Cyber Incident Response Analyst

2 weeks ago


Manila, National Capital Region, Philippines JTI Full time

Search by keyword and location and click "create alert" to receive your job alerts by email:

Select how often (in days) to receive an alert:

Professional area: Information Technology

Contract type: Permanent

Professional level: Experienced

Location:

Manila, PH, 00000

We're JTI, Japan Tobacco International, and we believe in freedom.

We think that the possibilities are limitless when you're free to choose. We've spent the last 20 years innovating and creating new and better products for our consumers to choose from. It's how we've grown to be present in 130 countries, and how we've grown from 40 to 4,000+ employees in the Philippines since 2009.

But our business isn't just business, our business is our people. Their talent. Their potential. We believe that when they're free to be themselves, to grow, travel and develop, amazing things can happen for our business. That's why our employees, from around the world, choose to be a part of JTI. It's why 9 out of 10 would recommend us to a friend, and why we've been recognized as INVESTORS IN PEOPLE in the Philippines

It's the perfect moment for you to #JoinTheIdea. We're opening our Global Business Service center in the heart of BGC Manila and looking for more than 300 bright minds to join a global multinational with an exciting start-up vibe.

Local applicants only.
Department: Global IT
Location: Taguig, Philippines
Reporting to: Cyber Detection & Response Manager

With the growing number of Security Incidents and in order to improve Incident Response process, the Security Operations Center needs to assign a Tier 1 Cyber SOC Incident Response Analyst who will be able to quickly identify the true cause of a cyber incident, figure out span of a compromise and provide practical advice to fix and prevent the threats and if required, to assist with recovering critical data and services. Within its main functions, this person will:

  • Act as first line of defense handling low and medium security incidents.
  • Raise to the Tier 2 and Tier 3 Cyber Incident Response Managers high severity incidents, providing information about first analysis and contribute to the resolution.
  • Follow IR security standards and playbooks, properly document IR actions and coordinate IR tasks with other functions within SOC and rest of the organization.

What will you do?

  • Respond to low and medium Security Incidents, mainly but not exclusively to Phishing, Malware and Web Attacks related Security Incidents.
  • Assess, triage, categorize and prioritize Security Incidents and raise to higher tiers when severity is elevated.
  • Derive immediate mitigation measures for containment, eradication, and recovery of Security Incident in line with JTI internal SLAs and track progress.
  • Coordinate Incident Response taskforces with different IT functions and end users according to established playbooks.
  • Estimate the scope of impacted asset , ensure that remediation is properly address to all scope identified during the Analysis stage.
  • Collect forensics malicious payloads, forensics artifacts and IOCs according to JTI SOPs and for further analysis by JTI SOC personnel.
  • Concisely summarize the analysis and actions carried out during the Incident Response handling in the Review phase and provide lessons learn recommendations if any.
  • Provide basic malware analysis using sandboxing solutions.
  • Support Security Incident Managers during relevant security incidents by following their ad-hoc instructions during incident handling.
  • Contribution to the creation, maintenance and improvement of Security Incident playbook and SOPs in scope of Incident Response daily activities abd provide support on reporting activities
  • Monitor Security Industry trends on new threats and share knowledge with rest of the team.

Who are we looking for?

  • University degree in Computer Sciences, Information Systems, or related field or relevant experience
  • 1 year of experience in Information Security or 2 years of experience in system or network administration.
  • 1 year working within a SOC team preferred
  • Knowledge of information security principles and best practices.
  • Familiarity with tools and techniques used in incident detection and response.
  • Experience with Microsoft security products preferred E.g. Microsoft Defender for Endpoint.
  • Fluent English written and spoken skills.
  • Analytical/problem solving ability
  • Understanding of fundamentals of OS and Networking
  • Good understanding EDR/XDR solutions, SIEM platforms and Ticketing systems
  • Knowledge of security santandar (e.g. NIST and MITRE ATT&CK framework
  • Ability to work under constantly evolving conditions and tight deadlines
  • Communications skills and capable of focusing on the important and the details.
  • Scripting abilities are a plus (Powershell or Python desirable)
  • Certifications (any security certification like but not exclusive to the following): CEH, CND, CSA, CompTIA Security+

What's in it for you?


