Hiring a SOC analyst in the Philippines, and when you need one instead of a security engineer
A SOC analyst monitors, triages and responds to alerts. A security engineer builds and hardens the systems that generate them. Most companies making their first security hire need an engineer, not an analyst, because a single analyst cannot provide meaningful coverage and there is usually nothing to monitor properly yet.
This is the most common mis-hire in security. A company decides it needs security, sees SOC analyst roles advertised everywhere, hires one, and discovers 6 months later that they employed someone to watch alerts from tooling nobody had configured. The distinction is worth getting right before the search starts.
The 2 jobs
Security engineer. Builds and hardens. Identity and access, network and cloud security controls, vulnerability management, logging and detection tooling, secure development practice. Proactive, project based, and the person who creates the telemetry an analyst would later watch.
A useful test: if you cannot currently answer what would generate an alert and who would see it, you do not have a monitoring problem yet. You have an engineering one.
Why 1 analyst does not give you coverage
Genuine 24 by 7 in house coverage needs 5 or more analysts on rotation. Below that you are choosing which hours to watch, and attackers do not schedule around your roster.
The realistic options for a smaller company: build engineering capability first and use a managed detection service for out of hours, or hire analysts in a tier that reflects the hours you have actually decided to cover. Both are legitimate. Hiring 1 analyst and describing it as 24 by 7 is not.
What the Philippine market supplies
Well represented: tier 1 and tier 2 analysis, SIEM operation, endpoint detection and response tooling, incident triage, vulnerability management, compliance and audit support.
Thinner: senior detection engineering, threat hunting at depth, purple team capability, and cloud security architecture. These exist but are scarce and are actively recruited internationally, which is exactly why they take longer to hire.
How to test for the real thing
Ask about a false positive they spent too long on. Every real analyst has one and the story reveals how they think.
Ask what they escalated that turned out to be nothing, and what they did not escalate that turned out to be something. Candour here is the strongest signal in the interview.
Ask them to walk through triage of a specific alert type end to end. What they look at first, what would make them escalate, what they would document.
Ask what tuning they have done. Analysts who have only consumed alerts, never tuned the rules generating them, are earlier in their development than the CV suggests.
The shift question, and what it costs
Work between 10pm and 6am attracts a night shift differential of not less than 10 percent of the regular hourly wage. Overtime, rest day and holiday premiums are separate and stack.
Decide the roster before the job description, because it changes who applies and it changes the cost. It is also the single largest driver of attrition in this function, so a rotation that shares the burden will outlast one that does not.
The sequence that usually works
For a second: either a second engineer if the estate is growing, or an analyst if there is now genuine telemetry and a decided coverage window.
For 24 by 7: accept that this is a team, not a hire, and decide whether you are building it or buying part of it.
Hiring in the Philippines?
Book a 30-minute call. We scope your role, share market context, and confirm a realistic timeline. No pitch, no pressure.
Book a FREE 30-minute call