Incident Response Lead

Axonect

Kuala Lumpur

On-site

MYR 240,000 - 360,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Axiata Group is seeking an Incident Response Lead to orchestrate cyber incident detection, investigation, containment, eradication, recovery, and post-incident activities across the Axiata Cyber Fusion Center. You will coordinate with SOC, Threat Intelligence, engineering teams, and external partners to strengthen cyber resilience.

Lead incident response programs, develop playbooks, and drive improvements in detection, forensics, and hunting using MITRE ATT&CK.

Qualifications

  • Bachelor's degree in Cyber Security, Information Security, Computer Science, Information Technology, or related discipline.
  • Master's degree or relevant advanced studies is an added advantage.

Responsibilities

  • Lead end-to-end cyber security incident management including detection, containment, eradication and recovery.
  • Act as escalation point for high-severity incidents and coordinate response across OpCos and stakeholders.
  • Develop and maintain incident response playbooks, runbooks, and SOPs.
  • Conduct post-incident reviews, root cause analysis, and remediation tracking.

Skills

Incident response
Digital forensics
Threat hunting
MITRE ATT&CK
Scripting (Python/PowerShell)

Education

Bachelor's degree in Cyber Security/Information Security/CS
Master's degree (advantage)

Tools

SIEM (Microsoft Sentinel/Splunk/QRadar)
EDR/XDR (CrowdStrike/Microsoft Defender)
SOAR
NDR
Threat Intelligence platforms
Cloud Security technologies

Job description

Overview

The Incident Response Lead is responsible for leading cyber incident detection, investigation,containment, eradication, recovery, and post incident activities across Axiata Cyber Fusion Center(ACFC). The role provides technical leadership and coordination for cyber incident response, digitalforensics, threat hunting, intelligence-driven defense, and continuous improvement of detection andresponse capabilities.

The incumbent will work closely with SOC analysts, Security Engineering, Threat Intelligence, OperationalCompanies (OpCos), Technology teams, and external partners to ensure timely and effective handling ofcyber threats and incidents while strengthening the organization’s cyber resilience.

