IT Security Analyst
CallTek
| Company | CallTek |
| Category | Security |
| Location | Cebu City |
| Remote | On-site (inferred) |
| Employment | Full-time |
| Level | Not stated |
| Salary | Not stated by the employer |
| Posted | 22 Jul 2026 |
| Last verified | 30 Jul 2026 |
| Source | Employer career page (workable) |
Description
The Entry-Level IT Security Analyst provides first-line review and analysis of alerts generated by Wazuh, Bitdefender, and other approved security or IT management tools. The analyst validates alert context, reviews relevant logs, inspects affected computers or devices, gathers evidence, follows approved response procedures, and records findings in the designated ticketing or incident-management system. This role works under the direction of the IT Security Manager or assigned senior security resource. The analyst is expected to use sound basic IT and security knowledge, remain within approved access and response boundaries, escalate uncertainty promptly, protect confidential information, and avoid making unsupported conclusions or high-risk production changes without authorization. Requirements Alert Queue Monitoring: Review assigned security alerts and notifications consistently, acknowledge them promptly, and prevent unresolved events from aging without ownership. Initial Incident Analysis: Gather relevant facts from Wazuh, Bitdefender, operating-system logs, ticket history, asset records, and approved supporting tools before forming an assessment. Affected Equipment Inspection: Perform structured remote or physical inspection of affected endpoints and related equipment using approved checklists, access methods, and safety precautions. Evidence Collection and Preservation: Capture sufficient evidence to support escalation, investigation, remediation, audit, and possible root-cause review while protecting integrity and confidentiality. Incident Classification and Escalation: Apply the approved severity matrix and escalate suspected malware, unauthorized access, data exposure, policy violations, repeated detections, or uncertain findings to the designated incident lead. Authorized Containment Support: Carry out only approved containment actions and immediately report any business interruption, tool failure, unexpected behavior, or unsuccessful response action. Remediation Verification: Confirm that scans, updates, quarantine actions, policy corrections, patches, credential actions, or other assigned remediation steps were completed and produced the expected result. Tool Coverage and Health Review: Identify inactive agents, outdated components, missed check-ins, policy mismatches, logging gaps, duplicate assets, and other conditions that weaken security visibility or protection. Ticketing and Reporting: Maintain accurate, factual, and timely incident records; avoid speculation and clearly distinguish confirmed facts, working assessments, pending validation, and required decisions. Policy, Privacy, and Access Compliance: Use assigned privileges only for authorized work, follow least-privilege principles, protect credentials and confidential information, and comply with evidence-retention and acceptable-use requirements. Process Improvement Support: Identify repeat alerts, confusing runbook steps, missing data, common false positives, and training needs, then submit improvement recommendations to the security team. Qualifications: Associate's or bachelor's degree in Information Technology, Cybersecurity, Computer Science, Information Systems, or a related discipline, or equivalent technical education, laboratory training, certification study, internship, or practical experience. Zero to two years of experience in IT support, desktop support, system administration, networking, NOC, SOC, managed services, cybersecurity operations, or a related technical environment; qualified entry-level candidates are encouraged. Basic IT knowledge is required, including Windows endpoints, computer hardware, applications, user accounts, permissions, file systems, services, remote support, software installation, patching, IP addressing, DNS, and common network concepts. Basic security knowledge is required, including malware, phishing, endpoint protection, event logs, indicators of compromise, vuln
You found the opening. Now track it.Tracker, radar and AI drafts in one place.erioun.com →