Cyber Incident Responder (Python / ELK / Java / SIEM)

Maltem Asia Pte. Ltd.

Santo Niño 1st

On-site

PHP 1,000,000 - 1,800,000

Full time

6 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Maltem Asia-Pacific is seeking a Cyber Incident Responder to lead security usecase definition, design, and implementation for an i-Banking client. You will oversee the detection capabilities of the 24/7 regional SOC and respond to cyber incidents with threat-hunting and incident analysis.

With 7+ years in cyber security, you will work across Linux environments, ELK stacks, and scripting languages to translate logs into threat models, driving robust security postures.

Qualifications

  • 7+ years in Cyber Security Incident Response experience.
  • 4+ years in security use case design and development.
  • Experience with ELK stack is a plus.

Responsibilities

  • Lead security usecase definition, design, implementation and enrichment for robust detection.
  • Understand threats and propose usecases to detect, protect or mitigate.
  • Autonomously perform R&D, threat hunting and oversee 24/7 regional SOC activities.
  • Respond to cyber incidents and classify severity of security events.

Skills

Security incident response
Threat hunting
SIEM awareness
Python/PowerShell/Bash/SQL
Linux administration
Threat modeling
MITRE ATT&CK knowledge
Communication skills
Autonomous work

Tools

ELK Stack

Job description

Maltem Asia-Pacific is currently seeking aCyber Incident Responderfor our i-Banking Client.

Summary:
  • Lead technical activities (security usecase definition, design, implementation & enrichment) in the team of IT Production Security Investigation & Incident Response based on real-world attack scenarios and framework like MITRE ATT&CK, ensuring robust security detection posture across various layers.
  • Understand ongoing security threats in the wild and propose security usecase to detect and when possible, protect or mitigate.
  • Be autonomous on technical activities (definition, R&D/threat hunting) in the team of IT Production Security Investigation & Incident Response and oversee the detection capabilities of the 24/7 regional IT Production SOC
  • Respond to Cyber / IT security incidents and evaluates the type and severity of security events.
Technical Skills:
  • Requires a minimum of 7 or more years of experience as security professional
  • Experience in security usecase design/development with understanding of Java language.
  • Good working knowledge of Linux (RedHat/Ubuntu).
  • Working knowledge to interpret security logs or instructions into threat models. SecOPS-DevOPS mindset & skills.
  • Experience and knowledge in investigating incidents, remediation, tracking and follow-up for incident closure with concerned teams, stakeholders.
  • Thorough understanding of technologies and security concepts, with knowledge & hands on experience in SIEM Product and Security Incident Management
  • Experience on incident response activities (threat hunting, event analysis, incident investigation, reporting)
  • Comfortable working with and making the most of large data sets (collection, analysis, response), creating content/use cases/models and bringing an automation mindset. Personal Attributes
  • Strong problem-solving skills Good communication skills.
  • Positive attitude, willing to upskill and carry out in-depth troubleshooting
  • Has the ability to work autonomously and think on feet, be-proactive.
  • Good interpersonal skills and team player
  • High energy level coupled with a desire to take on responsibility
  • Able to multi-task & deliver within agreed deadlines.
Must have:
  • Candidate MUST have 7 or more years of experience on overall Cyber Security Incident Response with 4+ years specifically on security used case design, development, coding.
  • Experience in SIEM on ELK(Elastic Logstash Kibana) stack is a plus
  • Professional credentials in one of the relevant IT Security disciplines is a plus (SANS / CISSP / OSCP)
  • Experience in common scripting languages such as Python, PowerShell, Bash, SQL is a plus
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Cyber Incident Responder & Threat Hunter
Senior Cyber Incident Responder & Threat Hunter

Maltem Asia Pte. Ltd. • Santo Niño 1st

On-site
PHP 1,000,000 - 1,800,000
Senior SIEM Engineer for Cybersecurity Detection
Senior SIEM Engineer for Cybersecurity Detection

Boehringer Ingelheim GmbH • Hinoba-an

On-site
PHP 1,200,000 - 1,800,000
Incident Response Analyst
Incident Response Analyst

Dencom Consultancy and Manpower Services • Taguig

On-site
PHP 700,000 - 900,000
DFIR Specialist / Senior SOC Analyst (Malaysia)
DFIR Specialist / Senior SOC Analyst (Malaysia)

THEOS • Manila

Hybrid
PHP 1,200,000 - 1,800,000
PRINCIPAL SAP ABAP DEVELOPER
PRINCIPAL SAP ABAP DEVELOPER

Nityo Infotech Services Philippines Inc. • Muntinlupa

Hybrid
PHP 1,200,000 - 1,800,000
Hybrid work arrangement
DFIR Specialist / Senior SOC Analyst
DFIR Specialist / Senior SOC Analyst

THEOS • Hinoba-an

Hybrid
PHP 900,000 - 1,300,000
Security Engineer (Elastic stack / Python / RHEL / Ubuntu)
Security Engineer (Elastic stack / Python / RHEL / Ubuntu)

Maltem Asia Pte. Ltd. • Santo Niño 1st

On-site
PHP 5,914,000 - 8,871,000
Security Operations Center (SOC) - Head
Security Operations Center (SOC) - Head

SMITS, Inc. - IT Company of San Miguel Corporation • Mandaluyong

On-site
PHP 900,000 - 1,600,000
Senior Consultant – Digital Forensics & Incident Response (DFIR)
Senior Consultant – Digital Forensics & Incident Response (DFIR)

PM Consulting • Philippines

On-site
PHP 900,000 - 1,500,000
IT Security Analyst (Intermediate to Senior) - Leading Multinational Company
IT Security Analyst (Intermediate to Senior) - Leading Multinational Company

PFCC Group • Manila

On-site
PHP 900,000 - 1,700,000