Senior Incident Response (IR) Analyst

TrendMicro

Manila

On-site

PHP 1,200,000 - 1,800,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Trend Micro seeks an experienced Incident Response and Digital Forensics expert to lead investigations, analyze cloud and on-prem logs, and drive AI-enabled detection and response across multi-cloud environments.

The role partners with technical teams and business stakeholders, mentors junior analysts, and delivers timely executive summaries while staying ahead of evolving threats and AI-related security challenges.

Qualifications

  • 5+ years of incident response and forensics experience.
  • Hands-on AI tools experience in security operations and incident response.
  • Experience working with clients during live incidents.
  • Strong knowledge of networks, OS, and cloud environments (AWS/Azure/GCP).
  • Experience with cloud forensics across major providers and analyzing cloud logs.

Responsibilities

  • Lead investigations into security incidents including malware, data breaches, and APTs.
  • Perform forensic analysis on compromised systems, traffic, and logs.
  • Evaluate and pilot AI-based detection, triage, and reporting tools.
  • Provide timely incident reports and executive summaries to stakeholders.
  • Mentor junior analysts on methodology and AI-assisted tooling.
  • Improve detection, monitoring, and response capabilities with AI/automation.

Skills

Incident response
Digital forensics
AI security tools
Cloud forensics
SIEM/XDR
Client liaison
MITRE ATT&CK

Education

Bachelor's degree in CS/InfoSec

Tools

Splunk
CrowdStrike
Microsoft Sentinel
Azure CloudTrail
AWS CloudTrail

Job description

As the number of cyberattacks and digital threats continue to grow, our world needs more passionate and innovative individuals who seek to be trailblazers in and shapers of the rapidly evolving cybersecurity landscape. At Trend Micro, we offer tremendous opportunities that will challenge and equip you to become engineered to do good in whatever path you take. By choosing to be an agent of change, you will be part of an impactful mission that aims to make the world safe for exchanging digital information. This role requires strong technical expertise, sound judgment under pressure, and the ability to communicate clearly with both technical teams and business stakeholders during high-stakes incidents. We are especially interested in candidates with hands-on experience applying AI tools to security operations and incident response, as we continue to expand AI-driven detection, triage, and analysis capabilities across the team. Lead investigations into security incidents, including malware infections, data breaches, and advanced persistent threats (APTs). Perform forensic analysis on compromised systems, network traffic, and log data (e.g., WAF, firewall, endpoint, cloud, and application logs). Evaluate, pilot, and integrate AI-based tools (e.g., AI-powered SIEM/XDR triage, anomaly detection, LLM-assisted log analysis and report generation) into the incident response lifecycle. Provide timely, accurate incident reports and executive summaries to stakeholders and customers. Identify indicators of compromise (IOCs) and threat actor tactics, techniques, and procedures (TTPs), including AI-enabled attack methods. Mentor and guide junior analysts on investigation methodology, best practices, and use of AI-assisted tooling. Create and implement improvements to detection, monitoring, and response capabilities, including AI/automation-driven enhancements. Maintain awareness of the evolving threat landscape, including emerging vulnerabilities, attack techniques, and AI-related threats (e.g., AI-generated phishing, adversarial ML). Support post-incident reviews and root cause analysis to strengthen organizational security posture.

