Turn this role into an interview — a resume and cover letter built around what this employer wants.
StarHub is seeking a Senior Analyst – Cyber Security Incident Response to monitor, detect, and analyse cybersecurity incidents within the SOC. You will handle end-to-end incident lifecycle from triage to closure, acting as L2 responder and coordinating with internal teams for resolution.
You will perform detailed log correlation across networks, endpoints, and cloud, fine-tune Elastic Stack detections, and contribute to incident documentation and playbooks.
The Senior Analyst – Cyber Security Incident Response is responsible for monitoring, detecting, and analysing cybersecurity incidents through the Security Operations Centre (SOC) platform. The role supports the end-to-end incident lifecycle — including triage, investigation, containment, and closure — ensuring timely response to security events and maintaining StarHub's cyber resilience. This role acts as the Level 2 (L2) Incident Responder, bridging SOC analysts and Incident Response management by performing deep technical analysis and coordinating with internal teams for resolution.
Key responsibilities
Perform end-to-end incident triage and investigation of security alerts escalated from L1 SOC analysts
Ensure timely incident analysis, containment, and escalation aligned with MTTD and MTTR goals
Support the SIEM platform (Elastic Stack) by fine-tuning existing rules and suggesting new detections
Conduct log analysis and correlation across multiple data sources (network, endpoint, and cloud)
Create and maintain incident documentation, reports, and lessons learned
Support incident response playbook execution during containment and recovery phases
Collaborate with IT, network, and application teams for incident remediation and root cause analysis
Provide insights for use case improvements and participate in use case validation and testing
Escalate confirmed incidents to CSIRT / Assistant Manager – Incident Response for further action
Participate in post-incident reviews, contributing to process and detection improvements
About you
2–3 years of experience in a SOC or Incident Response (L2) environment
Intermediate hands-on experience with SIEM platforms (Elastic Stack preferred)
Exposure to incident triage, malware analysis, phishing response, and log correlation
Strong understanding of use case creation and MITRE ATT&CK framework mapping
Demonstrated ability to analyze complex alerts and distinguish false positives from true incidents
Familiarity with security tools such as EDR, NDR, Cyber security tools and threat intelligence platforms
Good communication and documentation skills for stakeholder updates
Certifications such as CEH, CompTIA Security+, GCIA, or Elastic Certified Analyst preferred