Job Description
About Us:
PILLAR AI (formerly Ringkas) — the AI-native sales infrastructure for financial institutions, loan origination, built on four years of live, real-world data. We're not prototyping. We're scaling a system already proven across 33 bank partners and 50+ cities. What started in Asia is now expanding across the GCC through our partnership with ROSHN Group in Saudi Arabia and others.
Role Summary:
We are hiring a Junior SOC Analyst to monitor, triage and escalate security events in Google Security Operations (SecOps, formerly Chronicle) as part of a 24/7 security monitoring service. You will be one of the people who keeps eyes on our Google Cloud (GCP) environment around the clock, including nights, weekends and public holidays.
Key Responsibilities:
Monitoring and triage (Google SecOps SIEM)
- Watch Google SecOps alert queues, dashboards and detections in real time during your shift.
- Triage alerts from YARA-L detection rules and curated detections; classify each as true positive, false positive or benign.
- Investigate events with UDM search, entity/asset views and raw log search to build a timeline.
- Prioritise security events such as Cloud Armor/WAF blocks, IAM role and service-account key changes, access revocations, unauthorised access attempts, and public exposure of data or resources.
- Enrich alerts with threat intelligence (VirusTotal, Google Threat Intelligence, IP/domain reputation).
Incident handling and escalation
- Open, document and track cases in Google SecOps SOAR, following the Incident Response Plan and playbooks.
- Escalate confirmed or suspected incidents to the SOC Lead / L2 within the defined SLA, and send client notifications through the approved channels.
- Run first-response playbook steps under guidance: disable accounts, revoke sessions or keys, block IPs in Cloud Armor.
Log sources and detection hygiene
- Check that log ingestion is healthy (Cloud Audit Logs, Cloud Armor, VPC Flow Logs, Entra ID sign-in logs, endpoints) and raise tickets for gaps or parser errors.
- Flag noisy rules and suggest tuning; help draft new detections with senior analysts.
Reporting and handover
- Write a shift handover at the end of every shift: open cases, actions taken, pending escalations.
- Contribute evidence to the monthly security-incident summary (security incidents only: breach, unauthorised access, revocation, exposure).
- Keep SOPs, runbooks and the knowledge base up to date.
Requirements:
- Diploma or bachelor's degree in Computer Science, Information Security, IT or a related field, or equivalent hands-on experience.
- 0–2 years in a SOC, NOC, IT support or security role; fresh graduates with strong lab or internship experience are welcome.
- Hands-on exposure to a SIEM, with Google SecOps (Chronicle) preferred: UDM search, reading alerts, basic YARA-L rule logic.
- Working knowledge of networking (TCP/IP, DNS, HTTP/S, firewalls, WAF) and common attack types (phishing, brute force, credential stuffing, privilege escalation).
- Basic familiarity with Google Cloud: IAM, service accounts, Cloud Audit Logs, Cloud Armor.
- Understanding of identity and access concepts: SSO, MFA, Microsoft Entra ID sign-in logs.
- Familiarity with MITRE ATT&CK and the incident response lifecycle (NIST SP 800-61).
- Clear written English for tickets, handovers and client notifications; Bahasa Indonesia for internal communication.
- Willing and able to work rotating 24/7 shifts, including nights, weekends, holidays and overtime.
- Willing and able to secured google security officer certification
- Calm under pressure, detail-oriented, and disciplined about following SOPs.
Nice To Have:
- Certifications: Google Cloud Professional Security Operations Engineer, CompTIA Security+ or CySA+, Google Cybersecurity Certificate, EC-Council CSA, or Blue Team Level 1 (BTL1).
- Experience with Google SecOps SOAR playbooks or another SOAR tool.
- Exposure to other SIEMs (Splunk, Microsoft Sentinel, IBM QRadar).
- Basic scripting in Python, Bash or PowerShell to automate lookups.
- Awareness of ISO 27001, SOC 2, or Saudi NCA ECC / Indonesian OJK and UU PDP requirements.
- Home lab, CTF or TryHackMe / LetsDefend SOC path experience.
Item
Detail
More Info
Key Skills
UDM search
Cloud Armor
Cloud Audit Logs
YARA-L
NIST SP 800-61
Google SecOps