Key Responsibilities
Cyber Incident Response & Management
  • Lead the end-to-end management of cyber security incidents, ensuring appropriate prioritization,investigation, containment, eradication, and recovery activities
  • Act as the primary escalation point for high-severity security incidents and coordinate incidentresponse activities across OpCos and stakeholders
  • Direct cyber incident bridge calls and crisis management activities during major security incidents
  • Ensure incident response activities are executed in accordance with established SLAs, regulatoryrequirements, and organizational policies
  • Develop and maintain incident response playbooks, runbooks,escalation matrices, and standardoperating procedures (SOPs)
  • Conduct post-incident reviews, root cause analysis, lessons learned sessions, and trackremediation actions
Security Monitoring & Detection Enhancement
  • Provide guidance and oversight to SOC analysts and managed security service providers to improve detection accuracy, triage quality, and investigation effectiveness
  • Review and validate alerts escalated from monitoring teams to ensure accurate contextualizationand prioritization
  • Drive continuous enhancement of security monitoring use cases, detection content, correlationrules, and threat detection frameworks
  • Collaborate with Security Engineering teams to improve visibility, telemetry, and detectioncoverage across enterprise environments
Digital Forensics & Malware Analysis
  • Lead forensic investigations involving endpoint, network, cloud, and mobile environments
  • Perform or oversee digital evidence acquisition, preservation, analysis, and reporting inaccordance with forensic standards
  • Conduct advanced malware analysis and reverse engineering activities to determine attackmethodologies, indicators of compromise (IOCs), and business impact
  • Support legal, regulatory, and compliance investigations where digital forensic expertise isrequired
Threat Intelligence & Threat Hunting
  • Analyze emerging cyber threats, vulnerabilities, adversary tactics, techniques, and procedures(TTPs) to improve defensive capabilities
  • Convert threat intelligence into actionable detection rules, hunting hypotheses, and responseactions
  • Lead proactive threat hunting activities leveraging MITRE ATT&CK and intelligence-ledmethodologies
  • Coordinate with internal and external intelligence sources to assess risks affecting Axiata Groupand OpCos
Automation & Continuous Improvement
  • Drive security orchestration, automation, and response (SOAR) initiatives to improve operationalefficiency and reduce mean time to detect (MTTD) and mean time to respond (MTTR)
  • Identify opportunities for process optimization, workflow automation, and operational maturityenhancements
  • Evaluate emerging cyber security technologies and recommend adoption based on business andoperational requirements
  • Contribute to the strategic development and maturity roadmap of ACFC's incident responsecapabilities
Security Testing & Readiness
  • Coordinate cyber security assessments, threat-led exercises, tabletop simulations, red teamengagements, and breach attack simulations
  • Validate detection and response capabilities against identified threats and attack scenarios
  • Provide guidance and recommendations for remediation and risk reduction initiatives
  • Support cyber crisis exercises and preparedness activities across the Axiata Group
Leadership & Stakeholder Management
  • Provide technical leadership, coaching, and mentoring to SOC analysts and incident responders
  • Engage effectively with senior management, technology teams, risk, compliance, legal, andexternal partners during security incidents
  • Prepare executive-level incident reports, risk summaries, and operational metrics
  • Foster collaboration across multicultural and geographically distributed teams
Key Performance Indicators (KPIs)
  • Achievement of Incident Response SLA and KPI targets
  • Reduction in Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR)
  • Timely containment and eradication of high and critical severity incidents
  • Improvement in detection use case effectiveness and detection coverage
  • Successful execution of threat hunting and proactive detection initiatives
  • Enhancement of automation and orchestration within incident response processes
  • Quality and completeness of forensic investigations and incident reports
  • Completion of post-incident reviews and remediation tracking
  • Stakeholder satisfaction and effective coordination during major incidents
  • Contribution towards ACFC operational maturity and cyber resilience objectives
Person Specifications
Education
  • Bachelor's Degree in Cyber Security, Information Security, Computer Science, InformationTechnology, or related discipline
  • Master's degree or relevant advanced studies is an added advantage
Experience
  • Minimum 8 years of experience in Cyber Security Operations, Incident Response, or CyberDefense functions
  • Minimum 5 years of hands-on experience managing cyber incidents in enterprise or regionalenvironments
  • Experience operating within a SOC, Cyber Fusion Center, CSIRT, CERT, or Incident Responseenvironment
  • Experience managing security incidents across multi-country or regional operations is highlypreferred
  • Experience with cloud incident response (Azure, AWS, GCP) is highly desirable
Professional Certifications (Preferred)
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Certified Forensic Analyst (GCFA)
  • GIAC Reverse Engineering Malware (GREM)
  • Certified Incident Handler (EC-Council ECIH)
  • Certified Ethical Hacker (CEH)
  • Certified Information Systems Security Professional (CISSP)
  • GIAC Certified Intrusion Analyst (GCIA)
  • CrowdStrike Certified Incident Responder (CCIR)
  • Microsoft Cybersecurity Architect Expert or equivalent
Technical Competencies
  • Strong knowledge of incident response lifecycle, digital forensics, malware analysis, and threathunting methodologies
  • Deep understanding of MITRE ATT&CK framework, cyber kill chain, and adversary emulationtechniques
  • Strong knowledge of Advanced Persistent Threats (APT), ransomware, business emailcompromise, insider threats, and cloud-focused attacks
  • Experience with:
    o SIEM platforms (Microsoft Sentinel, Splunk, QRadar)
    o EDR/XDR platforms (CrowdStrike, Microsoft Defender, Carbon Black)
    o SOAR platforms
    o Network Detection & Response (NDR)
    o Threat Intelligence platforms
    o Email Security platforms
    o Cloud Security technologies
  • Strong understanding of:
    o TCP/IP networking
    o Network security monitoring
    o Firewalls, IDS/IPS
    o DNS, Proxy and Web Security
    o Endpoint Security technologies
  • Experience performing log analysis, packet analysis, forensic investigations, and advanced threatinvestigations
  • Working knowledge of scripting and automation languages such as Python, PowerShell, Bash, orKQL
  • Experience in Telecom incident Response will be added advantage
  • Experience in FinTech incident Response will be added advantage
Behavioral Competencies
  • Strong analytical and problem-solving capabilities
  • Ability to perform effectively under pressure during major cyber security incidents
  • Excellent stakeholder management and communication skills
  • Strong report writing and executive presentation abilities
  • Ability to lead and coordinate cross-functional teams across multiple countries and cultures
  • Results-oriented with a continuous improvement mindset
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cyber Incident Response Lead
Senior Cyber Incident Response Lead

Axonect • Kuala Lumpur

On-site
MYR 240,000 - 360,000
Security Operations Center Lead
Security Operations Center Lead

Altera • Bayan Lepas

On-site
MYR 180,000 - 280,000
Digital Forensic & Incident Response (L3)
Digital Forensic & Incident Response (L3)

GoKardz Technologies • Kuala Lumpur

On-site
MYR 80,000 - 120,000
SOC Lead
SOC Lead

Axonect • Kuala Lumpur

On-site
MYR 180,000 - 240,000
Manager Endpoint Protection (Operation)
Manager Endpoint Protection (Operation)

Telekom Malaysia • Kuala Lumpur

On-site
MYR 180,000 - 320,000
Deputy Head of Security Operations Center (SOC)
Deputy Head of Security Operations Center (SOC)

Krisvconsulting Services Pte Ltd • Kuala Lumpur

On-site
MYR 320,000 - 550,000
Security Engineer - Offensive Security
Security Engineer - Offensive Security

Axonect • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Senior Cyber Security Consultant (SOC) Cyber security Kuala Lumpur
Senior Cyber Security Consultant (SOC) Cyber security Kuala Lumpur

S-RM Intelligence and Risk Consulting • Kuala Lumpur

Hybrid
MYR 120,000 - 180,000
Cyber Defence Lead, Cyber Security Department
Cyber Defence Lead, Cyber Security Department

Bank Negara Malaysia • Kuala Lumpur

On-site
MYR 180,000 - 300,000
Security Analyst (Intelligence & Operations)
Security Analyst (Intelligence & Operations)

GXS Bank • Petaling Jaya

On-site
MYR 90,000 - 150,000