Incident Response Analyst

HRTX

Philippines

On-site

PHP 600,000 - 1,000,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

HRTX is seeking an Incident Response Analyst to detect, contain, and analyze security events, protecting information systems in line with business and regulatory goals. The role supports Tier 2 IR, forensics, and threat detection across a global organization.

The candidate will work with SIEM, log management, IDS/EDR, and other security tooling, perform malware analysis, and contribute to security standards while communicating findings clearly in English. Shift-based work is required.

Qualifications

  • Experience in information security with a focus on incident response and forensics.
  • Foundational IR concepts, including forensics and chain-of-custody.
  • Strong written and verbal English communication skills.
  • Experience with SIEM, log management, IDS/IPS, and EDR/breach detection tools.

Responsibilities

  • Provide Tier 2 incident response services for the global organization.
  • Receive, process, and resolve tickets per defined SLA's.
  • Analyze monitoring data to determine scope and impact of incidents.
  • Assist with design and implementation of threat detection and prevention solutions.
  • Utilize IR toolsets such as SIEM, log management, IDS, and packet capture.
  • Support forensic examinations and chain-of-custody procedures as directed.

Skills

Incident response
Forensics
Malware analysis
Threat hunting
SIEM
Log management
IDS/IPS
EDR
Packet capture
TCP/IP knowledge
English communication

Tools

Qualys
Nessus
EnCase
FTK
Sleuth Kit
X-Ways
SIEM tooling

Job description

The Incident Response Analyst will provide detection, containment, and analysis of security events to protect the confidentiality, integrity, and availability of information systems in accordance with the firm’s business objectives, regulatory requirements, and strategic goals.

Responsibilities:
  • Provide Tier 2 incident response services to the global organization on behalf of the Information Security Team
  • Receive, process, and resolve tickets per defined SLA's
  • Analyze information garnered from monitoring systems, operational incidents, and other sources to determine the scope and impact of potential security incidents, and process accordingly
  • Critically assess current practices and provide feedback to management on improvement opportunities
  • Assist with the design and implementation of threat detection and prevention solutions identified as necessary for the protection of Firm assets
  • Effectively utilize common IR toolsets, platforms, and processes, such as SIEM, log management, packet capture, and breach detection systems
  • Assist with forensic examinations and chain-of-custody procedures as directed by the Security Incident Response Engineers
  • Provide input into standards and procedures
  • Report compliance failures to management for immediate remediation
  • Maintain assigned systems to ensure availability, reliability, and integrity, including the oversight of current and projected capacity, performance, and licensing
  • Provide status reports and relevant metrics to the Security Operations Manager
  • Contribute to the Firm's security-related information repositories and other marketing/awareness endeavors
  • Participate in special projects as needed
Skills and Experience:
  • Some professional experience in information security with a
  • Focus on incident response and forensics
  • Foundational knowledge of IR concepts and best practices, including forensics and chain-of-custody
  • Experience with common IR tools such as SIEM, log management, IDS, breach detection systems (APT/BDS/EDR), and packet capture.
  • Broad understanding of TCP/IP, DNS, common network services, and other foundational topics
  • Working knowledge of malware detection, analysis, and evasion techniques
  • Able to conduct static and dynamic analysis of malware to extract indicators of compromise, profile malware behavior, and provide recommendations for mitigating and detecting malware; Able to analyze suspicious websites, script-based and malware code
  • Experience with vulnerability management tools such as Qualys, Nessus, or other vulnerability scanning discovery tools
  • Broad familiarity with the threat landscape and the ability to adapt practices to evolving circumstances
  • Identify, analyze, and report threats within the enterprise by using information collected from a variety of sources (IDS/IPS, SIEM, AV), to protect data and networks. Implement techniques to hunt for known and unknown threats based on available threat intelligence reports and knowledge of the attacker's TTPs
  • Able to gather and analyze facts, draw conclusions, define problems, and suggest solutions
  • Maintain critical thinking and composure under pressure
  • Strong written and oral communication skills. Ability to convey complex concepts to non-technical constituents. Proficiency in oral and written English
  • Capable of assisting with the preparation of internal training materials and documentation
  • Able to be productive and maintain focus without direct supervision
  • Passionate in the practice and pursuit of IR excellence
  • Can exhibit a disciplined and rigorous approach to incident handling
  • Willing to accommodate shift-based work for a global organization
  • Provide exemplary customer service by striving for first-call resolution and demonstrating empathy, respect, professionalism, and expertise
  • Experience with digital forensics on host or network and identification of anomalous behavior on the network or endpoint devices. Familiar with host and network-based forensic tools such as EnCase, FTK, Sleuth Kit, X Ways, etc.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Incident Response Analyst
Incident Response Analyst

PM Consulting • Philippines

On-site
PHP 400,000 - 600,000
Cybersecurity and Incident Response Specialist
Cybersecurity and Incident Response Specialist

Accenture in the Philippines • Mandaluyong

On-site
PHP 900,000 - 1,400,000
Incident Response Analyst
Incident Response Analyst

Dencom Consultancy and Manpower Services • Taguig

Hybrid
PHP 700,000 - 900,000
IT Security Analyst
IT Security Analyst

Ibex Limited • Davao del Sur

On-site
PHP 480,000 - 840,000
IT Security Analyst
IT Security Analyst

IBEX Global Solutions (Philippines) Inc. • Davao del Sur

On-site
PHP 420,000 - 560,000
L3 Threat Response Analyst
L3 Threat Response Analyst

IBM • Taguig

On-site
PHP 600,000 - 1,200,000
Incident Response & Forensics Analyst
Incident Response & Forensics Analyst

HRTX • Philippines

On-site
PHP 600,000 - 1,000,000
SOC Analyst
SOC Analyst

HRTX • Philippines

On-site
PHP 600,000 - 900,000
IT Security Analyst
IT Security Analyst

CallTek • Cebu City

On-site
PHP 200,000 - 360,000
IT Security Analyst
IT Security Analyst

CallTek, Inc. • Cebu City

On-site