Required Qualifications
  • 5+ years of experience in incident response and digital forensics
  • Demonstrated experience with AI-related projects or activities in a security context (e.g., deploying or tuning AI-based detection/triage tools, using generative AI/LLMs to accelerate investigations or reporting, building automation that leverages machine learning models)
  • Prior experience working directly with clients/customers during live incident engagements
  • Strong understanding of network protocols, operating systems (Windows/Linux), and cloud environments (AWS, Azure, GCP)
  • Proven experience conducting cloud forensics investigations across major cloud service providers (AWS, Azure, GCP), including: Acquiring and analyzing cloud-native artifacts (VM snapshots/disk images, memory captures, container images, serverless function logs)
  • Analyzing cloud control plane and audit logs (e.g., Azure Activity Log, AWS CloudTrail, GCP Audit Logs) to reconstruct attacker activity and timelines
  • Understanding shared responsibility models and their impact on evidence availability and collection methods
  • Investigating incidents involving cloud storage (e.g., S3 buckets, Azure Blob Storage), managed databases, and Kubernetes/container orchestration environments
  • Working with volatile and ephemeristic cloud resources where traditional forensic imaging techniques may not apply
  • Hands-on experience with SIEM platforms, EDR/XDR tools, and log analysis (e.g., Splunk, CrowdStrike, Microsoft Sentinel), including AI-enabled features of these platforms
  • Relevant certifications such as GCIH, GCFA, GNFA, CISSP, CEH, OSCP, or cloud-specific credentials.
  • Familiarity with WAF, load balancer, and application gateway logs (e.g., Azure Application Gateway, Cloudflare, AWS WAF)
  • Solid understanding of the MITRE ATT&CK framework and threat intelligence concepts
  • Experience conducting forensic investigations and chain-of-custody procedures, including in distributed and multi-cloud environments
  • Excellent written and verbal communication skills, with the ability to translate technical findings for non-technical audiences
  • Ability to work under pressure and manage multiple concurrent investigations
  • Bachelor's degree in Computer Science, Information Security, or related field (or equivalent experience)
Preferred Qualifications
  • Experience with scripting/automation (Python, PowerShell) for investigation tasks, including integrating AI libraries or APIs into workflows
  • Practical exposure to concepts such as model training, prompt engineering, or AI governance/risk as applied to cybersecurity
  • Experience with cloud-native security tools and container security
  • Familiarity with cloud-native forensic and incident response tooling (e.g., AWS Detective, Azure Sentinel, Google Chronicle, Magnet AXIOM Cloud)

Be Passionate. Be Innovative. Be a Trender. Be EngineeredToDoGood. TrendAI, the global AI security leader and enterprise business unit of Trend Micro, empowers organizations with full AI visibility and consolidated security that inspires confidence, drives innovation, and eliminates risk. Trusted by the largest enterprises and governments across 185 countries, TrendAI secures the entire organization, from identities to infrastructure to data. We embrace change, empower our people, and foster innovation in an increasingly connected world. Our diverse, multicultural workforce is at the heart of our global success. At TrendAI, we're always seeking exceptional talent; people who want to collaborate with the best and push boundaries together. Here, your work goes beyond building a career. You will help protect what matters and play a vital role in shaping a safer, more trustworthy AI-powered future. Explore working at TrendAI AI Fearlessly.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior AI-Driven Incident Response Analyst
Senior AI-Driven Incident Response Analyst

TrendMicro • Manila

On-site
PHP 1,200,000 - 1,800,000
Senior Incident Response Analyst - AI-Driven Security
Senior Incident Response Analyst - AI-Driven Security

TrendAI • Pasig

On-site
PHP 1,200,000 - 2,400,000
Incident Response Analyst
Incident Response Analyst

Check Point Software Technologies Ltd. • Manila, Hinoba-an

On-site
PHP 1,800,000 - 2,400,000
Incident Response Analyst
Incident Response Analyst

Check Point Software • Metro Manila

On-site
PHP 2,000,000 - 2,800,000
Manager, Cyber Threat Intel Information Security
Manager, Cyber Threat Intel Information Security

AIA Hong Kong and Macau • Makati

On-site
PHP 1,200,000 - 1,500,000
Cyber Security Incident Response - Assistant Manager
Cyber Security Incident Response - Assistant Manager

Willis Towers Watson • España

On-site
PHP 3,690,000 - 4,921,000
Consulting_Cyber Detection & Response IRR Senior
Consulting_Cyber Detection & Response IRR Senior

EY • Taguig

On-site
PHP 900,000 - 1,200,000
Health and wellness packages
Opportunities for continuous learning
Access to cutting-edge technologies
Senior Cyber Security Analyst - APAC
Senior Cyber Security Analyst - APAC

Intuition Machines • Manila

On-site
PHP 3,059,000 - 4,896,000
Flexible working hours
Modern development workflows
Inclusive work environment
L3 Threat Response Analyst
L3 Threat Response Analyst

IBM • Taguig

On-site
PHP 600,000 - 1,200,000
Senior Cyber Security Analyst - APAC
Senior Cyber Security Analyst - APAC

Internetwork Expert • Manila

Remote
PHP 3,428,571 - 5,714,286
Fully remote position
Flexible working hours
Inspiring global team
+2