization, enrichment, clustering, prioritization) to accelerate triage and investigations.
  • Perform AI-augmented investigations as a core responsibility, using AI tools to enhance hypothesis generation, evidence correlation, and incident analysis.
  • Independently validate all AI-generated outputs against authoritative telemetry and established runbooks before taking action.
  • Translate “why flagged” signals into evidence-based explanations suitable for peer review.
  • Identify and document inconsistencies, hallucinations, and gaps in AI outputs, ensuring accuracy and reliability.
  • Execute response actions that are pre-approved in playbooks and verify outcomes with clear documentation of results.
  • Escalate cases with complete context including timeline, evidence, impact assessment, actions taken, and recommended next steps.

Documentation, Communication, and Automation Safety:

  • Document investigations in the case management system, including queries used, evidence excerpts, timelines, decisions, and residual risk.
  • Provide structured feedback to detection engineering and ML stakeholders to improve alert fidelity and reduce false positives.
  • Maintain up-to-date knowledge of cybersecurity threats, attacker techniques, detection methodologies, and AI-assisted security operations practices.

Basic Qualifications:

  • Bachelor's degree in Computer Science, Information Technology, or a related field (or equivalent practical experience).
  • 2+ years of experience in a Security Operations Center, security monitoring, or incident triage/investigation role (Level 2 or equivalent).
  • Applied proficiency investigating alerts using SIEM queries/pivots and one or more of the following: EDR/XDR, IAM/IdP telemetry, cloud audit logs, email security, network telemetry.
  • Strong analytical and problem-solving skills with the ability to conduct hypothesis-driven investigations and produce defensible conclusions.
  • Strong written and verbal communication skills with the ability to collaborate effectively across teams and produce audit-ready documentation.
  • Ability to work in a fast-paced environment and manage multiple concurrent investigations.
  • Working knowledge of AI-assisted security operations concepts and limitations (e.g., false positives, bias, hallucinations) with a strong emphasis on validation and evidence-based decision making.
  • Strong discipline in handling sensitive data and using AI tools responsibly (approved platforms, data minimization, and secure practices).

Preferred Qualifications:

  • Certifications such as CompTIA Security+, CEH, GIAC (e.g., GCIH/GCIA/GMON), or similar.
  • Experience with MITRE ATT&CK mapping to structure investigations and communicate findings.
  • Experience investigating cloud environments (AWS, Azure) and interpreting cloud/SaaS telemetry.
  • Experience with scripting or query languages (e.g., Python, PowerShell, SQL) for enrichment and analysis.
  • Experience executing SOAR playbooks with human-in-the-loop validation.
  • Experience contributing to detection engineering improvements and SIEM tuning.
  • Experience using LLM/AI copilots to accelerate investigations while maintaining strict validation and secure data handling practices.

Benefits:

  • Competitive salary and benefits package.
  • Opportunities for professional growth and development.
  • Collaborative and inclusive work environment.
  • Access to advanced cybersecurity tools and technologies.

Success Criteria (First 90 Days):

  • Consistently produces complete, reviewable incident case notes including evidence, queries, timelines, and rationale.
  • Demonstrates strong capability in AI-augmented investigations with reliable validation of AI outputs against telemetry.
  • Identifies and corrects AI model errors such as hallucinations or inconsistencies.
  • Provides actionable feedback that improves detection quality and reduces false positives.
  • Executes containment actions safely and escalates complex cases with clear, well-documented context.
Create a job alert for this search

Security Operations Center (SOC) Analyst, Level 2 • Mandaue City, Philippines

Similar jobs

Project/Ops Manager ( PMP or LSS certification required)

Innodata Inc.cebu city, central visayas, ph

In this position, you’ll manage the overall performance and governance of the Statement of Work (SOW), manage the day-to-day operations in accordance with the requirements of the Service Level Agre... Show more

 • Promoted

Lead Operations Specialist

MEDVAcebu city, central visayas, ph

The Lead Operations Specialist ensures the sales and marketing teams always have clean, qualified, and campaign-ready lead lists to work from.This role owns the end-to-end process of sourcing, cura... Show more

 • Promoted

Guest Support and Operations Analyst

RivetStayscebu city, central visayas, ph

We are seeking a Guest Support & Operations Analyst to manage overnight guest communications and support key backend operations.This role combines guest relations, reservation management, and admin... Show more

 • Promoted

US Accounting and Operations Analyst | 100% Remote | Independent Contractor | Direct Hire

TeamUpcebu city, central visayas, ph

Are you an accounting professional who enjoys improving systems, solving operational challenges, and making processes more efficient? Do you thrive in fast-paced environments where curiosity, owner... Show more

