SOC Tier 3 Analyst
Makati (KPH51673) Flex Office, Philippines
Kyndryl
At Kyndryl, we design, build, manage and modernize the mission-critical technology systems that the world depends on every day.Who We Are
At Kyndryl, we design, build, manage and modernize the mission-critical technology systems that the world depends on every day. So why work at Kyndryl? We are always moving forward – always pushing ourselves to go further in our efforts to build a more equitable, inclusive world for our employees, our customers and our communities.
The Role
Are you ready to elevate your career in cybersecurity and take on a challenging, impactful role? Kyndryl has an exciting opportunity for you as a SOC Tier 3 Analyst. This is your chance to play a central role in protecting critical infrastructures, identifying advanced threats, and shaping the cybersecurity landscape for our global clien
What You'll Be Doing:
Lead Critical Incident Investigations & Response: You will be responsible for leading high-priority, complex security incidents from start to finish. When incidents occur, you’ll take charge, ensuring effective investigation, analysis, and resolution. Your deep understanding of advanced threats and vulnerabilities will be key in leading these investigations, and your ability to think critically under pressure will make a real difference in protecting client assets.
Conduct Deep-Dive Forensic Analysis: In this role, you’ll be digging deep into security events and conducting thorough forensic analysis to uncover the root cause of incidents. Your expertise will help identify weaknesses, trace attack vectors, and develop insights that will not only guide incident response but also inform future prevention strategies. You’ll also be involved in refining detection methods to catch threats earlier in their lifecycle.
Develop & Refine Detection Strategies: You’ll play an essential role in improving detection capabilities across client environments. From refining existing detection rules to creating new strategies, you’ll work closely with the team to ensure that security systems can identify, respond to, and mitigate evolving threats with precision. Your insights will directly shape the way we monitor for future incidents and proactively prevent attacks.
Guide Junior Analysts & Provide Expertise: As a senior member of the team, you’ll mentor and guide junior analysts, providing them with the expertise they need to grow. You’ll ensure that best practices are followed, share your knowledge to improve team performance, and help develop the next generation of cybersecurity professionals. You’ll also act as a key resource for incident response, helping to troubleshoot complex issues and offering your expert judgment during escalations.
Coordinate with Stakeholders for Security Improvements: In addition to your technical responsibilities, you’ll work closely with internal teams and clients to communicate findings, discuss risks, and implement necessary improvements to security operations. You will be a trusted advisor, helping clients strengthen their security posture and ensure that the organization’s security measures align with evolving threat landscapes.
Your Future at Kyndryl
Every position at Kyndryl offers a way forward to grow your career. Whether you want to broaden your knowledge base or narrow your scope and specialize in a specific sector, you can find your opportunity here. We have opportunities that you won’t find anywhere else, including hands-on experience, learning opportunities, and the chance to certify in all four major platforms.
Who You Are
You’re good at what you do and possess the required experience to prove it. However, equally as important – you have a growth mindset; keen to drive your own personal and professional development. You are customer-focused – someone who prioritizes customer success in their work. And finally, you’re open and borderless – naturally inclusive in how you work with others.
Required Skills and Experience:
Experience: 5+ years in a SOC analyst role (preferably Tier 2 or Tier 3), with substantial experience in incident response and analyzing complex security threats.
Advanced Threat Analysis & Response: Expertise in identifying, analyzing, and responding to advanced cyber threats.
Digital Forensics & Malware Analysis: Proficiency in conducting digital forensics and analyzing malware to understand and mitigate threats.
Threat Hunting Methodologies: Strong knowledge of threat hunting techniques to proactively identify potential security threats.
Security Architecture & Threat Modeling: Experience in designing security architectures and creating threat models to protect organizational assets.
Incident Response & Remediation: Extensive experience in incident escalation, containment, and remediation.
SIEM Fine-Tuning & Rule Creation: Expertise in fine-tuning SIEM tools (e.g., Splunk, QRadar, ArcSight) and creating effective rules for threat detection.
Technical Proficiency: Proficiency in SIEM tools, IDS/IPS, firewalls, and endpoint protection systems.
Analytical Skills: Strong ability to analyze and correlate security data, identifying patterns and making decisions based on analysis.
Preferred Skills and Experience:
Certifications: Valid and current certification or equivalent experience in CISSP, GIAC (Global Information Assurance Certification), CompTIA Security+, Certified Cloud Security Professional, or similar advanced certifications.
Security Operations Center Experience: Previous experience working in a Security Operations Center (SOC).
Security Tooling: Proficiency with security tooling for Endpoint Detection and Response (EDR).
Cybersecurity Knowledge: Understanding of basic security concepts, including malware, vulnerabilities, and threat actors.
Technical Architecture Skills: Strong skills in designing and implementing technical security architectures.
Experience Advising C-Suite: Experience in advising C-suite executives on cybersecurity matters.
DevSecOps Practices: Familiarity with DevSecOps practices and methodologies, and experience integrating security into agile development processes.
Emerging Security Technologies: Knowledge of emerging security technologies and trends, such as artificial intelligence/machine learning in security, zero trust architecture, or secure remote access solutions.
Being You
Diversity is a whole lot more than what we look like or where we come from, it’s how we think and who we are. We welcome people of all cultures, backgrounds, and experiences. But we’re not doing it single-handily: Our Kyndryl Inclusion Networks are only one of many ways we create a workplace where all Kyndryls can find and provide support and advice. This dedication to welcoming everyone into our company means that Kyndryl gives you – and everyone next to you – the ability to bring your whole self to work, individually and collectively, and support the activation of our equitable culture. That’s the Kyndryl Way.
What You Can Expect
With state-of-the-art resources and Fortune 100 clients, every day is an opportunity to innovate, build new capabilities, new relationships, new processes, and new value. Kyndryl cares about your well-being and prides itself on offering benefits that give you choice, reflect the diversity of our employees and support you and your family through the moments that matter – wherever you are in your life journey. Our employee learning programs give you access to the best learning in the industry to receive certifications, including Microsoft, Google, Amazon, Skillsoft, and many more. Through our company-wide volunteering and giving platform, you can donate, start fundraisers, volunteer, and search over 2 million non-profit organizations. At Kyndryl, we invest heavily in you, we want you to succeed so that together, we will all succeed.
Get Referred!
If you know someone that works at Kyndryl, when asked ‘How Did You Hear About Us’ during the application process, select ‘Employee Referral’ and enter your contact's Kyndryl email address.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Agile ArcSight Artificial Intelligence C CISSP Cloud CompTIA DevSecOps EDR Firewalls Forensics GIAC IDS Incident response IPS Machine Learning Malware QRadar SIEM SOC Splunk Threat detection Vulnerabilities Zero Trust
Perks/benefits: Career development Startup environment Team events
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.