Incident Responder

Lintasarta

Jakarta Pusat

On-site

IDR 420,000,000 - 640,000,000

Full time

33 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Lintasarta seeks an experienced Incident Responder to join its SOC and lead response during security breaches. You will investigate complex incidents, contain threats, and eradicate attackers from enterprise environments.

You will coordinate with IT Infra and DR teams, perform cross-platform forensic analysis, and develop automated response playbooks for rapid containment.

Qualifications

  • 4–6+ years of technical cybersecurity experience with a focus on DFIR.
  • Proven incident responder on major incidents (ransomware, exfiltration, BEC).
  • Hands-on with forensic tools: KAPE, Velociraptor, Volatility, FTK Imager, EnCase, X-Ways.
  • Advanced experience with EDR/XDR platforms (CrowdStrike, Defender, Cortex XDR).
  • Strong log analysis skills using Splunk, KQL, or Elastic Security.
  • Scripting in Python, PowerShell, or Bash.
  • Knowledge of MITRE ATT&CK framework and NIST SP 800-61.
  • Ability to stay calm under pressure and communicate clearly.
  • Disciplined in following playbooks and documenting steps in tickets.

Responsibilities

  • Lead security incidents from initial confirmation through remediation.
  • Plan and execute targeted eradication, including removing artifacts.
  • Guide safe restoration with IT Infra and Disaster Recovery teams.
  • Perform forensic collection on Windows, Linux, and macOS endpoints.
  • Reconstruct multi-stage attack timelines across cloud, identity, network, and apps.
  • Conduct behavioral malware analysis to identify IoCs and C2.
  • Author RCA and PIR for leadership and auditors.
  • Turn findings into automated playbooks in SOAR.
  • Maintain chain-of-custody for regulatory disclosures or legal actions.
  • Participate in critical incident on-call rotation.

Skills

DFIR
Malware analysis
Threat hunting
EDR/XDR
Splunk
Scripting: Python
PowerShell/Bash
MITRE ATT&CK
Cloud telemetry

Tools

KAPE
Velociraptor
Volatility
FTK Imager
EnCase
X-Ways Forensics
CrowdStrike Falcon
Defender for Endpoint
Cortex XDR
Splunk (forensics)

Job description

We are looking for an Incident Responder to join our Security Operations Center (SOC) and lead the response when a security breach occurs. In this role, you will investigate major, complex incidents escalated from Tier-2 analysts, contain active threats, and ensure attackers are fully eradicated from enterprise environments.

Job Description
  • Lead security incidents from initial confirmation through successful remediation, executing rapid-containment playbooks under time pressure
  • Plan and execute targeted eradication, including removing web shells, persistence mechanisms, rogue admin accounts, and malware payloads
  • Partner with IT Infrastructure and Disaster Recovery teams to guide safe, verified restoration of business systems after a breach
  • Perform forensic collection on Windows, Linux, and macOS endpoints (memory captures, MFT extraction, and other system artifacts)
  • Reconstruct multi-stage attack timelines by correlating telemetry across cloud (AWS/Azure/GCP), identity, network firewall, and application layers
  • Conduct behavioral malware analysis to identify IoCs, C2 infrastructure, and attacker capabilities
  • Author Root Cause Analysis (RCA) and Post-Incident Reports (PIR) for executive leadership and compliance auditors
  • Turn findings from real incidents into automated response playbooks in the SOAR platform
  • Maintain strict chain-of-custody and evidentiary standards to support regulatory disclosures, insurance claims, or legal actions
  • Participate in the critical incident on-call rotation
Qualifications
  • Minimum 4–6+ years of technical cybersecurity experience, including at least 2–3 years dedicated to Digital Forensics and Incident Response (DFIR)
  • Proven experience as a primary responder on major incidents (e.g., ransomware, data exfiltration, business email compromise, cloud tenant hijacking)
  • Hands‑on experience with forensic tools such as KAPE, Velociraptor, Volatility, FTK Imager, EnCase, or X‑Ways Forensics
  • Advanced experience with EDR/XDR platforms (CrowdStrike Falcon, Microsoft Defender for Endpoint, Cortex XDR) for threat hunting, triage collection, and remote isolation
  • Strong log analysis skills using Splunk (SPL), Microsoft Sentinel (KQL), or Elastic Security
  • Scripting skills in Python, PowerShell, or Bash
  • Solid understanding of the MITRE ATT&CK framework and NIST SP 800-61
  • Ability to stay calm under pressure, make decisions independently, and communicate clearly with non-technical stakeholders
  • Disciplined in following playbooks and documenting every step in ticketing systems
  • Preferred certifications: GCIH, GCFA, GCFE, GCDA, or CSIH
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Defense Incident Responder (SOC)
Cyber Defense Incident Responder (SOC)

RecruiterPal • Indonesia

On-site
IDR 89,280,000 - 167,400,000
IT CYBERSECURITY
IT CYBERSECURITY

PT Dharma Satya Nusantara Tbk • Jakarta Timur

On-site
IDR 240,000,000 - 360,000,000
Threat Hunter & Incident Response Engineer
Threat Hunter & Incident Response Engineer

Jedi Solutions • Jakarta Utara

On-site
IDR 200,000,000 - 500,000,000
Senior Incident Response Lead: Threat Hunting & Forensics
Senior Incident Response Lead: Threat Hunting & Forensics

NTT America, Inc. • Jakarta Pusat

On-site
IDR 350,000,000 - 550,000,000
Manager, Defensive Security Operation
Manager, Defensive Security Operation

bank saqu • Indonesia

On-site
IDR 2,500,000,000 - 4,500,000,000
Threat Hunter & Incident Response Engineer
Threat Hunter & Incident Response Engineer

PT Cemerlang Tunggal Intikarsa (CTI Group Jakarta) • Jakarta Utara

On-site
IDR 400,000,000 - 700,000,000
Senior SOC (Tier 3) - Cyber Security Consultant
Senior SOC (Tier 3) - Cyber Security Consultant

EY • Daerah Khusus Ibukota Jakarta

On-site
IDR 20,000,000 - 30,000,000
TC - SOC Cybersecurity Consultant Manager
TC - SOC Cybersecurity Consultant Manager

EY • Daerah Khusus Ibukota Jakarta

On-site
IDR 279,000,000 - 390,600,000
Security Analyst L1
Security Analyst L1

Ensign InfoSecurity • Jakarta Pusat

On-site
IDR 66,960,000 - 133,920,000
Senior Incident Response Lead: Threat Hunting & Forensics
Senior Incident Response Lead: Threat Hunting & Forensics

Indodax - Indonesia Digital Asset Exchange • Jakarta Pusat

On-site
IDR 350,000,000 - 550,000,000