Job Description

Lead Incident Response. Strengthen Cyber Defense.

Join Accenture's Cybersecurity team as a SOC Team Lead (L2) and play a key role in detecting, investigating, and responding to advanced security threats. This role is ideal for experienced SOC professionals who enjoy leading analysts, driving incident response efforts, and continuously improving security operations.

What You'll Do


  • Lead the investigation and resolution of complex security incidents escalated by L1 analysts.
  • Perform root cause analysis, threat validation, and incident triage across enterprise environments.
  • Act as a key responder during high-severity incidents, coordinating with CSIRT, engineering teams, and stakeholders.
  • Conduct threat hunting activities using indicators of compromise (IoCs) and threat intelligence.
  • Mentor and guide SOC analysts through coaching, quality reviews, and incident handling best practices.
  • Collaborate with detection engineering teams to improve use cases, alert quality, and SOC processes.
  • Maintain incident documentation, reports, playbooks, and operational procedures.


  • What We're Looking For


  • 3–5+ years of experience in a SOC, Incident Response, or Cyber Defense environment.
  • Previous experience leading, mentoring, or supervising SOC analysts is highly preferred.
  • Strong hands-on experience investigating security incidents using SIEM and security monitoring tools.
  • Knowledge of network security, threat detection, malware analysis, incident response, and threat hunting.
  • Experience analyzing logs, network traffic, and security events across enterprise environments.
  • Ability to work effectively during high-priority security incidents and coordinate cross-functional response efforts.


  • Preferred Qualifications


  • Experience with CrowdStrike Falcon (highly preferred).
  • Hands-on experience with SIEM platforms such as Splunk, Sentinel, QRadar, Google SecOps, or similar.
  • Scripting experience using Python or PowerShell for automation and investigations.
  • Certifications such as Security+, CEH, GCIH, GCIA, or similar.
  • Exposure to cloud security monitoring across AWS, Azure, or GCP.


  • pahabol din Marquez, Gladys Faith

    Security Information & Event Management (SIEM) Platform OperationsR1428168ATCP-1428168-S424121CapBldg - Security9

    Job Posting Title: Cyber Security Engineer (SIEM & SOAR)

    Job Description:

    Join Accenture's Cybersecurity team and help organizations strengthen their defenses through advanced threat detection, security automation, and incident response. You'll work with leading SIEM and SOAR technologies while partnering with SOC analysts and security teams to build scalable, enterprise-grade security solutions.

    What You'll Do

    SIEM Engineering


  • Design, implement, and optimize SIEM platforms such as Google SecOps, Splunk, QRadar, Microsoft Sentinel, or Elastic.
  • Develop correlation rules, dashboards, alerts, and reports to improve threat visibility.
  • Integrate security data from networks, endpoints, cloud environments, and applications.
  • Improve data quality, parsing, and normalization to enhance detection accuracy.


  • SOAR & Security Automation


  • Build and maintain automated response workflows using SOAR platforms such as Cortex XSOAR, Splunk SOAR, IBM Resilient, or Google SecOps SOAR.
  • Develop playbooks for alert triage, incident response, and threat intelligence enrichment.
  • Streamline SOC processes through automation and tool integrations.


  • Security Operations Support


  • Support incident response activities through actionable detections and automated workflows.
  • Investigate recurring security issues and implement long-term engineering solutions.
  • Partner with compliance, audit, and IT teams to strengthen security controls and processes.


  • Job Qualifications:

    What We're Looking For


  • Minimum of 3 years of experience in SIEM and/or SOAR engineering or administration.
  • Experience working in a SOC environment is preferred.
  • Hands-on experience with at least one major SIEM platform (Google SecOps, Splunk, Sentinel, QRadar, ArcSight, etc.).
  • Experience developing SOAR playbooks and security automations.
  • Scripting experience in Python, PowerShell, or Bash.
  • Knowledge of security frameworks such as MITRE ATT&CK, NIST, or CIS Controls.
  • Familiarity with EDR/XDR, IDS/IPS, firewalls, threat intelligence platforms, and cloud security technologies.


  • Work Setup


  • Hybrid work arrangement
  • Cubao office location
  • Amenable to possible shifting schedules


  • Why Join Accenture?

    At Accenture, you'll work on impactful projects using emerging technologies while collaborating with some of the industry's top cybersecurity professionals.

    Benefits & Perks


  • Competitive salary package
  • Performance bonus and 13th Month Pay
  • Day 1 HMO and Life Insurance coverage
  • Flexible working arrangements*
  • Company-sponsored training, upskilling, and certifications
  • Expanded maternity and paternity benefits*
  • Employee Stock Purchase Plan
  • Inclusive and collaborative work culture
  • Terms and conditions apply.


  • Be Part of an Inclusive Workplace

    At Accenture, we celebrate diversity and are committed to creating an inclusive environment where everyone can thrive. We welcome applications from all qualified candidates and provide reasonable accommodations throughout the recruitment process.

    Application Reminder

    To help us process your application faster, please complete your Workday profile within 24 hours after applying.

    Important: In line with Accenture's identity verification process, please ensure your resume/CV includes a recent photo.

    If you're an experienced SOC professional ready to step into a leadership role, we'd love to hear from you.


    Job Details

    Role Level: Mid-Level Work Type: Full-Time
    Country: Philippines City: Quezon City National Capital Region
    Company Website: https://www.accenture.com/ph-en Job Function: Cybersecurity
    Company Industry/
    Sector:
    Software Development

    What We Offer


    About the Company

    Searching, interviewing and hiring are all part of the professional life. The TALENTMATE Portal idea is to fill and help professionals doing one of them by bringing together the requisites under One Roof. Whether you're hunting for your Next Job Opportunity or Looking for Potential Employers, we're here to lend you a Helping Hand.

    Report

    Disclaimer: talentmate.com is only a platform to bring jobseekers & employers together. Applicants are advised to research the bonafides of the prospective employer independently. We do NOT endorse any requests for money payments and strictly advice against sharing personal or bank related information. We also recommend you visit Security Advice for more information. If you suspect any fraud or malpractice, email us at abuse@talentmate.com.


    Recent Jobs
    View More Jobs
    Talentmate Instagram Talentmate Facebook Talentmate YouTube Talentmate LinkedIn