• Work at our JTI Global Business Services office in McKinley West Campus, Taguig.

• Be part of a truly international and diverse company with over 40,000 employees in 130 countries.

• Experience the culture of an Investors in People certified company

• Find out most of our employees recommend us to a friend.

• Understand why most our our employees say they feel free to be themselves.

What are the next steps?

Thank you very much for your interest in the role. You are welcome to apply. We will make sure every candidate will receive a reply within 2 weeks after the application deadline.

#J-18808-Ljbffr

  • Manila, National Capital Region, Philippines JT International S.A. Full time

    We're JTI, Japan Tobacco International, and we stand for freedom.We believe that opportunities are boundless when individuals have the freedom to make choices. Over the past two decades, we have dedicated ourselves to innovating and developing new and improved products for our customers to select from. This approach has driven our expansion to 130 countries...


  • Manila, National Capital Region, Philippines JT International S.A. Full time

    We're JTI, Japan Tobacco International, and we stand for freedom.We believe that opportunities are boundless when individuals have the freedom to make choices. Over the past two decades, we have dedicated ourselves to innovating and developing new and improved products for our customers to select from. This approach has driven our expansion to 130 countries...


  • Manila, National Capital Region, Philippines Willis Towers Watson Full time

    The Incident Response Group (IRG) is a key team within Service Desk responsible for the incident management and other ITIL processes. The Incident Response Group Analyst delivers improved client experiences by managing the end to end incident management process and identifying and fixing process gaps, with the aim to deliver faster response times and quicker...


  • Manila, National Capital Region, Philippines Cyber Crime Full time

    Kroll As the leading independent provider of risk and financial advisory solutions, Kroll leverages our unique insights, data and technology to help clients stay ahead of complex demands. Click for more details. View company page In a world of disruption and increasingly complex business challenges, our professionals bring truth into focus with the Kroll...


  • Manila, National Capital Region, Philippines Kroll Full time

    Kroll As the leading independent provider of risk and financial advisory solutions, Kroll leverages our unique insights, data and technology to help clients stay ahead of complex demands. Click for more details. View company page We are looking for an experienced SOC Analyst to join our thriving Cyber Team.You will be joining the Security Operations team...


  • Manila, National Capital Region, Philippines Kroll Full time

    We are looking for an experienced SOC Analyst to join our thriving Cyber Team. You will be joining the Security Operations team within Cyber Risk. This role will be Hybrid. Our lovely offices in Manila 7/F, One Ayala Tower 2, EDSA, Corner Ayala Ave, Makati, Metro Manila, Philippines. Day-to-day responsibilities: To be a key member of the SOC and...


  • Manila, National Capital Region, Philippines Adlumin Inc. Full time

    About Adlumin:What you can't see poses the most significant risk to your organization. Your exposures lurk in the cloud, hybrid environments, and the darknet. There are countless gaps where threats can hide before they lead to business-disrupting events like ransomware shutdowns or massive data breaches.Adlumin Inc. is a patented, cloud-native Managed...


  • Manila, National Capital Region, Philippines WTW Full time

    The RoleAs a Threat Intelligence Analyst, you have a pivotal role in operationalizing threat intelligence within our organization. By monitoring and analyzing the tactics, techniques, and procedures (TTPs) of threat actors, campaigns, and malware, you generate actionable intelligence to safeguard our systems and data. This position involves producing timely...


  • Manila, National Capital Region, Philippines QBE Insurance Group Full time

    Cyber Security Risk and Governance Analyst page is loaded Cyber Security Risk and Governance Analyst Apply locations PHI - Manila Cebu, Philippines time type Full time posted on Posted 4 Days Ago job requisition id Primary DetailsTime Type: Full timeWorker Type: EmployeePrimary Responsibilities• Working experience of security design/architecture for new...


  • Manila, National Capital Region, Philippines Kroll Full time

    Associate - Security Operations Centre Analyst, Cyber Risk Kroll As the leading independent provider of risk and financial advisory solutions, Kroll leverages our unique insights, data and technology to help clients stay ahead of complex demands. Click for more details. View company page In a world of disruption and increasingly complex business...


