About Us
Supply Chimp (Mono Machines LLC dba Supply Chimp) has spent two decades supporting the U.S. government with critical supplies and logistics solutions. Our mission is simple and focused: we serve those who serve us by providing customer-driven supply solutions that get the right products to the right place at the right time.
At Supply Chimp, how we work matters just as much as what we deliver. Our values, teamwork, accountability, action, and integrity, shape how we show up for our customers, support one another, and deliver with purpose, trust, and follow-through.
Our Values
- Teamwork:
- We treat people with respect and work as one team to serve our customers
- Accountability
- We own it and follow through
- Action
- We act with urgency & purpose
- Integrity
- We do the right thing. Always.
About the Role
We are looking for a Security Operations Specialist to independently execute and support Supply Chimp’s day-to-day security operations. This role is responsible for security monitoring and alert triage, recurring security and compliance activities, evidence and documentation, security maintenance, incident response support, risk assessment, and security testing. This is a hands-on role for someone who can work effectively within established processes while also recognizing where processes, documentation, or tooling need to improve. Some of our security systems and workflows are still being developed, so success requires someone who can contribute useful operational input while reliably executing the work that already exists.
What Success Looks Like
- You independently manage recurring security operations work and meet established cadences without needing reminders.
- Security alerts and suspected events are investigated, documented, and escalated appropriately with useful supporting context.
- Security reviews, compliance evidence, and operational records are accurate, complete, organized, and ready for review.
- You demonstrate sound judgment when information is incomplete, know when to continue investigating, and know when escalation is needed.
- You identify practical improvements to security processes, documentation, monitoring, or controls and help move those improvements forward.
Key Responsibilities
Security Monitoring & Incident Response
- Monitor and triage security alerts and investigate suspected security events.
- Assess available information to help determine scope, impact, priority, and appropriate next steps.
- Document alert dispositions, findings, decisions, and actions clearly and accurately.
- Escalate confirmed or suspected security events with relevant context and supporting information.
- Coordinate approved containment, recovery, and follow-up activities within defined authority and working hours.
Security Controls, Compliance & Evidence
- Execute recurring security and compliance reviews across assigned controls and applicable frameworks.
- Collect, review, organize, and maintain supporting evidence in accordance with established standards.
- Identify control gaps, missing evidence, control drift, or potential findings and escalate them appropriately.
- Track open findings and remediation commitments through completion or escalation.
- Maintain review-ready security plans, compliance records, assessment artifacts, and supporting documentation.
Security Maintenance, Access & Risk
- Perform recurring vulnerability, endpoint, configuration, backup, access, and security-tool reviews within assigned scope.
- Review vulnerability findings, verify remediation status, and escalate unresolved material issues.
- Evaluate access, authentication, permissions, shared or service accounts, and related security controls for appropriate use and least privilege.
- Conduct or support security risk assessments for systems, applications, vendors, projects, integrations, and material changes.
- Maintain risk and remediation records and follow up on material open items.
Security Documentation, Testing & Improvement
- Create and maintain security procedures, runbooks, checklists, assessment tools, and triage guidance.
- Keep security documentation aligned with current systems, configurations, and operating processes.
- Design, configure, execute, and evaluate approved phishing simulations and related security testing.
- Identify gaps in monitoring, processes, documentation, or control coverage and recommend practical improvements.
- Collaborate with IT, Engineering, and other internal teams on security activities, findings, remediation, and user-facing security needs.
Role Reality
This role operates in an environment where some security tools, processes, documentation, and compliance workflows are established while others are still being developed or improved. You will need to execute reliably with the systems and procedures available today while identifying gaps, asking useful questions, and contributing practical input as the security operations function matures. Incident response responsibilities are handled during the stated core business hours; there is no routine after-hours or on-call expectation.
You May Be a Strong Fit If
- You have hands-on security operations experience and take ownership of recurring responsibilities without needing frequent reminders.
- You enjoy investigating alerts, security findings, control gaps, and technical issues until you can reach a defensible conclusion or escalation point.
- You are comfortable working with incomplete or ambiguous information while clearly separating facts, assumptions, and open questions.
- You can communicate clearly with technical and non-technical teammates and produce documentation others can rely on.
This Role May Not Be the Best Fit If
- You prefer highly structured environments where priorities rarely change.
- You are uncomfortable making decisions with incomplete information.
- You prefer to focus on contract administration without broader operational ownership.
- You avoid difficult conversations, accountability, or cross-functional collaboration.
- You prefer narrowly defined responsibilities with limited ambiguity.
What We're Looking For
- 3+ years of relevant experience in security operations, information security, cybersecurity, or a closely related role.
- Hands-on experience with security monitoring and SIEM tools, including alert triage, investigation, search or query capabilities, and documenting alert dispositions; hands on experience with provisioning devices.
- Hands-on experience with Microsoft security and identity technologies, including Microsoft Entra ID, Microsoft Intune, Conditional Access policies, and related endpoint and access controls is strongly preferred.
- Strong understanding of common security operations disciplines such as vulnerability management, access control, endpoint security, logging, and incident response.
- Experience performing recurring security or compliance control activities and producing clear, review-ready evidence and documentation; CMMC, NIST SP 800-171, PCI DSS, or comparable framework experience and relevant security certifications are preferred.
- Strong organization, prioritization, written communication, and follow-through with the ability to manage recurring responsibilities and competing deadlines independently.
- Demonstrated problem-solving and sound judgment when working through security issues with incomplete information or unclear conditions.
- Ability to work during our core business hours of 7:00 AM to 4:00 PM PST.
- Excited about remote work and collaborating across a distributed team.
What We Offer
- PHP 62,500/month + PHP 1150/month Rice Allowance after probationary period
- Leave Benefits:
- 160 hours of PTO (accrued), with an additional 8 hours for every year of service, up to a maximum of 40 extra hours
- US Paid Holidays
- Mandatory PH statutory benefits
- Government Contribution
- Night Differential, Holiday Pay Rate, and Overtime Pay
- 13th Month Pay
- HMO on Day 1
- PHP 580/month internet stipend (we require you to have at least 25MBPS home internet)
- Fun extras that make remote work feel human
- Surprise treats (yes, including coffee!)
- Gifts of appreciation and recognition
- Company shout-outs and celebrations
- Virtual parties and team moments throughout the year
Why Join Supply Chimp
This role will play an important part in helping Supply Chimp operate a reliable, practical security program that supports the company’s customers, systems, and compliance responsibilities.
You will have the opportunity to take meaningful ownership of day-to-day security operations while helping improve the tools, processes, documentation, and controls that support the company’s security program.
At Supply Chimp, we value ownership, collaboration, continuous improvement, and people who are willing to roll up their sleeves to help solve problems. If that sounds like you, we'd love to hear from you.