
Sandisk · Work Location: Remote Office - Philippines, LOCATION-3-332, PH · 3 months ago
Job Type (exemption status): Exempt position - Please see related compensation & benefits details below
Work Location: Remote Office - Philippines--LOCATION-3-332
Company Description
Sandisk understands how people and businesses consume data and we relentlessly innovate to deliver solutions that enable today’s needs and tomorrow’s next big ideas. With a rich history of groundbreaking innovations in Flash and advanced memory technologies, our solutions have become the beating heart of the digital world we’re living in and that we have the power to shape.
Sandisk meets people and businesses at the intersection of their aspirations and the moment, enabling them to keep moving and pushing possibility forward. We do this through the balance of our powerhouse manufacturing capabilities and our industry-leading portfolio of products that are recognized globally for innovation, performance and quality.
Sandisk has two facilities recognized by the World Economic Forum as part of the Global Lighthouse Network for advanced 4IR innovations. These facilities were also recognized as Sustainability Lighthouses for breakthroughs in efficient operations. With our global reach, we ensure the global supply chain has access to the Flash memory it needs to keep our world moving forward.
The Security Operations Center (SOC) Analyst L3 is a critical member of the Information Security team responsible for monitoring, detecting, analyzing, and responding to cybersecurity threats across the organization's environment. This role serves as the frontline defense against adversarial activity, operating within a 24×7 detection-first SOC model.
The primary responsibility of this position is the security alert workflow — the continuous triage, investigation, and disposition of security alerts and events generated across our security tooling ecosystem. Beyond queue operations, this role offers structured growth into threat hunting, detection engineering, incident response, vulnerability management, insider risk management and cross-functional InfoSec support.
This is a shift-based role supporting 24×7 operations; schedules may include evenings, overnight shifts, weekends, and holidays as business needs require.
Oversee detection queue health and ensure consistent SLA adherence, assisting with prioritization during high-volume or high-severity events
Conduct advanced investigations involving complex, multi-stage attacks across endpoint, identity, network, cloud, and third-party environments
Provide expert-level case documentation that supports executive reporting, compliance, and post-incident reviews
Act as a primary escalation point for major incidents, coordinating with Incident Response, Threat Intelligence, IT, and business stakeholders
Drive continuous improvement of detection logic, escalation criteria, and investigative workflows
Ensure effective shift transitions, including direct briefings when required
Author and maintain SOC documentation, including playbooks, SOPs, runbooks, training content, and detection standards
Support SOC maturity initiatives, such as detection tuning, automation use cases, metrics refinement, and analyst skill development
Support incident response efforts during active security events, including evidence gathering, containment actions, and timeline construction
Assist in the preparation of incident summaries, post-incident reports, and lessons-learned documentation
Execute containment and remediation actions under the guidance of IR leads (e.g., endpoint isolation, account disablement)
Participate in tabletop exercises and IR simulations to develop and validate response readiness
Review vulnerability scan results and assist in triaging findings based on severity, exploitability, and asset criticality
Support the coordination of remediation activities with IT asset owners, tracking tickets through to closure
Cross-reference active vulnerabilities with threat intelligence to identify weaponized CVEs that require prioritization
Assist in producing vulnerability reporting for team leads and stakeholders on a periodic basis
Support the review and triage of alerts generated by User and Entity Behavior Analytics (UEBA) platforms, Data Loss Prevention (DLP) tools, and insider threat-specific monitoring solutions
Correlate insider risk indicators across identity, endpoint, email, and cloud data sources to build a complete picture of potential policy violations or malicious intent
Assist in the investigation of data exfiltration attempts, unauthorized access to sensitive systems, and anomalous after-hours or off-network activity
Maintain strict confidentiality and chain-of-custody standards when handling insider risk cases, ensuring investigations are properly documented and legally defensible
Contribute to the ongoing refinement of the Insider Threat Program by surfacing patterns, gaps, and lessons learned from completed investigations
Serve as an available resource to other InfoSec teams, lending hands-on support for security-related tasks, reviews, and initiatives on an as-needed basis
Assist with security awareness initiatives, phishing simulations, and education campaigns
Support access reviews, security tool deployments, and policy compliance assessments as directed
Bachelor's degree in Cybersecurity, Computer Science, Information Systems, or equivalent practical experience
2–4+ years of experience in a SOC, IT security, or related technical role depending on level applied for
Familiarity with enterprise IT environments including Windows/Linux systems, Active Directory, and cloud platforms (Azure, AWS, GCP)
Experience with security tools such as SIEM (Sentinel, Splunk), EDR (CrowdStrike, SentinelOne, Defender), or email security platforms
CompTIA Security+, CySA+, or equivalent foundational security certification
EC-Council CEH, SANS GCIA/GCIH, or GREM (preferred for L3)
Strong analytical and critical-thinking skills with high attention to detail
Clear and concise written and verbal communication, including to non-technical stakeholders
Ability to remain composed and effective under pressure during active security incidents
Team-oriented and collaborative with a proactive, security-first mindset
Ability to approach security challenges with genuine curiosity and a questioning attitude, consistently digging deeper to understand the "why" behind alerts, behaviors, and anomalies rather than accepting surface-level conclusions
Sandisk is committed to providing equal opportunities to all applicants and employees and will not discriminate against any applicant or employee based on their race, color, ancestry, religion (including religious dress and grooming standards), sex (including pregnancy, childbirth or related medical conditions, breastfeeding or related medical conditions), gender (including a person’s gender identity, gender expression, and gender-related appearance and behavior, whether or not stereotypically associated with the person’s assigned sex at birth), age, national origin, sexual orientation, medical condition, marital status (including domestic partnership status), physical disability, mental disability, medical condition, genetic information, protected medical and family care leave, Civil Air Patrol status, military and veteran status, or other legally protected characteristics. We also prohibit harassment of any individual on any of the characteristics listed above. Our non-discrimination policy applies to all aspects of employment. We comply with the laws and regulations set forth in the "Know Your Rights: Workplace Discrimination is Illegal” poster. Our pay transparency policy is available here.
Sandisk thrives on the power and potential of diversity. As a global company, we believe the most effective way to embrace the diversity of our customers and communities is to mirror it from within. We believe the fusion of various perspectives results in the best outcomes for our employees, our company, our customers, and the world around us. We are committed to an inclusive environment where every individual can thrive through a sense of belonging, respect and contribution.
Sandisk is committed to offering opportunities to applicants with disabilities and ensuring all candidates can successfully navigate our careers website and our hiring process. Please contact us at jobs.accommodations@sandisk.com to advise us of your accommodation request. In your email, please include a description of the specific accommodation you are requesting as well as the job title and requisition number of the position for which you are applying.
Headquarters
Work Location: Remote Office - Philippines, LOCATION-3-332
Work Location
remote
Job Category
IT - Network/Sys/DB Admin
Application Deadline
Not specified
Job Type
full-time
Experience Level
Not specified
Application Method
Apply via Website
Salary
Not specified
No related jobs found