Incident Response Analyst
2 hours ago
The
Incident Response Analyst will provide detection, containment, and analysis of security events to protect the confidentiality, integrity, and availability of information systems per the firm's business objectives, regulatory requirements, and strategic goals.
Main responsibilities:
- Provide Tier 2 incident response services to the global organization on behalf of the Information Security Team
- Receive, process, and resolve tickets per defined SLA's
- Analyze information garnered from monitoring systems, operational incidents, and other sources to determine the scope and impact of potential security incidents, and process accordingly
- Critically assess current practices and provide feedback to management on improvement opportunities
- Assist with the design and implementation of threat detection and prevention solutions identified as necessary for the protection of the Firm's assets
- Effectively utilize common IR toolsets, platforms, and processes, such as SIEM, log management, packet capture, and breach detection systems
- Assist with forensic examinations and chain-of-custody procedures as directed by the Security Incident Response Engineers
- Provide input into standards and procedures
- Report compliance failures to management for immediate remediation
- Maintain assigned systems to ensure availability, reliability, and integrity, including the oversight of current and projected capacity, performance, and licensing
- Provide status reports and relevant metrics to the Security Operations Manager
- Contribute to the Firm's security-related information repositories and other marketing/awareness endeavors
- Assist with the preparation of internal training materials and documentation
- Participate in special projects as needed
Skills and experience:
- A bachelor's degree in Computer Science or strong equivalent experience
- GSEC, GCIH, GCFE, GREM, CISSP or SSCP certifications are desirable but not required
- Some professional experience in information security with a focus on incident response and forensics
- Foundational knowledge of IR concepts and best practices, including forensics and chain-of-custody
- Experience in common IR tools such as SIEM, log management, IDS, breach detection systems (APT/BDS/EDR), and packet capture
- Broad understanding of TCP/IP, DNS, common network services, and other foundational topics
- Working knowledge of malware detection, analysis, and evasion techniques
- Able to conduct static and dynamic analysis of malware to extract indicators of compromise, profile malware behavior, and provide recommendations for mitigating and detecting malware; able to analyze suspicious websites, script-based and malware code
- Experience in vulnerability management tools such as Qualys, Nessus, or other vulnerability scanning discovery tools
- Familiar with the threat landscape and the ability to adapt practices to evolving circumstances
- Identify, analyze, and report threats within the enterprise by using information collected from a variety of sources (IDS/IPS, SIEM, AV), to protect data and networks; implement techniques to hunt for known and unknown threats based on available threat intelligence reports and knowledge of the attacker's TTPs
- Able to gather and analyze facts, draw conclusions, define problems, and suggest solutions
- Maintain critical thinking and composure under pressure
- Strong written and oral communication skills; able to convey complex concepts to non-technical constituents
- Excellent written and spoken English communication skills
- Able to maintain focus without direct supervision
- Passionate in the practice and pursuit of IR excellence
- Can demonstrate a disciplined and rigorous approach to incident handling
- Willing to accommodate shift-based work for a global organization
- Provide exemplary customer service by striving for first-call resolution and demonstrating empathy, respect, professionalism, and expertise
- Experience in digital forensics on host or network and identification of anomalous behavior on the network or endpoint devices; familiar with host and network-based forensic tools such as EnCase, FTK, Sleuth Kit, X Ways, etc.
Reports to:
Manager, Security Operations
Position type:
Center Services
Development framework:
Specialist
-
Incident Response Specialist
2 weeks ago
Manila, National Capital Region, Philippines QBE Insurance Group Full time ₱50,000 - ₱100,000 per yearPrimary DetailsTime Type: Full timeWorker Type: EmployeeIncident Response Specialist, Group CyberReporting to the GSOC Lead, the Incident Response Specialist will be a key member of our rapidly growing Global Security Operations team. This dynamic role combines hands-on technical analysis with stakeholder engagement and incident coordination. The successful...