  • Manila, National Capital Region, Philippines Willis Towers Watson Full time

    The Role As a Threat Intelligence Analyst, you will play a crucial role in operationalising threat intelligence within our organisation. By tracking and analysing the tactics, techniques, and procedures (TTPs) of threat actors, campaigns, and malware, you will produce actionable intelligence to protect our systems and data. This role involves generating...


  • Manila, National Capital Region, Philippines ePLDT, Inc. Full time

    JOB DESCRIPTION: Assists the IR Lead during engagements and mentoring/training junior analysisContinues to focus on process improvement for the customer-facing incident response servicesConducts host-based analysis and forensic functions on Windows, Linux, and Mac OS X systemsReviews firewall, web, database, and other log sources to identify evidence and...


  • Manila, National Capital Region, Philippines ePLDT, Inc. Full time

    JOB DESCRIPTION: Assists the IR Lead during engagements and mentoring/training junior analysisContinues to focus on process improvement for the customer-facing incident response servicesConducts host-based analysis and forensic functions on Windows, Linux, and Mac OS X systemsReviews firewall, web, database, and other log sources to identify evidence and...


  • Manila, National Capital Region, Philippines Willis Towers Watson Full time

    The Cyber Defence Assurance Specialist plays a pivotal role within our Global Information and Cyber Security Defence (ICSD) function, ensuring the highest standards of cyber defence across the organisation. This role demands a proactive approach to supporting our global incident response teams, providing an essential quality assurance function with a global...


  • Manila, National Capital Region, Philippines Financial Times group Full time

    About UsAcross the FT Group, our people are united by a mission to deliver world-class information, news and services to our global audiences. We're a digital-first organisation made up of journalists, technologists, product managers, event planners, strategists, commercial and finance experts, marketing and communications specialists - and much more. Our...

  • Associate, Cyber Risk

    2 weeks ago


    Manila, National Capital Region, Philippines Kroll Full time

    In a world of disruption and increasingly complex business challenges, our professionals bring truth into focus with the Kroll Lens. Our sharp analytical skills, paired with the latest technology, allow us to give our clients clarity—not just answers—in all areas of business. We embrace diverse backgrounds and global perspectives, and we cultivate...


  • Manila, National Capital Region, Philippines 20 DexCom Philippines Inc Full time

    Associate IOC Major Incident Analyst page is loaded Associate IOC Major Incident Analyst Apply remote type Flex locations Manila, Philippines Cebu, Philippines time type Full time posted on Posted Yesterday job requisition id JR105817 About DexcomFounded in 1999, Dexcom, Inc. (NASDAQ: DXCM), develops and markets Continuous Glucose Monitoring (CGM) systems...

  • CyberSecurity Analyst

    2 weeks ago


    Manila, National Capital Region, Philippines Concentrix Philippines Full time

    Are you ready to POWER UP your skills? Take the leap and join Concentrix's League of TOP-NOTCH TALENTS Prepare for an Extra-Ordinary Journey where you not only Collaborate with Industry Champions but also immerse yourself in an Innovative Workplace filled with Laughter, Continuous Learning, and Limitless Opportunities. Join the Leading Global Provider of CX...

  • CyberSecurity Analyst

    2 weeks ago


    Manila, National Capital Region, Philippines Concentrix Philippines Full time

    Are you ready to POWER UP your skills? Take the leap and join Concentrix's League of TOP-NOTCH TALENTS Prepare for an Extra-Ordinary Journey where you not only Collaborate with Industry Champions but also immerse yourself in an Innovative Workplace filled with Laughter, Continuous Learning, and Limitless Opportunities. Join the Leading Global Provider of CX...


  • Manila, National Capital Region, Philippines Damco Spain SL Full time

    Senior Security Operation Center Manager Introduction:Maersk is a global leader in integrated logistics and have been industry pioneers for over a century. Through innovation and transformation we are redefining the boundaries of possibility, continuously setting new standards for efficiency, sustainability, and excellence.At Maersk, we believe in the power...