Junior SOC Analyst SIEM (Google SecOps)
pillar- Posted 4 hours ago
- Be among the first 10 applicants
Job Description
PILLAR AI (formerly Ringkas) — the AI-native sales infrastructure for financial institutions, loan origination, built on four years of live, real-world data. We're not prototyping. We're scaling a system already proven across 33 bank partners and 50+ cities. What started in Asia is now expanding across the GCC through our partnership with ROSHN Group in Saudi. Arabia and others.
We are hiring a Junior SOC Analyst to monitor, triage and escalate security events in Google Security Operations (SecOps, formerly Chronicle) as part of a 24/7 security monitoring service. You will be one of the people who keeps eyes on our Google Cloud (GCP) environment around the clock, including nights, weekends and public holidays.
Key responsibilities:
Monitoring and triage (Google SecOps SIEM)
- Watch Google SecOps alert queues, dashboards and detections in real time during your shift.
- Triage alerts from YARA-L detection rules and curated detections; classify each as true positive, false positive or benign.
- Investigate events with UDM search, entity/asset views and raw log search to build a timeline.
- Prioritise security events such as Cloud Armor/WAF blocks, IAM role and service-account key changes, access revocations, unauthorised access attempts, and public exposure of data or resources.
- Enrich alerts with threat intelligence (VirusTotal, Google Threat Intelligence, IP/domain reputation).
Incident handling and escalation
- Open, document and track cases in Google SecOps SOAR, following the Incident Response Plan and playbooks.
- Escalate confirmed or suspected incidents to the SOC Lead / L2 within the defined SLA, and send client notifications through the approved channels.
- Run first-response playbook steps under guidance: disable accounts, revoke sessions or keys, block IPs in Cloud Armor.
Log sources and detection hygiene
- Check that log ingestion is healthy (Cloud Audit Logs, Cloud Armor, VPC Flow Logs, Entra ID sign-in logs, endpoints) and raise tickets for gaps or parser errors.
- Flag noisy rules and suggest tuning; help draft new detections with senior analysts.
Reporting and handover
- Write a shift handover at the end of every shift: open cases, actions taken, pending escalations.
- Contribute evidence to the monthly security-incident summary (security incidents only: breach, unauthorised access, revocation, exposure).
- Keep SOPs, runbooks and the knowledge base up to date.
Shift & working arrangement
This is a 24/7 rotating role: you must be able to work nights, weekends, public holidays and overtime. Please apply only if you can commit to this schedule.
Shift
Morning: 07:00 – 15:00 - Overlaps business hours; handover to afternoon
Afternoon: 15:00 – 23:00 - Covers Saudi Arabia business hours (UTC+3)
Night: 23:00 – 07:00 - Solo or paired monitoring; escalate via on-call
- Rotation of 8-hour shifts across 7 days, including Saturdays, Sundays and public holidays (Indonesian and client-region).
- Typical pattern: 5 shifts on, 2 days off, with the rotation published at least 2 weeks ahead.
- Overtime when needed to cover absences, active incidents or shift gaps, paid in line with Vietnam Labor Law.
- Stay on until your handover is complete; an active incident may extend a shift.
- Occasional on-call availability outside your shift for escalations.
- A 15-minute overlap between shifts for handover.
Requirements
- Diploma or bachelor's degree in Computer Science, Information Security, IT or a related field, or equivalent hands-on experience.
- 0–2 years in a SOC, NOC, IT support or security role; fresh graduates with strong lab or internship experience are welcome.
- Hands-on exposure to a SIEM, with Google SecOps (Chronicle) preferred: UDM search, reading alerts, basic YARA-L rule logic.
- Working knowledge of networking (TCP/IP, DNS, HTTP/S, firewalls, WAF) and common attack types (phishing, brute force, credential stuffing, privilege escalation).
- Basic familiarity with Google Cloud: IAM, service accounts, Cloud Audit Logs, Cloud Armor.
- Understanding of identity and access concepts: SSO, MFA, Microsoft Entra ID sign-in logs.
- Familiarity with MITRE ATT&CK and the incident response lifecycle (NIST SP 800-61).
- Clear written English for tickets, handovers and client notifications; Bahasa Indonesia for internal communication.
- Willing and able to work rotating 24/7 shifts, including nights, weekends, holidays and overtime.
- Calm under pressure, detail-oriented, and disciplined about following SOPs.
Nice to have
- Certifications: Google Cloud Professional Security Operations Engineer, CompTIA Security+ or CySA+, Google Cybersecurity Certificate, EC-Council CSA, or Blue Team Level 1 (BTL1).
- Experience with Google SecOps SOAR playbooks or another SOAR tool.
- Exposure to other SIEMs (Splunk, Microsoft Sentinel, IBM QRadar).
- Basic scripting in Python, Bash or PowerShell to automate lookups.
- Awareness of ISO 27001, SOC 2, or Saudi NCA ECC / Indonesian OJK and UU PDP requirements.
- Home lab, CTF or TryHackMe / LetsDefend SOC path experience.
Benefits:
- Competitive compensation.
- 13th Month Salary
- Monitor provided by the company
- Company sponsorship for personal laptop $1,400 or BYOD (bring your own device) option with bonus $1,400
- Private Health Insurance
- 100% Insurance According To Labor Law
- 14 Days Paid Annual Leave
- Gifts on holidays, parking, wedding & newborn baby allowance
- Office facilities: Coffee maker, snacks & drinks
- Happy hour, Team bonding, Company trip
- Opportunities for onsite trips to Indonesia.
- Multicultural, English-speaking, challenging but fun environment.