 • Promoted

Network Operations Center L1 (Remote)

STAFFVIRTUALCebu City, Cebu, Philippines
Quick Apply

A technology solutions provider that helps businesses simplify and manage their communications and IT systems through a single platform.They offer fully managed services such as cloud-based phone s... Show more

Security Head | Cebu

Rockwell Land Corporationcebu, central visayas, ph

Develops and manages security programs, training, and security personnel management.Establishes and implements security regulations and procedures to prevent and/or reduce business interruptions re... Show more

 • Promoted

Information System Security Engineer

Atmailcebu city, central visayas, ph

Join Atmail and Help Shape the Future of Continuous Compliance.At Atmail, we’re looking for an Information System Security Engineer to join our Cloud Platforms team and help bridge the gap between ... Show more

 • Promoted

IT Systems & Security Engineer

Twin Signalcebu city, central visayas, ph

Remote IT Systems & Security Engineer.Compensation: $800 - $1,200 per month.Twin Signal, a ZenitechCS company, is dedicated to launching new products and expanding into new markets, building on our... Show more

 • Promoted

Zone Manager (Leasing Operations)

Our ClientsPhilippines, Cebu, Philippines
Quick Apply

The Zone Manager is responsible for overseeing the overall operations, maintenance, and tenant relations within assigned office zones or commercial property areas.The role ensures operational effic... Show more

Fraud Operations Team Lead (Credit Cards)

Extend Your Teamcebu city, central visayas, ph

Our mission is to reduce the cost of capital across the world.We have invented a new credit card powered by an advanced asset-securing platform that enables us to offer much lower APRs to consumers... Show more

 • Promoted

Systems Integration Support Analyst

KMC Solutionscebu city, central visayas, ph

We seek an enthusiastic, versatile individual to join an established team providing a range of technical support services around the BPA Business Process Automation platform, supporting API-led int... Show more

 • Promoted

Mall Operations Associate Manager (Soft Services) (Cebu)

Ayala Mallscebu, central visayas, ph

As we re-define our malls, this transformation is more than just a facelift—this is a visionary re-invention.It’s a complete reimagining of how we serve communities, connect people, and elevate the... Show more

 • Promoted

Risk Analyst - Asia

BettingJobscebu city, central visayas, ph

Gaming operator seeking to add an experienced.The Risk Analyst role is responsible for assessing and mitigating potential risks to the business by safeguarding the integrity of the platform and pro... Show more

 • Promoted

Sales Operations Analyst (Cebu) - AU Client/Morning

HGS Offshore Staffing Solutions (HGS OSS)cebu, central visayas, ph

The Revenue Operations (RevOps) Analyst is a key analytical role within the RevOps team,.This role focuses on transforming data from Salesforce and other systems into clear, actionable.Build and ma... Show more

 • Promoted

Operations Specialist (Hubspot) - Morning Shift/Cebu

HGS Offshore Staffing Solutions (HGS OSS)cebu, central visayas, ph

Day‑to‑day operational support across customer support, success, sales and finance.Creating, maintaining, and improving SOPs, workflows, and internal documentation.Supporting and maintaining CRM an... Show more

 • Promoted

Operations Support Project Coordinator

Wimmer Solutions Philippinescebu city, central visayas, ph

Job Title: Operations Support Project Coordinator.Shift: Monday to Friday, 8:00 AM – 5:00 PM EST.The Operations Support Project Coordinator supports multiple project teams by coordinating telecommu... Show more

 • Promoted

Technology Solutions Analyst | WFH

TaskUscebu city, central visayas, ph

What can you expect in a Technology Solutions Analyst role with TaskUs:.The Technology Solution Analyst is an Individual Contributor role who will support the Sales and Customer Service Team organi... Show more

 • Promoted

E-Commerce Operations Specialist

Revayacebu city, central visayas, ph

E-Commerce Operations Specialist.Job Type: Part-Time (15 hours per week).Work Hours: Monday to Friday, 10:00 AM - 1:00 PM Eastern Time.We are seeking a highly organized and detail-driven.E-Commerce... Show more

 • Promoted

Revenue Operations Coordinator PH

Esusucebu city, central visayas, ph

Esusu: Building Credit Access for All.Your financial future shouldn't depend on your race, background, or zip code.Yet 45 million Americans remain \"credit invisible,\" while countless others face ... Show more

 • Promoted

Risk & Compliance (Assistant Manager)

Our ClientsPhilippines, Cebu, Philippines
Quick Apply

Assistant Manager – Risk & Compliance.The Assistant Manager – Risk & Compliance is responsible for overseeing IT security, compliance, and risk management initiatives within a BPO environme... Show more