Key Responsibilities
Incident Response & Investigation
- Lead and conduct end-to-end incident response across detection, triage, containment, eradication, and recovery.
- Able to perform deep technical investigations across endpoints, network, identity, cloud, and application layers.
- Analyze malware, attacker behaviors, and intrusion patterns to determine root cause and attack scope.
- Handle high-severity and sophisticated cyber incidents, including APT, ransomware, and fraud-related attacks.
- Maintain detailed documentation of incidents, actions taken, and lessons learned.
Security Incident Management
- Act as Incident Commander during major security incidents, coordinating cross-functional teams (SOC, IR, IT, Legal, Risk, Communications).
- Drive structured incident management processes, ensuring adherence to SLAs and playbooks.
- Provide timely and clear communications to senior management and stakeholders.
- Lead post-incident reviews (PIRs) and ensure remediation actions are tracked to closure.
SOC Operations & Escalation
- Serve as the highest technical escalation point within SOC for complex investigations.
- Support SOC analysts in triage and response for high-priority alerts.
- Improve escalation processes and decision-making frameworks during incidents.
Playbooks, Processes & Readiness
- Develop, maintain, and continuously improve incident response playbooks and runbooks.
- Ensure readiness for various threat scenarios including ransomware, data exfiltration, and insider threats.
- Conduct and support tabletop exercises and incident simulations.
- Align incident response processes with industry frameworks (e.g., MAS TRMG, CCoP, NIST, ISO 27035).
Threat Intelligence & Detection Feedback Loop
- Leverage threat intelligence to enhance incident response effectiveness.
- Provide feedback to detection engineering and threat hunting teams to improve use cases and monitoring coverage.
- Identify detection gaps exposed during incidents and drive remediation.
Digital Forensics & Evidence Handling
- Perform or oversee forensic data acquisition and analysis (disk, memory, logs).
- Ensure proper chain of custody and evidence handling for legal and regulatory needs.
- Support investigations that may require regulatory reporting or legal actions.
Automation & Tooling
- Drive the use of automation and SOAR playbooks to accelerate response actions.
- Recommend and implement tools to improve investigation speed and accuracy.
Stakeholder & Regulatory Engagement
Liaise with internal stakeholders including Fraud, Risk, Compliance, and IT.
Support regulatory incident reporting requirements relevant to financial/payment systems.
Act as a trusted advisor during cyber crisis situations.
Required Qualifications & Experience
10–15+ years of cybersecurity experience, with:
- 5+ years in incident response / digital forensics / SOC operations
- 3+ years in a lead or incident management capacity
Strong hands-on experience in:
- Incident response methodologies and frameworks
- EDR/XDR platforms
- SIEM platforms
- Network and endpoint investigation techniques
Deep understanding of:
- Threat actor tactics, techniques, and procedures (TTPs)
- MITRE ATT&CK framework
- Malware behavior and attack lifecycle
Experience in:
- Crisis management and incident command
- Cross-functional coordination during high-pressure scenarios
Strong technical skills in:
- OS internals (Windows/Linux)
- Networking (TCP/IP, DNS, HTTP/S, etc.)
- Log analysis and correlation
Preferred Qualifications
Experience in financial services, payments, or critical infrastructure environments
Hands-on malware analysis and reverse engineering (basic to advanced)
Familiarity with:
- Cloud security incident response (AWS, Azure, GCP)
- Identity-based attacks and investigations
- Exposure to fraud-related cybersecurity incidents
Preferred Certifications
- GIAC certifications (GCFA, GCIH, GNFA, GREM)
- CISSP, CISM
- Certified Incident Handler / Forensics certifications
- Vendor certifications (Microsoft, CrowdStrike, Google Mandiant, Elastic, etc.)
Key Competencies
- Strong technical depth and investigative skills
- Ability to lead during high-pressure incidents
- Excellent communication and stakeholder management
- Structured and analytical thinking
- Decisiveness and accountability
- Mentorship and team leadership
What Success Looks Like
- Rapid and effective containment of high-impact security incidents
- Reduced MTTR (Mean Time to Respond) and improved response quality
- Well-executed and coordinated incident management processes
- Continuous improvement of IR playbooks and readiness
- Strong trust and confidence from executive leadership and stakeholders