-
Cyber Incident Response Coordinator
2 hours ago
Manila, National Capital Region, Philippines Trend Micro Full time ₱1,200,000 - ₱2,400,000 per yearAs the number of cyberattacks and digital threats continue to grow, our world needs more passionate and innovative individuals who seek to be trailblazers in and shapers of the rapidly evolving cybersecurity landscape.At Trend Micro, we offer tremendous opportunities that will challenge and equip you to become engineered to do good in whatever path you take....
-
Enterprise Incident
3 hours ago
Manila, National Capital Region, Philippines FIS Full time ₱3,500,000 - ₱7,000,000 per yearPosition Type :Full timeType Of Hire :Experienced (relevant combo of work and education)Education Desired :Bachelor's DegreeGENERAL DUTIES & RESPONSIBILITIES • Manages global incidents across multiple data center environments to protect production systems critical to business success. • Ensures contractual service level agreements are met in support of...
-
Incident Manager
2 hours ago
Manila, National Capital Region, Philippines Luxoft Full time ₱900,000 - ₱1,200,000 per yearProject Description:DXC - a Fortune 500 global IT services leader. At DXC Technology we deliver the mission-critical IT services that move the world. Every day we use the power of technology to build better futures for our customers, colleagues, environment, and communities across the globe.We are flexible - we provide everything you need to comfortably work...
-
Incident Manager
55 minutes ago
Manila, National Capital Region, Philippines Nezda Global Full time ₱2,000,000 - ₱2,500,000 per yearAbout the CompanyJoin a leading financial institution that powers digital banking and financial services across the Philippines. You'll be part of a Service Management team that ensures continuity, stability, and rapid recovery during major incidents.About the RoleAs a Major Incident Manager, you'll be the single point of control during crisis situations —...
-
Incident Manager
2 weeks ago
Manila, National Capital Region, Philippines NYGC Services, Inc. Full time ₱900,000 - ₱1,200,000 per yearJob DescriptionProject Role : Incident MangerLocation : Alabang MuntinlupaWork setup : HybridRequirements :● Bachelor's Degree in an IT-related, Management, Engineering or Computer Science field● At least 3 years of experience in Incident Management, Problem and Change Management and IT Operations● Strong verbal and written communication skills, with...
-
Incident Management Lead
1 hour ago
Manila, National Capital Region, Philippines Nezda Global Full time ₱2,500,000 - ₱3,500,000 per yearKey Responsibilities:Lead and own incident management across the full lifecycle.Achieve SLAs and ensure timely resolution of all incidents.Lead escalation and stakeholder management.Identify incident patterns and invoke Major Incident processes when needed.Resolve incidents by coordinating the right technical teams.Drive or perform Root Cause Analysis (RCA)...
-
Senior Analyst, Cyber Security Operations
19 minutes ago
Manila, National Capital Region, Philippines Melco Resorts & Entertainment Full time ₱1,200,000 - ₱2,400,000 per yearREQ12454 Senior Analyst, Cyber Security Operations (Open)Position SummaryThe Senior Analyst, Cyber Security Operations acts as a critical escalation point within the Cyber Security Operations Center (CSOC) team. He/she is responsible for advanced analysis, incident handling, and in-depth investigations of security events. The analyst serves as a mentor to...
-
SOC Analyst- Philippines
49 minutes ago
Manila, National Capital Region, Philippines CyberMaxx Full time ₱960,000 - ₱1,440,000 per yearCyberMaxx is looking to add a Security Operations Center (SOC) Analyst to its top-tier team. The SOC Analyst works as part of a 24/7 operational team to perform first-level analysis and triage on incoming network, EDR, and SIEM alerts. The position works closely with the SOC Manager and shift leaders to prevent, detect, and respond to cyberattacks. THIS...
-
Program Manager Major Incident
1 hour ago
Manila, National Capital Region, Philippines Nordic Global Full time ₱1,200,000 - ₱3,600,000 per yearMake a difference. Be happy. Grow your career.The Major Incident Manager is responsible for ensuring that Major Incidents with potential or actual impact to patient care or major businesses SLAs are dealt with effectively, with minimum disruption to the production environments. The Major Incident Manager will also be expected to support other Service...