Remote Incident Response & Threat Hunting Specialist

CyberOne

Metro Manila

On-site

PHP 500,000 - 900,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

CyberOne is seeking an Incident Response Specialist to support customers through all stages of cyber incidents, from investigation to containment, eradication, recovery, and post-incident reporting.

You will work with senior responders, analyze evidence across endpoints, networks, and cloud, and assist with proactive security services and threat hunting. Excellent English communication is essential.

Qualifications

  • Relevant experience in Cyber Security or Incident Response.
  • Strong English communication skills.

Responsibilities

  • Investigate cyber security incidents affecting customer environments.
  • Analyse endpoint, network, cloud and identity-based evidence.
  • Perform host-based investigations across Windows and M365 environments.
  • Support containment, eradication and recovery activities.
  • Identify attacker tactics, techniques and procedures using the MITRE ATT&CK framework.
  • Collect, preserve and analyse forensic artefacts where appropriate.
  • Produce Indicators of Compromise and detection recommendations.
  • Support evidence collection for regulatory or legal requirements.
  • Analyse Microsoft Defender XDR telemetry.
  • Investigate Microsoft Sentinel incidents.
  • Review Windows Event Logs and Sysmon data.
  • Analyse Entra ID sign-in and audit logs.
  • Investigate Exchange Online activity.
  • Perform malware triage and basic static analysis.
  • Review firewall, proxy, VPN and authentication logs.
  • Conduct threat hunting activities across customer environments.
  • Participate in customer investigation calls.
  • Explain technical findings to both technical and non-technical audiences.
  • Produce high-quality investigation reports.
  • Provide remediation recommendations.
  • Support post-incident lessons learned workshops.
  • Incident Response Readiness Assessments
  • Tabletop Exercises
  • Threat Hunting engagements
  • Threat Intelligence services
  • Security posture reviews
  • AI security investigations where required
  • Develop new investigation playbooks.
  • Improve Incident Response procedures.
  • Contribute to internal knowledge sharing.
  • Support development of detection content.
  • Assist with automation opportunities using Microsoft and AI technologies.

Skills

Cyber Security
Incident Response
English Communication

Education

Bachelor's degree in CS/IT or related

Tools

Microsoft Defender XDR
Microsoft Sentinel
Entra ID logs

Job description

CyberOne is seeking an Incident Response Specialist to support customers through all stages of cyber incidents, from investigation to containment, eradication, recovery, and post-incident reporting.

You will work with senior responders, analyze evidence across endpoints, networks, and cloud, and assist with proactive security services and threat hunting. Excellent English communication is essential.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Remote Incident Response Specialist & Threat Hunter
Remote Incident Response Specialist & Threat Hunter

CyberOne • Manila

On-site
PHP 600,000 - 900,000
Incident Response Analyst
Incident Response Analyst

PM Consulting • Philippines

On-site
PHP 400,000 - 600,000
Global Incident Response Specialist
Global Incident Response Specialist

PM Consulting • Philippines

On-site
PHP 400,000 - 600,000
Threat Hunter & Incident Response Specialist — Hybrid
Threat Hunter & Incident Response Specialist — Hybrid

First Focus • Hinoba-an

Hybrid
PHP 600,000 - 1,000,000
Hybrid working arrangements
HMO day 1 including one dependent
Dental cover
+8
Senior Cyber Incident Response & Threat Hunter
Senior Cyber Incident Response & Threat Hunter

Jobtailor • Mexico

On-site
MXN 420,000 - 660,000
Remote Cyber Security Analyst - Incident Response & Triage
Remote Cyber Security Analyst - Incident Response & Triage

Sourcepass • Hinoba-an

On-site
PHP 300,000 - 420,000
Threat Hunter & Incident Response Specialist
Threat Hunter & Incident Response Specialist

First Focus Information Technology, Inc. • Metro Manila

Hybrid
PHP 600,000 - 900,000
Hybrid work arrangements
HMO from Day 1
Paid study days
Cybersecurity Incident Response Engineer
Cybersecurity Incident Response Engineer

Assurity Trusted Solutions Pte Ltd • Santo Niño 1st

On-site
PHP 4,436,000 - 6,407,000
A wholly-owned subsidiary of GovTech.
Learning culture and growth encouraged
Remote Incident Response Analyst - Digital Security & Rights
Remote Incident Response Analyst - Digital Security & Rights

Access Now • Philippines

Hybrid
PHP 1,116,000 - 1,228,000
Health insurance
Generous paid time-off
Incident Response Analyst
Incident Response Analyst

Dencom Consultancy and Manpower Services • Taguig

Hybrid
PHP 700,000 - 900,000