Senior Threat Response Analyst: Incident & Forensics

IBM

Taguig

On-site

PHP 600,000 - 1,200,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

IBM Consulting in the Philippines seeks a Senior Threat Response Analyst to lead advanced incident investigations, drive containment, and remediation efforts. You will work with clients across industries, applying SIEM, forensics, and threat intel to stop complex cyber threats.

You will collaborate with IT and security teams, deliver periodic threat briefs, and leverage IBM QRadar, Splunk, ArcSight, and other tools to strengthen defenses.

Qualifications

  • More than five years in SOC, Incident Response, or Threat Hunting roles.
  • Hands-on experience with SIEM platforms such as IBM QRadar, Splunk, ArcSight, Microsoft Sentinel, or LogRhythm.
  • Strong knowledge of network security, log analysis, malware analysis, and forensic investigation techniques.
  • Knowledge of Digital Forensics, including disk imaging, memory forensics, log analysis, and evidence handling best practices.
  • Familiarity with cyber threat intelligence frameworks like MITRE ATT&CK, NIST, and CIS.
  • Expertise in network and endpoint security monitoring tools (IDS, firewalls, EDR, proxy, email security solutions).
  • Proficiency in log analysis, regular expressions (regex), and scripting languages like Python or PowerShell.
  • Ability to create custom threat detection rules, SIEM dashboards, and correlation policies.

Responsibilities

  • Provide incident investigation as per Security Incident Management Process / Guidelines.
  • Drive containment strategy during incidents escalated by the triage team.
  • Investigate and resolve advanced vector attacks such as botnets and advanced persistent threats (APTs).
  • For critical incidents, be part of CSIRT activities and execute the incident handling process.
  • Coordinate with IT, security operations, and other teams for remediation and trigger forensic processes as appropriate.
  • Perform Root Cause Analysis (RCA) for security incidents and update knowledge management.
  • Work directly with data asset owners and business response plan owners during high-severity incidents.
  • Engage with clients during debrief meetings to address questions, gather feedback, and align on security objectives.
  • Provide tuning recommendations for IDS, proxy policies, and in-line malware tools based on threat feeds, trust and reputation data, incidents, or vulnerabilities and exploits of downstream systems.
  • Provide tuning recommendations to administrators based on findings from investigations or threat information reviews.
  • Prepare and deliver comprehensive weekly and monthly Threat Incident debrief reports for clients, including insights on security trends, incidents, system performance, and recommendations.

Skills

Analytical skills
Problem solving
Communication skills
Stakeholder management
Multi-tasking

Education

Bachelor's Degree

Tools

IBM QRadar
Splunk
ArcSight
Microsoft Sentinel
LogRhythm

Job description

IBM Consulting in the Philippines seeks a Senior Threat Response Analyst to lead advanced incident investigations, drive containment, and remediation efforts. You will work with clients across industries, applying SIEM, forensics, and threat intel to stop complex cyber threats.

You will collaborate with IT and security teams, deliver periodic threat briefs, and leverage IBM QRadar, Splunk, ArcSight, and other tools to strengthen defenses.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

L3 Threat Response Analyst
L3 Threat Response Analyst

IBM • Taguig

On-site
PHP 600,000 - 1,200,000
Security Operations Analyst – Threat & Incident Response
Security Operations Analyst – Threat & Incident Response

ibex • Mandaluyong

On-site
PHP 420,000 - 640,000
SOC Threat Hunter & Incident Response Analyst
SOC Threat Hunter & Incident Response Analyst

Ibex Limited • Davao del Sur

On-site
PHP 480,000 - 840,000
Senior Cybersecurity Solutions Architect — SIOC & SIEM Lead
Senior Cybersecurity Solutions Architect — SIOC & SIEM Lead

IBM • Philippines

On-site
PHP 1,500,000 - 3,000,000
Cyber Incident Response Lead & Forensics Expert
Cyber Incident Response Lead & Forensics Expert

Accenture in the Philippines • Mandaluyong

On-site
PHP 900,000 - 1,400,000
Security Analyst — Threat Detection & Incident Response
Security Analyst — Threat Detection & Incident Response

Acquire Intelligence • Pasig

On-site
PHP 480,000 - 720,000
Senior Cybersecurity Architect: SIOC & SIEM Solutions Lead
Senior Cybersecurity Architect: SIOC & SIEM Solutions Lead

Hakkoda • Pateros

Hybrid
PHP 1,200,000 - 1,800,000
Senior Incident Response Analyst - AI-Driven Security
Senior Incident Response Analyst - AI-Driven Security

TrendAI • Pasig

On-site
PHP 1,200,000 - 2,400,000
Cyber Defense Analyst: Threat Hunter & Incident Response
Cyber Defense Analyst: Threat Hunter & Incident Response

Acquire Intelligence • Pasig

On-site
PHP 600,000 - 900,000
SOC Analyst — Fast-Track Cyber Defense & Growth
SOC Analyst — Fast-Track Cyber Defense & Growth

OFFSHORE BUSINESS PROCESSING INC. • Philippines

On-site
PHP 446,000 - 558,000
HMO on Day 1
Receive promising perks and rewards
Experience travel opportunities
+3