Incident Response Analyst

2 days ago


Manila, National Capital Region, Philippines Ciena Full time ₱1,200,000 - ₱2,400,000 per year

As the global leader in high-speed connectivity, Ciena is committed to a people-first approach. Our teams enjoy a culture focused on prioritizing a flexible work environment that empowers individual growth, well-being, and belonging. We're a technology company that leads with our humanity—driving our business priorities alongside meaningful social, community, and societal impact.

The Security Organization

The Security team at Ciena is a tightly knit group of skilled professionals who share the same passion for defending against cyber criminals. With the increase in volume and sophistication of cyber-crime, we are growing and have tons of exciting work planned.

Key Responsibilities

  • Incident Response Leadership
  • Lead the detection, containment, eradication, and recovery phases of cybersecurity incidents in collaboration with the SOC and other teams.
  • Coordinate and facilitate the Extended Security Incident Response Team (ESIRT) during high-severity incidents.
  • Develop and maintain incident response playbooks, procedures, and workflows to improve readiness and efficiency.
  • Digital Forensic Analysis
  • Perform host forensic analysis on Windows based systems.
  • Conduct network forensics by leveraging disparate log sources to include firewall logs, NetFlow, full packet capture, and various intrusion detection/prevention logs.
  • Leverage available tooling to contain and eradicate a threat actor's presence from the network when responding to live intrusion events.
  • Understand the capabilities of malicious binaries and scripts through usage of sandbox environments and static analysis.
  • Tabletop Exercises (TTXs)
  • Design, develop, and lead regular Tabletop Exercises (TTXs) to test and enhance the organization's incident response capabilities.
  • Evaluate the performance of participants during TTXs and provide actionable feedback for improvement.
  • Maintain detailed records and reports of TTX outcomes to guide future training and preparedness.
  • Proactive Threat Hunting
  • Conduct regular proactive threat-hunting activities to identify potential risks, vulnerabilities, and indicators of compromise (IOCs).
  • Utilize advanced tools, techniques, and threat intelligence to uncover malicious activity within the environment.
  • Collaborate with the SOC to refine detection mechanisms and improve response capabilities based on threat-hunting findings.
  • Collaboration and Communication
  • Work closely with the SOC, Security Architecture, IT, and other teams to enhance incident response and threat-hunting processes.
  • Serve as a liaison between technical teams and executive stakeholders during incidents, providing clear and concise updates.
  • Represent the organization in external threat-sharing communities and partnerships to stay ahead of emerging threats.
  • Process Development and Maintenance
  • Continuously improve incident response processes and threat-hunting methodologies.
  • Ensure compliance with relevant regulations, industry standards, and company policies in all incident response activities.
  • Maintain detailed and accurate documentation of incidents, investigations, and lessons learned.

Qualifications

  • Education:
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field or equivalent experience.
  • Relevant Certifications pertaining to DFIR are desirable but not required.
  • Experience:
  • 3-5+ years of experience in cybersecurity, with a focus on incident response and threat hunting.
  • Experience in Digital Forensics and Incident Response ("DFIR") consulting or IR within a global organization is highly desirable.
  • Skills
  • Strong knowledge of incident response methodologies, threat-hunting, cyber threat intelligence research, and cybersecurity tools (e.g., SIEM, EDR, forensic tools).
  • Familiarity with digital forensics and Windows based artifacts.
  • Strong understanding of attacker Tactics, Techniques, and Procedures ("TTPs").
  • Proficiency in scripting and automation (e.g., Python, PowerShell) is a plus.
  • Strong analytical, communication, and organizational skills.
  • Other Requirements:
  • Ability to work effectively in a fast-paced, 24/7/365 environment, including participating in on-call rotations as needed.
  • Strong problem-solving skills with a focus on collaboration and teamwork.
  • Experience designing and leading Tabletop Exercises is a significant advantage.
LI-SM #LI-Remote #LI-Hybrid

Not ready to apply? Join our

Talent Community

to get relevant job alerts straight to your inbox.

At Ciena, we are committed to building and fostering an environment in which our employees feel respected, valued, and heard. Ciena values the diversity of its workforce and respects its employees as individuals. We do not tolerate any form of discrimination.

Ciena is an Equal Opportunity Employer, including disability and protected veteran status.

If contacted in relation to a job opportunity, please advise Ciena of any accommodation measures you may require.



  • Manila, National Capital Region, Philippines Ciena Full time ₱1,200,000 - ₱2,400,000 per year

    As the global leader in high-speed connectivity, Ciena is committed to a people-first approach. Our teams enjoy a culture focused on prioritizing a flexible work environment that empowers individual growth, well-being, and belonging. We're a technology company that leads with our humanity—driving our business priorities alongside meaningful social,...


  • Manila, National Capital Region, Philippines Five9 Full time ₱900,000 - ₱1,200,000 per year

    Join us in bringing joy to customer experience. Five9 is a leading provider of cloud contact center software, bringing the power of cloud innovation to customers worldwide. Living our values everyday results in our team-first culture and enables us to innovate, grow, and thrive while enjoying the journey together. We celebrate diversity and foster an...


  • Manila, National Capital Region, Philippines DTCC Full time $80,000 - $120,000 per year

    DescriptionAre you ready to make an impact at DTCC?Do you want to work on innovative projects, collaborate with a dynamic and supportive team, and receive investment in your professional development? At DTCC, we are at the forefront of innovation in the financial markets. We're committed to helping our employees grow and succeed. We believe that you have the...


  • Manila, National Capital Region, Philippines Trend Micro Full time $100,000 - $120,000 per year

    As the number of cyberattacks and digital threats continue to grow, our world needs more passionate and innovative individuals who seek to be trailblazers in and shapers of the rapidly evolving cybersecurity landscape.At Trend Micro, we offer tremendous opportunities that will challenge and equip you to become engineered to do good in whatever path you take....


  • Manila, National Capital Region, Philippines FIS Full time

    Position Type :Full timeType Of Hire :Experienced (relevant combo of work and education)Education Desired :Bachelor of Commerce/BusinessAs the world works and lives faster, FIS is leading the way. Our fintech solutions touch nearly every market, company and person on the planet. Our teams are inclusive and diverse. Our colleagues work together and celebrate...

  • Incident Manager

    2 weeks ago


    Manila, National Capital Region, Philippines Luxoft Full time ₱900,000 - ₱1,200,000 per year

    Project Description:DXC - a Fortune 500 global IT services leader. At DXC Technology we deliver the mission-critical IT services that move the world. Every day we use the power of technology to build better futures for our customers, colleagues, environment, and communities across the globe.We are flexible - we provide everything you need to comfortably work...

  • Incident Manager

    1 week ago


    Manila, National Capital Region, Philippines Nezda Global Full time ₱2,000,000 - ₱2,500,000 per year

    About the CompanyJoin a leading financial institution that powers digital banking and financial services across the Philippines. You'll be part of a Service Management team that ensures continuity, stability, and rapid recovery during major incidents.About the RoleAs a Major Incident Manager, you'll be the single point of control during crisis situations —...

  • L2 SOC Analyst

    2 days ago


    Manila, National Capital Region, Philippines Emapta Global Full time ₱60,000 - ₱120,000 per year

    Job Description:As a Level 2 SOC Analyst, you will lead threat detection, investigation, and incident response efforts using tools like Sentinel and Defender. You'll mentor L1 analysts, refine security rules, and contribute to the ongoing evolution of cybersecurity frameworks, making an impact in both day-to-day operations and long-term...


  • Manila, National Capital Region, Philippines Melco Resorts & Entertainment Full time ₱1,200,000 - ₱2,400,000 per year

    REQ12454 Senior Analyst, Cyber Security Operations (Open)Position SummaryThe Senior Analyst, Cyber Security Operations acts as a critical escalation point within the Cyber Security Operations Center (CSOC) team. He/she is responsible for advanced analysis, incident handling, and in-depth investigations of security events. The analyst serves as a mentor to...


  • Manila, National Capital Region, Philippines QBE Insurance Group Limited Full time ₱40,000 - ₱120,000 per year

    Primary DetailsTime Type: Full timeWorker Type: EmployeeWe are seeking a highly skilled and motivated Senior Security Analyst to join our Global Security Operations Centre based in the Philippines. Reporting to the Global Security Operations Centre Lead, the Senior Security Analyst will be a key member of our rapidly growing Global team. This role is...