Apply Edge Start your job search

Junior SOC Analyst — SIEM (Google SecOps)

PILLAR · Ho Chi Minh City, Vietnam

Apply & track with Apply Edge

PILLAR AI (formerly Ringkas) — the AI-native sales infrastructure for financial institutions, loan origination, built on four years of live, real-world data. We're not prototyping. We're scaling a system already proven across 33 bank partners and 50+ cities. What started in Asia is now expanding across the GCC through our partnership with ROSHN Group in Saudi. Arabia and others.We are hiring a Junior SOC Analyst to monitor, triage and escalate security events in Google Security Operations (SecOps, formerly Chronicle) as part of a 24/7 security monitoring service. You will be one of the people who keeps eyes on our Google Cloud (GCP) environment around the clock, including nights, weekends and public holidays.Key responsibilities:Monitoring and triage (Google SecOps SIEM)Watch Google SecOps alert queues, dashboards and detections in real time during your shift.Triage alerts from YARA-L detection rules and curated detections; classify each as true positive, false positive or benign.Investigate events with UDM search, entity/asset views and raw log search to build a timeline.Prioritise security events such as Cloud Armor/WAF blocks, IAM role and service-account key changes, access revocations, unauthorised access attempts, and public exposure of data or resources.Enrich alerts with threat intelligence (VirusTotal, Google Threat Intelligence, IP/domain reputation).Incident handling and escalationOpen, document and track cases in Google SecOps SOAR, following the Incident Response Plan and playbooks.Escalate confirmed or suspected incidents to the SOC Lead / L2 within the defined SLA, and send client notifications through the approved channels.Run first-response playbook steps under guidance: disable accounts, revoke sessions or keys, block IPs in Cloud Armor.Log sources and detection hygieneCheck that log ingestion is healthy (Cloud Audit Logs, Cloud Armor, VPC Flow Logs, Entra ID sign-in logs, endpoints) and raise tickets for gaps or parser errors.Flag noisy rules and suggest tuning; help draft new detections with senior analysts.Reporting and handoverWrite a shift handover at the end of every shift: open cases, actions taken, pending escalations.Contribute evidence to the monthly security-incident summary (security incidents only: breach, unauthorised access, revocation, exposure).Keep SOPs, runbooks and the knowledge base up to date.Shift & working arrangementThis is a 24/7 rotating role: you must be able to work nights, weekends, public holidays and overtime. Please apply only if you can commit to this schedule.ShiftMorning: 07:00 – 15:00 - Overlaps business hours; handover to afternoonAfternoon: 15:00 – 23:00 - Covers Saudi Arabia business hours (UTC+3)Night: 23:00 – 07:00 - Solo or paired monitoring; escalate via on-callRotation of 8-hour shifts across 7 days, including Saturdays, Sundays and public holidays (Indonesian and client-region).Typical pattern: 5 shifts on, 2 days off, with the rotation published at least 2 weeks ahead.Overtime when needed to cover absences, active incidents or shift gaps, paid in line with Vietnam Labor Law.Stay on until your handover is complete; an active incident may extend a shift.Occasional on-call availability outside your shift for escalations.A 15-minute overlap between shifts for handover.RequirementsDiploma or bachelor's degree in Computer Science, Information Security, IT or a related field, or equivalent hands-on experience.0–2 years in a SOC, NOC, IT support or security role; fresh graduates with strong lab or internship experience are welcome.Hands-on exposure to a SIEM, with Google SecOps (Chronicle) preferred: UDM search, reading alerts, basic YARA-L rule logic.Working knowledge of networking (TCP/IP, DNS, HTTP/S, firewalls, WAF) and common attack types (phishing, brute force, credential stuffing, privilege escalation).Basic familiarity with Google Cloud: IAM, service accounts, Cloud Audit Logs, Cloud Armor.Understanding of identity and access concepts: SSO, MFA, Microsoft Entra ID sign-in logs.Familiarity with MITRE ATT&CK and the incident response lifecycle (NIST SP 800-61).Clear written English for tickets, handovers and client notifications; Bahasa Indonesia for internal communication.Willing and able to work rotating 24/7 shifts, including nights, weekends, holidays and overtime.Calm under pressure, detail-oriented, and disciplined about following SOPs.Nice to haveCertifications: Google Cloud Professional Security Operations Engineer, CompTIA Security+ or CySA+, Google Cybersecurity Certificate, EC-Council CSA, or Blue Team Level 1 (BTL1).Experience with Google SecOps SOAR playbooks or another SOAR tool.Exposure to other SIEMs (Splunk, Microsoft Sentinel, IBM QRadar).Basic scripting in Python, Bash or PowerShell to automate lookups.Awareness of ISO 27001, SOC 2, or Saudi NCA ECC / Indonesian OJK and UU PDP requirements.Home lab, CTF or TryHackMe / LetsDefend SOC path experience.

Benefits

Competitive compensation.13th Month SalaryMonitor provided by the companyCompany sponsorship for personal laptop $1,400 or BYOD (bring your own device) option with bonus $1,400Private Health Insurance100% Insurance According To Labor Law14 Days Paid Annual LeaveGifts on holidays, parking, wedding & newborn baby allowanceOffice facilities: Coffee maker, snacks & drinksHappy hour, Team bonding, Company tripOpportunities for onsite trips to Indonesia.Multicultural, English-speaking, challenging but fun environment.