Skip to main content
Zezst Querubin BalevaZB
Open to opportunities

Zezst Querubin Baleva

@zezstquerubinbaleva

Senior cybersecurity leader specializing in security operations, incident response, and detection engineering across enterprise environments.

Philippines
Message

What I'm looking for

I’m open to remote work, and I want to lead security operations and incident response while building detections and automations in SIEM environments. I value cross-functional leadership, rigorous QA, and clear executive communication.

I’m a dynamic, highly analytical cybersecurity leader with over 13 years of progressive enterprise experience in Security Operations, Incident Response, and Detection Engineering. I naturally lead cross-functional security teams—delegating workloads, running quality assurance audits, and executing proactive threat-hunting campaigns. I also design robust CSIRT services from the ground up.

In my current role as a Professional Services Consultant IV (Lead Responder) at Verizon Communications, I deliver managed security and incident response services to global enterprise clients across multiple industries. I help greenfield and integrate CSIRT capabilities, architect Microsoft Sentinel detection logic, and build automated playbooks to accelerate triage and containment. As an Incident Commander, I conduct rigorous ticket audits to ensure accuracy, SLA conformance, and high-quality peer coaching.

Earlier, I led SOC operations governance and SIEM rule development in a telecom environment, coordinating daily monitoring activities and workload routing. I also programmatically built and operationalized security controls like Symantec Data Loss Prevention, while mentoring junior analysts and establishing standard operating playbooks. Before that, I supported identity security through Active Directory access audits, monitored real-time endpoint and email pathways using tools like Splunk and Symantec DLP rules, and maintained evidence for audit and compliance needs.

I balance technical depth with executive-ready communication—translating complex incidents into business-aligned updates for CISOs, Directors, and Regional Officers. My professional foundation is reinforced by Security+ and role-focused identity and vulnerability certifications, plus specialized training across incident handling and SIEM use cases.

Experience

Work history, roles, and key accomplishments

VC
Current

Consultant IV - Lead Responder

Verizon Communications

Nov 2017 - Present (8 years 7 months)

Serves as Lead Responder for managed security operations and incident response services for multiple global enterprise clients. Leads greenfield CSIRT setup, detection engineering in Microsoft Sentinel (analytics and playbooks), proactive threat hunting, and executive-facing incident advisory.

CO

Information Security Analyst

Convergys

Apr 2013 - Jun 2014 (1 year 2 months)

Monitors and triages security events across endpoints and email pathways, and supports audit/compliance documentation for incident logs and risk exceptions. Performs active directory access monitoring and analysis to identify anomalous account behavior and reconcile access matrix discrepancies.

Education

Degrees, certifications, and relevant coursework

St. Paul University Philippines logoSP

St. Paul University Philippines

Bachelor of Science in Information Technology, Information Technology

2007 - 2011

Earned a Bachelor of Science in Information Technology at St. Paul University in Quezon City from 2007 to 2011.

Tech stack

Software and tools used professionally

Get matched with your dream remote job

Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan