Apply Edge Start your job search

Junior SOC Analyst — SIEM (Google SecOps)

PILLAR · Jakarta, Indonesia

Apply & track with Apply Edge

About Us:PILLAR AI (formerly Ringkas) — the AI-native sales infrastructure for financial institutions, loan origination, built on four years of live, real-world data. We're not prototyping. We're scaling a system already proven across 33 bank partners and 50+ cities. What started in Asia is now expanding across the GCC through our partnership with ROSHN Group in Saudi Arabia and others.

Role Summary

We are hiring a Junior SOC Analyst to monitor, triage and escalate security events in Google Security Operations (SecOps, formerly Chronicle) as part of a 24/7 security monitoring service. You will be one of the people who keeps eyes on our Google Cloud (GCP) environment around the clock, including nights, weekends and public holidays.

Key Responsibilities

Monitoring and triage (Google SecOps SIEM)Watch Google SecOps alert queues, dashboards and detections in real time during your shift.Triage alerts from YARA-L detection rules and curated detections; classify each as true positive, false positive or benign.Investigate events with UDM search, entity/asset views and raw log search to build a timeline.Prioritise security events such as Cloud Armor/WAF blocks, IAM role and service-account key changes, access revocations, unauthorised access attempts, and public exposure of data or resources.Enrich alerts with threat intelligence (VirusTotal, Google Threat Intelligence, IP/domain reputation).Incident handling and escalationOpen, document and track cases in Google SecOps SOAR, following the Incident Response Plan and playbooks.Escalate confirmed or suspected incidents to the SOC Lead / L2 within the defined SLA, and send client notifications through the approved channels.Run first-response playbook steps under guidance: disable accounts, revoke sessions or keys, block IPs in Cloud Armor.Log sources and detection hygieneCheck that log ingestion is healthy (Cloud Audit Logs, Cloud Armor, VPC Flow Logs, Entra ID sign-in logs, endpoints) and raise tickets for gaps or parser errors.Flag noisy rules and suggest tuning; help draft new detections with senior analysts.Reporting and handoverWrite a shift handover at the end of every shift: open cases, actions taken, pending escalations.Contribute evidence to the monthly security-incident summary (security incidents only: breach, unauthorised access, revocation, exposure).Keep SOPs, runbooks and the knowledge base up to date.

Requirements

Diploma or bachelor's degree in Computer Science, Information Security, IT or a related field, or equivalent hands-on experience.0–2 years in a SOC, NOC, IT support or security role; fresh graduates with strong lab or internship experience are welcome.Hands-on exposure to a SIEM, with Google SecOps (Chronicle) preferred: UDM search, reading alerts, basic YARA-L rule logic.Working knowledge of networking (TCP/IP, DNS, HTTP/S, firewalls, WAF) and common attack types (phishing, brute force, credential stuffing, privilege escalation).Basic familiarity with Google Cloud: IAM, service accounts, Cloud Audit Logs, Cloud Armor.Understanding of identity and access concepts: SSO, MFA, Microsoft Entra ID sign-in logs.Familiarity with MITRE ATT&CK and the incident response lifecycle (NIST SP 800-61).Clear written English for tickets, handovers and client notifications; Bahasa Indonesia for internal communication.Willing and able to work rotating 24/7 shifts, including nights, weekends, holidays and overtime.Willing and able to secured google security officer certificationCalm under pressure, detail-oriented, and disciplined about following SOPs.Nice To Have:Certifications: Google Cloud Professional Security Operations Engineer, CompTIA Security+ or CySA+, Google Cybersecurity Certificate, EC-Council CSA, or Blue Team Level 1 (BTL1).Experience with Google SecOps SOAR playbooks or another SOAR tool.Exposure to other SIEMs (Splunk, Microsoft Sentinel, IBM QRadar).Basic scripting in Python, Bash or PowerShell to automate lookups.Awareness of ISO 27001, SOC 2, or Saudi NCA ECC / Indonesian OJK and UU PDP requirements.Home lab, CTF or TryHackMe / LetsDefend SOC path experience.ItemDetail