APAC Cyber Inc. Res. Specialist

Richemont Iberia SL

Hong Kong

On-site

HKD 900,000 - 1,300,000

Full time

11 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Richemont Iberia SL in Hong Kong seeks a Senior Associate / Technical Lead, Cybersecurity Incident Response. You will operate at Level 3, escalating complex incidents and leading advanced investigations across endpoint, network, identity, cloud, and email environments.

You will mentor L1/L2 analysts, deploy detections, and strengthen playbooks, while contributing to threat hunting and automation. Fluency in English is essential; 5–8+ years in SOC/IR and strong MITRE ATT&CK knowledge are required.

Qualifications

  • 5–8+ years of hands-on cybersecurity experience.
  • Advanced knowledge of networking, operating systems, identity, cloud environments, and enterprise infrastructure.
  • Experience with attacker techniques and MITRE ATT&CK framework.
  • Proficiency with analytics languages such as SPL, KQL, SQL.
  • Experience scripting with Python/PowerShell/Bash is advantageous.
  • Ability to investigate ambiguous or complex cybersecurity incidents independently.

Responsibilities

  • Act as the L3 technical escalation point for complex and high‑impact cybersecurity incidents.
  • Lead advanced incident investigations and determine attack scope, root cause, attacker techniques, affected assets, identities, and potential business impact.
  • Perform advanced forensic analysis, including evidence collection, timeline reconstruction, endpoint analysis, and suspicious file analysis.
  • Lead proactive threat hunting activities and develop, validate detections across SIEM/EDR/identity/cloud platforms.
  • Mentor L1/L2 analysts and review investigations for quality and accuracy.

Skills

Incident response
Threat hunting
Digital forensics
SIEM / SOAR
EDR/XDR
MITRE ATT&CK
KQL / SPL / SQL
Python / PowerShell
Cloud security
Networking knowledge
English communication

Tools

SIEM
SOAR
EDR/XDR
IDS/IPS
NDR
Cloud security platforms
Identity security
Email security

Job description

HOW WILL YOU MAKE AN IMPACT?

As a Senior Associate / Technical Lead, Cybersecurity Incident Response, you will operate at the Level 3 (L3) layer of our Cybersecurity Incident Response function and act as a key technical escalation point for complex, high-impact, and unusual cybersecurity incidents affecting the Group and its Maisons.

You will lead advanced investigations across endpoint, network, identity, cloud, email, and application environments, working closely with Cyber Security, IT, Infrastructure, Cloud, Identity, Risk, Legal, and other relevant teams to understand the scope, root cause, attack techniques, and potential impact of cybersecurity incidents.

During significant incidents, you may act as the technical incident lead, providing direction on investigation, containment, remediation, and recovery activities.

Beyond incident response, you will help strengthen our overall detection and response capability through proactive threat hunting, detection enhancement, forensic analysis, automation, and continuous improvement of our tools, playbooks, and investigation processes.

You will also play an important role in maintaining the technical quality of our Cybersecurity Incident Response service by reviewing complex investigations, validating findings and conclusions, identifying investigation gaps, and helping ensure that incident cases are complete, evidence-based, technically accurate, and consistently documented.

As a senior technical reference within the team, you will support and mentor L1 and L2 analysts, provide hands‑on guidance during challenging investigations, and share your experience through case reviews, technical training, and knowledge‑sharing activities.

In this role, you will:

  • Act as the L3 technical escalation point for complex and high‑impact cybersecurity incidents.
  • Lead advanced incident investigations and determine attack scope, root cause, attacker techniques, affected assets, identities, and potential business impact.
  • Perform advanced analysis across endpoint, network, identity, cloud, email, and application telemetry.
  • Lead technical incident response activities, including investigation, containment, eradication, remediation, and recovery recommendations.
  • Perform advanced forensic analysis, including evidence collection, timeline reconstruction, endpoint analysis, and suspicious file analysis.
  • Lead proactive and hypothesis‑driven threat hunting activities based on emerging threats, threat intelligence, and attacker behaviours.
  • Develop, enhance, and technically validate security detections across SIEM, EDR/XDR, identity, cloud, network, and other security platforms.
  • Translate incident and threat hunting findings into improved detections, monitoring coverage, investigation procedures, and response capabilities.
  • Perform technical quality reviews of L1 and L2 investigations, including investigation approach, evidence, scope assessment, conclusions, escalation decisions, and recommended actions.
  • Review significant incident cases and reports to ensure findings are complete, technically accurate, evidence‑based, and aligned with established investigation standards.
  • Identify recurring investigation or quality gaps and help improve playbooks, SOPs, documentation standards, analyst training, and investigation methodologies.
  • Support threat intelligence, purple‑team, and threat‑informed defence activities to improve detection and response effectiveness.
  • Develop or support scripts, queries, SOAR workflows, and automation to improve investigation efficiency.
  • Provide technical guidance, mentoring, and hands‑on support to L1 and L2 analysts.
  • Contribute to Cyber Security projects and initiatives with implications for Incident Response, threat detection, and security operations.
HOW WILL YOU EXPERIENCE SUCCESS WITH US?

You will be successful in this role if you combine strong hands‑on technical investigation skills with the ability to lead complex investigations, challenge assumptions, maintain high investigation standards, and communicate clearly with both technical and non‑technical stakeholders.

