
Remote opportunity at
BlueVoyantSOC Security Analyst L3
BlueVoyant is seeking an experienced SOC Security Analyst L3 to safeguard global customers from persistent threat activity. Operating within the Security Operations Center, this position suits…
Career Tools
About This Role
BlueVoyant is seeking an experienced SOC Security Analyst L3 to safeguard global customers from persistent threat activity. Operating within the Security Operations Center, this position suits a senior technical professional capable of guiding investigations, handling active intrusions, and mentoring junior staff. BlueVoyant is an artificial intelligence-driven cybersecurity company that protects client networks, identities, vendors, and digital footprints through combined human and proprietary intelligence. As the primary technical escalation point, the…
Job Description
BlueVoyant is seeking an experienced SOC Security Analyst L3 to safeguard global customers from persistent threat activity. Operating within the Security Operations Center, this position suits a senior technical professional capable of guiding investigations, handling active intrusions, and mentoring junior staff. BlueVoyant is an artificial intelligence-driven cybersecurity company that protects client networks, identities, vendors, and digital footprints through combined human and proprietary intelligence.
As the primary technical escalation point, the chosen candidate will lead complex incident responses, execute live endpoint analysis, and perform proactive threat hunting. The individual will interact regularly with clients to deliver investigation documentation and coordinate remediation strategies. The role requires adhering strictly to organizational operating procedures, tooling, and access controls while operating across managed systems and client environments.
This full-time opportunity is situated in the Philippines and requires Philippine citizenship due to specific client engagement regulations. Candidates must maintain the capacity to work designated shift schedules spanning Sunday through Wednesday or Wednesday through Saturday from 7:00am to 5:00pm. The position involves collaborating within a globally distributed team to refine detection strategies, tune security alerts, and advance internal automation processes.
Responsibilities
- Monitor and examine security alerts originating from SIEM logs, endpoint logs, and EDR telemetry
- Serve as the technical escalation contact for active intrusions and lower-level analyst cases
- Execute intricate investigations, manage incident declarations, and perform live responses on compromised endpoints
- Analyze malware samples, malicious network infrastructure, and digital forensic artifacts
- Conduct threat hunting operations utilizing behavioral anomalies and curated intelligence
- Collaborate with Incident Response teams during active network incursions
- Produce investigation documentation that provides clients with clear remediation steps
- Communicate directly with clients to report security incidents and guide remediation
- Adjust and tune detection rules to minimize false-positive alerts
- Review peer investigations, assure quality, and mentor junior team members
- Assist in developing security policies, operational procedures, and automation mechanisms
Requirements
- Philippine citizenship
- Ability to work shifts from 7:00am to 5:00pm on either a Sunday through Wednesday or Wednesday through Saturday schedule
- Skill in handling high-pressure scenarios productively and professionally
- Advanced verbal and written communication abilities for explaining complex technical concepts
- Familiarity with SIEM solutions, Cloud App Security tools, and EDR platforms
- Experience building SIEM and EDR detection rules
- Proficiency in endpoint, web, and authentication log analysis
- Knowledge of network protocols, telemetry, and commonly abused protocols
- Experience mitigating modern authentication attacks targeting Active Directory, Entra ID, OAuth, and SSO
- Understanding of attack paths such as LOLBin utilization, adversary tools, business email compromise, and AiTM attacks
- Working knowledge of Microsoft Sentinel and Splunk workflows
- Competency in malware detection, including dynamic and light static analysis, Windows PE, and maldoc review
- Familiarity with network monitoring metadata, email security, and Windows or Unix forensic artifacts
Qualifications
- Background in intrusion analysis, incident response, digital forensics, or penetration testing
- Five or more years of practical SOC, TOC, or NOC experience
- Experience countering ransomware actors and operations
- Familiarity with Microsoft Sentinel, Splunk, Microsoft Defender suite, CrowdStrike Falcon, and SentinelOne
- Knowledge of infrastructure tools like GPO and LANDesk
- Understanding of programming languages including Python, JavaScript, Lua, Ruby, GoLang, or Rust
- GIAC certifications, CISSP, Security+, Network+, CEH, RHCA, RHCE, MCSA, MCP, or MCSE
- Bachelor’s degree in Information Security, Computer Science, or a related IT discipline, or equivalent professional experience
Core Skills
Benefits
- Competitive compensation
- Comprehensive benefits package supporting wellbeing, development, and career growth
Frequently Asked Questions
What is the location and remote status for this role?
The position is located in the Philippines. Philippine citizenship is strictly required for this role due to client contractual requirements and applicable laws.
What are the working hours and shift schedules?
The shift schedule runs from 7:00am to 5:00pm, covering either Sunday through Wednesday or Wednesday through Saturday.
What is the employment type?
The posting specifies a full-time employment type.
What salary and specific benefits are offered?
The job posting does not specify exact salary figures. It notes that competitive compensation and a comprehensive benefits package are provided.
Sample Interview Questions
AI-generated questions tailored to this specific role — a preview of the full practice set.