Incident Response Analyst

4 weeks ago


Manila, National Capital Region, Philippines Baker & McKenzie Rechtsanwaltsgesellschaft mbH Full time

The Incident Response Analyst will provide detection, containment, and analysis of security events to protect the confidentiality, integrity, and availability of information systems in accordance with the firm's business objectives, regulatory requirements, and strategic goals.

Responsibilities
  • Provide Tier 2 incident response services to the global organization on behalf of the Information Security Team
  • Receive, process, and resolve tickets per defined SLA's
  • Analyze information garnered from monitoring systems, operational incidents, and other sources to determine the scope and impact of potential security incidents, and process accordingly
  • Critically assess current practices and provide feedback to management on improvement opportunities
  • Assist with the design and implementation of threat detection and prevention solutions identified as necessary for the protection of Firm assets
  • Effectively utilize common IR toolsets, platforms, and processes, such as SIEM, log management, packet capture, and breach detection systems
  • Assist with forensic examinations and chain-of-custody procedures as directed by the Security Incident Response Engineers
  • Provide input into standards and procedures
  • Report compliance failures to management for immediate remediation
  • Maintain assigned systems to ensure availability, reliability, and integrity, including the oversight of current and projected capacity, performance, and licensing
  • Provide status reports and relevant metrics to the Security Operations Manager
  • Contribute to the Firm's security-related information repositories and other marketing/awareness endeavors
  • Participate in special projects as needed

Skills and Experience

Education

  • Possess a Computer Science Bachelor's Degree or substantial equivalent experience

Special Requirements, Licenses, and Certifications:

  • GCFE, GCFA, GCTI, GREM, GPEN, GWAPT
  • CISSP or SSCP desired

Experience

  • Some professional experience in information security with a focus on incident response and forensics
  • Foundational knowledge of IR concepts and best practices, including forensics and chain-of-custody
  • Experience with common IR tools such as SIEM, log management, IDS, breach detection systems (APT/BDS/EDR), and packet capture.
  • Broad understanding of TCP/IP, DNS, common network services, and other foundational topics
  • Working knowledge of malware detection, analysis, and evasion techniques
  • Able to conduct static and dynamic analysis of malware to extract indicators of compromise, profile malware behavior, and provide recommendations for mitigating and detecting malware
  • Able to analyze suspicious websites, script-based and malware code
  • Experience with vulnerability management tools such as Qualys, Nessus, or other vulnerability scanning discovery tools
  • Broad familiarity with the threat landscape and the ability to adapt practices to evolving circumstances
  • Identify, analyze, and report threats within the enterprise by using information collected from a variety of sources (IDS/IPS, SIEM, AV), to protect data and networks. Implement techniques to hunt for known and unknown threats based on available threat intelligence reports and knowledge of the attacker's TTPs
  • Able to gather and analyze facts, draw conclusions, define problems, and suggest solutions
  • Maintain critical thinking and composure under pressure
  • Strong written and oral communication skills. Ability to convey complex concepts to non-technical constituents. Proficiency in oral and written English
  • Capable of assisting with the preparation of internal training materials and documentation
  • Able to be productive and maintain focus without direct supervision
  • Passionate in the practice and pursuit of IR excellence
  • Can exhibit a disciplined and rigorous approach to incident handling
  • Willing to accommodate shift-based work for a global organization
  • Provide exemplary customer service by striving for first-call resolution and demonstrating empathy, respect, professionalism, and expertise
  • Experience with digital forensics on host or network and identification of anomalous behavior on the network or endpoint devices. Familiar with host and network-based forensic tools such as EnCase, FTK, Sleuth Kit, X Ways, etc.
#J-18808-Ljbffr

  • Manila, National Capital Region, Philippines Monroe Consulting Group Full time

    Role PurposeThe Incident Response Analyst is responsible for providing Tier 2 detection, containment, and analysis of security events. This role helps protect the confidentiality, integrity, and availability of information systems in alignment with the organization's business objectives, regulatory requirements, and strategic goals.Key...


  • Manila, National Capital Region, Philippines Metropolitan Bank & Trust Company Full time

    Be #InGoodHands with MetrobankHere at Metrobank, we don't simply hire employees-we hone future leaders. We provide opportunities that enhance your skills and unlock your talents, helping you evolve into a well-rounded individual. We supply you with all the pieces you need to do your best work, unleashing your full potential to help you secure your future and...

  • Incident Manager

    2 hours ago


    Manila, National Capital Region, Philippines TENTEN Partners Full time

    OverviewJoin us in partnership with a leading financial institution to hire an Incident Manager responsible for safeguarding mission-critical systems and ensuring seamless operations.You will serve as the central point of contact for managing major incidents, leading high-pressure recovery efforts across cross-functional teams. Your leadership will ensure...


  • Manila, National Capital Region, Philippines Michael Page Full time

    Join a pioneer team Enjoy a market-aligned salary & benefits About Our Client The client is a growing cybersecurity company providing services to clients all over the globe. Job Description Leads advanced threat detection, investigation, and response activities across cloud, endpoint, and web application layers. Performs in-depth analysis of...

  • Security Analyst

    4 weeks ago


    Manila, National Capital Region, Philippines blueAPACHE Full time

    About usblueAPACHE is an Australian owned award-winning Managed Service Provider, recognised for the 5th year running, as Mid-Market Partner of the Year at the ARN Innovation Awards.We pride ourselves on being a genuinely great place to work, with a vibrant culture, clear vision, and strong leadership. When joining blueAPACHE, you are joining an organisation...


  • Manila, National Capital Region, Philippines MERALCO Full time

    SPECIFIC DUTIES & RESPONSIBILITIES:1. Conduct assessment of security incidents and investigate data breaches and privacy-related complaints,including review of all relevant documentation in light of the incident.2. Submit to the PIM Head a report with detailed findings and recommendations on the DP issues arisingfrom the incidents and data breaches.3....

  • Security Analyst

    2 hours ago


    Manila, National Capital Region, Philippines Verifone Full time

    Job SummaryThe Security Analyst will be responsible for monitoring our security infrastructure, identifying and responding to security threats, managing vulnerabilities, and contributing to the continuous improvement of our overall security posture. This role is crucial in safeguarding our organization's systems, data, and reputation against an ever-evolving...

  • SOC Analyst

    4 weeks ago


    Manila, National Capital Region, Philippines Cato Networks Full time

    At Cato Networks, we have a team of veteran technology and security experts, looking to change the world. We believe that while good engineers can create simple solutions for complex problems, great engineers can make complex problems – simple.Welcome to the future of cloud networking and securityCato Networks is the first company to converge enterprise...


  • Manila, National Capital Region, Philippines SecureOps Full time

    OverviewL1 Cyber Security Analyst at SecureOps — This role focuses on analyzing and escalating cyber-security alerts within SIEM tools such as ArcSight, Splunk, and QRadar. The Analyst handles incident follow-up, suggests process improvements, and supports basic automation. Training is provided, with detailed documentation available.Schedule: This role...


  • Manila, National Capital Region, Philippines Kroll Full time

    Our professionals balance analytical skills, deep market insight and independence to deliver solid, defensible analysis and practical advice to our clients. As an organization, we think globally. We create transparency in an opaque world, and we encourage our people to do the same. That means when you take your place on our team, you'll discover a supportive...