You will bring:

  • Typically 5–8+ years of relevant cybersecurity experience, including hands‑on experience in Security Operations, Incident Response, Threat Hunting, Digital Forensics, or related disciplines.
  • Advanced knowledge of networking, operating systems, identity, cloud environments, and enterprise infrastructure.
  • Strong experience investigating attacker techniques such as credential access, privilege escalation, persistence, defence evasion, lateral movement, command and control, and data exfiltration.
  • Strong practical experience analysing endpoint, network, identity, cloud, email, and application telemetry and correlating activity across multiple data sources.
  • Practical experience with digital forensic investigation techniques, including evidence collection, timeline analysis, endpoint artefacts, suspicious file analysis, and root cause analysis.
  • Strong hands‑on experience with security technologies such as SIEM, SOAR, EDR/XDR, IDS/IPS, NDR, mail security, identity security, and cloud security platforms.
  • Experience developing, improving, or validating security detections, investigation queries, threat hunting methodologies, and response procedures.
  • Strong understanding of attacker tactics, techniques, and procedures, including practical use of frameworks such as MITRE ATT&CK.
  • Experience using analytics and investigation languages such as SPL, KQL, SQL, or equivalent.
  • Experience with scripting or automation using Python, PowerShell, Bash, or equivalent would be an advantage.
  • The ability to independently investigate ambiguous, unfamiliar, or technically complex cybersecurity incidents where established playbooks may not provide the full answer.
  • Strong technical quality‑assurance skills, with the ability to review investigations critically, identify gaps, and ensure conclusions are supported by evidence.
  • Strong analytical, problem‑solving, and communication skills.
  • Experience providing technical guidance, mentoring, or support to less experienced analysts.
  • Experience working in a large, multinational, or distributed enterprise environment would be a strong advantage.
  • Excellent proficiency in English. Additional languages would be an asset.

Relevant industry certifications such as CISSP, GCIH, GCIA, GCFA, GCFE, GNFA, GREM, GCTI, OSCP, SC-200, or equivalent qualifications would be considered a strong asset.

WHAT MAKES OUR GROUP DIFFERENT?

Our true power does not lie in our similarities but in the rich diversity of our arts, cultures, and human skills, as well as our specific ability to foster untapped potential.

  • We value freedom, collegiality, loyalty, and solidarity.
  • We foster empathy, curiosity, courage, humility, and integrity.
  • We care for the world we live in.
YOUR JOURNEY WITH US

Our recruitment process is designed to give both you and the team an opportunity to understand whether the role is the right fit.

You can expect the process to include:

  • An initial conversation with our Talent Acquisition team to understand your experience, motivation, and expectations.
  • An interview with the Hiring Manager to discuss the role, team, Cybersecurity Incident Response operating model, and your previous experience.
  • A technical interview or practical discussion with members of the Cyber Security team, focused on areas such as incident investigation, threat hunting, detection, forensic analysis, and how you would approach complex security scenarios.
  • A final conversation with relevant stakeholders to discuss team fit, ways of working, and the broader organisation.

Throughout the process, you will have the opportunity to learn more about the team, the challenges we are solving, and how this L3 technical leadership role contributes to strengthening our Cybersecurity Incident Response capability.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Incident Responder, Hong Kong
Senior Incident Responder, Hong Kong

Leadingnation • Hong Kong

On-site
HKD 600,000 - 800,000
DFIR Specialist / Senior SOC Analyst (Hong Kong)
DFIR Specialist / Senior SOC Analyst (Hong Kong)

THEOS • Hong Kong

On-site
HKD 600,000 - 900,000
Junior Incident Responder, Hong Kong
Junior Incident Responder, Hong Kong

Leadingnation • Hong Kong

On-site
HKD 240,000 - 360,000
Cyber Incident Responder
Cyber Incident Responder

Amaris Consulting • Hong Kong

On-site
HKD 900,000 - 1,300,000
International community
Robust training system
Team events & ESG initiatives
Cybersecurity Analyst
Cybersecurity Analyst

Janestreet • Hong Kong

On-site
HKD 500,000 - 800,000
Cybersecurity and Information Security Analyst
Cybersecurity and Information Security Analyst

Not Another Headhunting Company • Hong Kong

On-site
HKD 420,000 - 780,000
Assurance - Forensics - Cyber Incident Response - Manager - Ernst & Young - Hong Kong
Assurance - Forensics - Cyber Incident Response - Manager - Ernst & Young - Hong Kong

EY • Hong Kong

On-site
HKD 800,000 - 1,100,000
Security IT Support Engineer
Security IT Support Engineer

Crypto.com • Hong Kong

On-site
HKD 240,000 - 320,000
Competitive salary
Medical insurance for dependents
Generous annual leave
+3
Assistant Manager - Cyber Security Ops - Tech Risk & Security Assessment
Assistant Manager - Cyber Security Ops - Tech Risk & Security Assessment

New Galaxy Entertainment 2006 Company Limited • Hong Kong

On-site
HKD 420,000 - 700,000
Digital Core - Security Transformation Manager/Senior Manager
Digital Core - Security Transformation Manager/Senior Manager

Accenture • Hong Kong

On-site
HKD 900,000 - 1,200,000