Cyber Security Incident Responder

Orsted Asia Pacific

Warszawa

Hybrid

PLN 120,000 - 180,000

Full time

7 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Ørsted Asia Pacific is seeking a skilled cybersecurity professional to take charge of incident response, threat hunting, and forensic investigations across global IT and OT environments.

You will collaborate with security teams, vendors, and authorities to protect assets and information while continuously improving our cyber defence capabilities and playbooks.

Qualifications

  • Experience in incident response and cyber defence.
  • Familiarity with cloud logs, network captures, and forensic images.
  • Proficiency with SIEM/XDR and networking technologies.
  • Industry certifications such as GCFA/GCFE or equivalent.

Responsibilities

  • Lead incidents and technical analysis across IT and OT environments.
  • Analyze security events to identify root cause and impact.
  • Inform stakeholders and improve security posture based on lessons learned.
  • Coordinate incident analyses and document results.
  • Develop and update incident analyst playbooks and procedures.
  • Drive intelligence-based threat hunting and forensic investigations.
  • Maintain 24/7 readiness to respond to cyber-attacks worldwide.

Skills

Incident response
SIEM
XDR
Networking
Communication
GCFA/GCFE

Job description

Join us in this role where you’ll take charge of cybersecurity incidents and drive and develop our cyber response, threat hunting, and forensic investigation activities to protect our company, our employees, the production assets, and intellectual property from threat actors that seek harm to us and our partners. We invest in modern and advanced technologies to support the team members.

You’ll be part of Cyber Defence Centre where you, together with your colleagues, will work in close collaboration with other security departments, intelligence vendors, and national authorities around the world. The work environment is very healthy and diverse. You’ll have time to focus, deep dive, learn, and improve, so you’re the best at what you do, and you’ll have plenty of opportunities to excel, innovate, and push the conventional boundaries further. As a team, we are constantly developing, so you’ll find challenges that keep you motivated for months ahead.

You’ll play an important role in:
  • leading incidents and being a technical analyst in cyber response activities, both in IT and OT environments globally within the Cyber Defence Centre
  • analyzing and understanding information security events as well as analyzing incidents to identify root cause and impact
  • informing stakeholders and improving Ørsted’s security posture based on reporting and lessons learned from incidents
  • collecting incident report information and coordinating analyses
  • technical writing and updating incident analyst playbooks on operational and coordination level
  • designing and executing intelligence-based threat hunting activities and driving forensic investigations to completion
  • maintaining our 24/7 readiness in responding to cyber-attacks against Ørsted, around the globe.
To succeed in the role, you:
  • have some years of incident response experience
  • understand a broad palette of source material, whether cloud-related logs, network captures and forensic images
  • have experience in SIEM, XDR, networking and similar technologies
  • have a well-developed sense for communication to key stakeholders
  • are self-driven with in-depth technical knowledge, are curious in nature, and a team player
  • can keep updated on the latest developments in cybersecurity, supported by inputs from the team and formal training
  • have industry wide recognized certifications such as GCFA, GCFE or similar.

Maybe you’ve read the above and can see you have some transferable skills, even though they don’t quite match all the points. If you think you can bring something to the team, we still encourage you to apply.

As an applicant or employee, you may request reasonable work and position accommodation or adjustments via accommodation@orsted.com.

Please note that for your application to be taken into consideration, you must submit your application via our online career pages and answer the screening questions relevant for your country. We don't take applications or inquiries from external recruiters or agencies into account for this position.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Security Incident Responder
Cyber Security Incident Responder

Orsted Germany • Warszawa

Hybrid
PLN 200,000 - 320,000
Cyber Security Incident Responder
Cyber Security Incident Responder

Ørsted • Warszawa

On-site
PLN 180,000 - 280,000
Cyber Security Incident Responder
Cyber Security Incident Responder

Ørsted A/S • Warszawa

On-site
PLN 180,000 - 270,000
Lead Cybersecurity Incident Responder & Threat Hunter
Lead Cybersecurity Incident Responder & Threat Hunter

Ørsted A/S • Warszawa

On-site
PLN 180,000 - 270,000
Cyber Incident Responder & Threat Hunter
Cyber Incident Responder & Threat Hunter

Orsted Germany • Warszawa

Hybrid
PLN 200,000 - 320,000
Global Cyber Incident Response Lead
Global Cyber Incident Response Lead

Ørsted • Warszawa

On-site
PLN 180,000 - 280,000
Cyber Incident Response Lead - Threat Hunting & Forensics
Cyber Incident Response Lead - Threat Hunting & Forensics

Ørsted A/S • Warszawa

Hybrid
PLN 180,000 - 260,000
Cybersecurity Incident Response Analyst
Cybersecurity Incident Response Analyst

Hitachi Energy • Kraków

Hybrid
PLN 120,000 - 180,000
Competitive salaries
Flexible working hours
Professional development opportunities
+1
Senior IT Security Specialist Automation
Senior IT Security Specialist Automation

Nordea • Warszawa

On-site
PLN 180,000 - 240,000
Hybrid working model
OT Security Engineer
OT Security Engineer

Ramboll • Warszawa

On-site
PLN 120,000 - 160,000