Search by job, company or skills

Senior Security Analyst (Hybrid) | AU Healthcare

  • Posted 13 hours ago
  • Be among the first 10 applicants

Job Description

The Opportunity at a Glance

We're looking for a Senior Security Analyst to join a growing organisation in the healthcare and allied health sector, strengthening its cyber defence across a cloud-only Microsoft 365 environment. It's a hands-on, dual-focus role: day-to-day incident response plus real ownership of security uplift projects


 


What You'll Actually Do


How You'll Make an Impact

Security operations and alert triage



  • Own the day-to-day security alert queue across Microsoft 365 Defender, Sentinel (where in use), and Entra ID Identity Protection.

  • Investigate and resolve incidents end to end using a standard incident handling workflow, from evidence through to a clean, documented resolution.



Incident response and playbook execution



  • Execute documented playbooks across the full incident catalogue: phishing, identity compromise, data exfiltration, mail redirect, lost or stolen device, OAuth abuse, and privacy breach scenarios.

  • Select and apply the right containment action based on the evidence in front of you, from investigation package collection through to device isolation and live response.



Threat hunting and detection engineering



  • Write, tune, and maintain KQL queries and custom detection rules across Defender Advanced Hunting (and Sentinel, where in use).

  • Close detection gaps and cut down false-positive noise through iterative rule refinement.



Security uplift and project delivery



  • Actively drive security uplift projects: Essential Eight hardening, MFA maturity, Conditional Access uplift, application control, and data-layer protection.

  • Deploy and validate hardening policies in Intune for application control, macro control, and legacy runtime restrictions.

  • Contribute to application and data governance initiatives using Microsoft Defender for Cloud Apps and Microsoft Purview.



Identity, endpoint, and cloud security operations



  • Investigate identity-based threats (risky user, risky sign-in, anomaly detections) and coordinate remediation.

  • Own the employee offboarding security procedure and maintain endpoint security policy hygiene across Intune and Defender.



Compliance, reporting, and documentation



  • Report notifiable cybersecurity incidents to the relevant regulator and provide incident summaries to leadership.

  • Own and maintain SOC playbooks, runbooks, and detection library entries, and track hardening maturity progress against the roadmap.



Using AI as a genuine force multiplier



  • Use AI tools to speed up KQL query authoring, incident summaries, and playbook drafting.

  • Apply AI for structured software vetting and to flag red flags in third-party applications and browser extensions.

  • Use AI to spot patterns across historical incidents and surface recurring root causes, and to draft first cuts of reports and documentation.


 
What We're Looking For - You're the Perfect Fit if You:

Non-Negotiable Requirements


  • Bachelor's degree in Computer Science, Information Systems, or a related field.

  • At least 2-3+ years of experience specifically as a Security Analyst, SOC Analyst, or Blue Team role

  • Hands-on experience across the Microsoft Defender suite (Defender for Endpoint, Defender for Office 365, Defender for Cloud Apps).

  • Experience with Entra ID (Azure AD), Conditional Access, and Identity Protection.

  • Experience with Microsoft Cloud App Security (MCAS) and Microsoft Purview.

  • Real experience writing and tuning KQL queries for threat hunting and detection.

  • Experience with Microsoft Intune for endpoint security policy deployment.

  • A strong, proactive security mindset.






 

What Sets You Apart - You'll Shine Even Brighter With:

Nice to Haves (Non-Deal breakers)


  • Experience with Microsoft Sentinel

  • Microsoft security certifications such as SC-200, SC-300, AZ-500, or MS-500, or equivalents like Security+ or CySA+.

  • Experience contributing to a security certification or accreditation project for an organisation (for example, ISO 27001).

  •  Exposure to compliance standards such as the Australian Privacy Principles (APP), GDPR, or HIPAA.

  • Experience in health, disability, aged care, or another regulated, sensitive-data industry.

  • Familiarity with the ACSC Essential Eight Maturity Model, ISM controls, or ACSC Intune hardening guidelines.








Work Schedule & Employment Terms

Full-Time | Monday to Friday | 6:00 AM - 3:00 PM PHT



  • Hybrid Setup (On-site once a month in BGC, Taguig)

  • Philippine-based employment only


What's Included

  • HMO with 1 free dependent

  • Life Insurance

  • Paid Leave Credits

  • Government-mandated benefits (SSS, PhilHealth, Pag-IBIG)

  • Work-from-home equipment provided


Employment is fully compliant with Philippine taxes and government contributions.



More Info

Job Type:
Industry:
Employment Type:

About Company

Job ID: 152064009

Beware of Scammers

We don’t charge money for job offers