Work Setup: Hybrid (Minimum 8 RTO days per month)
Schedule:
- Asia Pacific: 6:00 AM – 3:00 PM
- Europe, Middle East & Africa: 2:00 PM – 11:00 PM
- WHEM: 10:00 PM – 7:00 AM (next day)
- Workdays: Sunday–Thursday or Monday–Friday (depending on shift)
- Shift rotation: Every 2 months
- Other Requirements: Amenable to overtime, weekend work, and PH holidays when necessary
The Incident Response Analyst is responsible for managing and resolving cybersecurity incidents across their full lifecycle—from detection and analysis to containment, remediation, and recovery. This role requires advanced technical expertise in threat investigation, response methodologies, and security operations. The analyst will work closely with cross‑functional teams to develop and implement solutions that proactively strengthen the organization’s security posture.
As an L2/L3 escalation point, the Incident Response Analyst handles complex cases, identifies emerging threats, creates detection rules, and contributes to continuous improvement of IR processes, tools, and reporting.
Qualifications
- At least 4–5 years of relevant experience in Incident Response or Security Operations (L2/L3 level)
- Proven hands‑on experience across the full Incident Response lifecycle
- Demonstrated ability to analyze and respond to complex security incidents
- Experience in creating detection rules, correlation searches, and signatures to identify suspicious or malicious behavior
- Strong understanding of cybersecurity frameworks, malware behavior, attack vectors, and threat actor tactics (MITRE ATT&CK)
- Familiarity with SIEM, SOAR, EDR/XDR, network security tools, and endpoint forensic methods
- Excellent communication skills with the ability to clearly document and present findings
- Willingness to work shifting schedules, weekends, holidays, and overtime when required