Relomote
Remote JobsRelocation Jobs
Add companySaved
Relomote

Relomote is a job board for remote, hybrid, and relocation jobs — every listing AI-classified for the countries it actually hires from, or the visa and relocation support it offers.

LinkedInCrunchbase

Remote jobs by category

  • Remote Engineering & Development jobs
  • Remote Customer Support jobs
  • Remote Design jobs
  • Remote Marketing jobs
  • Remote Sales jobs
  • Remote Product jobs
  • Remote Data & Analytics jobs
  • Remote People & Talent jobs
  • Remote Writing & Content Creation jobs
  • Remote Finance jobs
  • Remote Legal & Compliance jobs
  • Remote Operations & Admin jobs
  • Remote Data Entry jobs
  • Remote Virtual Assistant jobs
  • Remote Education/Training jobs
  • Remote Healthcare/Clinical jobs
  • Remote Other jobs

Remote jobs by location

  • Work from anywhere jobs
  • Remote jobs in Africa
  • Remote jobs in Asia
  • Remote jobs in Europe
  • Remote jobs in Latin America
  • Remote jobs in Middle East
  • Remote jobs in North America
  • Remote jobs in Oceania
  • All remote jobs →

Relocation & visa sponsorship

  • Visa sponsorship jobs
  • Relocation package jobs
  • Relocate to Europe
  • Relocate to Germany
  • Relocate to Netherlands
  • Relocate to Spain
  • Relocate to Portugal
  • Relocate to Greece
  • Relocate to United Kingdom
  • Relocate to Canada
  • Relocate to Australia
  • Relocate to Sweden
  • Relocate to Switzerland
  • Relocate to Japan
  • Relocate to United Arab Emirates
  • All relocation jobs →

© 2026 RelomoteAboutPrivacyTerms

Contact [email protected] · Built by Mahmoud

Relomote
Remote JobsRelocation Jobs
Add companySaved
CallTek logo

SOC Analyst L2

CallTek
Posted Jun 26, 2026, 9:28 PM UTC
🇵🇭Philippines🏠Remote📁Other
Is this job info correct?

As a SOC Analyst L2, you will lead deeper investigations of escalated cases, confirm incidents, determine scope and impact, drive containment actions with internal teams, and produce high-quality technical communications and post-incident outputs. You will also contribute to detection improvement (tuning, new detections, playbook updates). Responsibilities: Take escalations from L1 and perform in-depth investigations: hypothesis-driven analysis, evidence validation, scoping, impact assessment, and timeline building. Correlate telemetry across endpoint (EDR), Windows/Linux, AD, firewall/proxy/DNS/IDS, and (when applicable) cloud logs. Recommend and/or coordinate containment actions (host isolation, credential resets, IOC blocks, temporary control changes) following change control and governance. Determine severity and communicate clearly in English to technical stakeholders; provide concise executive-style updates when required. Identify detection gaps and drive improvements: reduce false positives, close false negatives, propose new rules/use cases. Ensure evidence integrity and proper documentation, coordinate handoffs with IR, IT Ops, Network, and Cloud teams. Produce post-incident deliverables: probable root cause, lessons learned, and preventive actions. 2–5 years in SOC/IR/Blue Team (or equivalent demonstrated incident-handling experience). Solid fundamentals in networking: TCP/IP, DNS, HTTP/S, VPN, NAT. EDR investigations (process trees, persistence, LOLBins behavior, containment workflows). Windows/AD triage (authentication patterns, suspicious logon behavior, account activity) and Linux triage. Network analysis and security controls (firewall/IDS/proxy/DNS), recognizing anomalous patterns. Proven ability to produce defensible scoping and timelines based on evidence. High documentation standards and the ability to perform under pressure. Threat hunting experience and MITRE ATT&CK mapping. Detection engineering exposure (Sigma/YARA at a basic/intermediate level), use-case design, and SIEM correlation strategy. Basic forensics capabilities (acquisition concepts, triage artifacts, memory/disk fundamentals). Certifications aligned to Blue Team / IR (e.g., GCIH/GCIA, BTL2, SC-200, etc.). Strong spoken and written English (B2-High/C1 preferred) — able to lead technical calls, write incident summaries, and investigation notes.

Similar jobs

Similar jobs

Infor logo

Dev Business Analyst, Associate

Infor

🇵🇭Philippines1 weeks ago
Infor logo

Quality Assurance Analyst, Associate

Infor

🇵🇭Philippines1 weeks ago
Creatoriq logo

Associate GTM Operations Analyst, Deal Desk

Creatoriq

🇵🇭Philippines1 weeks ago
Continental Group Sector ContiTech logo

Order Management Associate/Analyst - Morning Shift (Australia)

Continental Group Sector ContiTech

🇵🇭Philippines3 weeks ago
D2B logo

Senior Mortgage Associate / Credit Analyst (AU Mortgage - Mercury CRM)

D2B

🇵🇭Philippines3 weeks ago
Continental Group Sector ContiTech logo

Order Management Associate/Analyst - Mid Shift

Continental Group Sector ContiTech

🇵🇭Philippines4 weeks ago