Senior Incident Response Specialist

Starhub Ltd

Singapore

On-site

SGD 38,000 - 56,000

Full time

32 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

StarHub Ltd. in Petaling Jaya, Malaysia, seeks a Senior Incident Response Specialist to monitor, detect, and investigate cybersecurity incidents within the SOC framework.

You will triage, contain, and coordinate with CSIRT and IT teams to ensure rapid containment and remediation. The role demands hands-on SIEM work, log analysis across on-prem and cloud environments, and ongoing use-case improvement using MITRE ATT&CK mappings.

Qualifications

  • 2–3 years of experience in a SOC or Incident Response (L2) environment.
  • Hands-on experience with SIEM platforms, preferably Elastic Stack.
  • Experience in incident triage, malware analysis, phishing response, and log correlation.
  • Knowledge of MITRE ATT&CK framework mapping.
  • Ability to analyze complex alerts and distinguish real threats.
  • Familiarity with EDR/NDR tools and threat intelligence sources.
  • Good communication and documentation skills for stakeholder updates.
  • Certifications such as CEH, CompTIA Security+, GCIA, or Elastic Certified Analyst preferred.

Responsibilities

  • Monitor alerts generated from the SOC/SIEM and perform initial to intermediate-level investigations.
  • Review and validate security events from multiple log sources and identify legitimate threats.
  • Perform deep-dive investigations for incidents involving malware, phishing, insider threats, and cloud breaches.
  • Assist in detection rule creation and tuning under the guidance of senior incident responders.
  • Use frameworks like MITRE ATT&CK for mapping and improving detection quality.
  • Conduct threat hunting using Elastic Stack and related tools.
  • Collaborate with MSSP, CSIRT, and IT infrastructure teams to ensure timely incident handling.
  • Support incident response reporting, evidence collection, and documentation for compliance and audit.
  • Contribute to automation opportunities in detection and response workflows.
  • Participate in training sessions, simulations, and tabletop exercises to enhance readiness.
  • Responsible for the log source onboarding and managing the continuous logs availability on the SIEM platform.

Skills

SOC / Incident Response
SIEM (Elastic Stack)
Malware analysis
Phishing response
Log correlation
MITRE ATT&CK framework
EDR / NDR tools
Threat intelligence
Communication & documentation
Certifications (CEH, Security+, GCIA,/

Tools

Elastic Stack
EDR
NDR
SOAR platforms

Job description

Select how often (in days) to receive an alert:

Date: 27 Sept 2026

Location: Petaling Jaya, MY

Job Title: Senior Incident Response Specialist, Cyber Security

Role Mission: The Senior Analyst – Cyber Security Incident Response is responsible for monitoring, detecting, and analysing cybersecurity incidents through the Security Operations Centre (SOC) platform. The role supports the end-to-end incident lifecycle — including triage, investigation, containment, and closure — ensuring timely response to security events and maintaining StarHub’s cyber resilience. This role acts as the Level 2 (L2) Incident Responder, bridging SOC analysts and Incident Response management by performing deep technical analysis and coordinating with internal teams for resolution.

Accountabilities:

  • Perform end-to-end incident triage and investigation of security alerts escalated from L1 SOC analysts.
  • Ensure timely incident analysis, containment, and escalation aligned with MTTD and MTTR goals.
  • Support the SIEM platform (Elastic Stack) by fine-tuning existing rules and suggesting new detections.
  • Conduct log analysis and correlation across multiple data sources (network, endpoint, and cloud).
  • Create and maintain incident documentation, reports, and lessons learned.
  • Support incident response playbook execution during containment and recovery phases.
  • Collaborate with IT, network, and application teams for incident remediation and root cause analysis.
  • Provide insights for use case improvements and participate in use case validation and testing.
  • Escalate confirmed incidents to CSIRT / Assistant Manager – Incident Response for further action.
  • Participate in post-incident reviews, contributing to process and detection improvements.

Responsibilities:

  • Monitor alerts generated from the SOC/SIEM and perform initial to intermediate-level investigations.
  • Review and validate security events from multiple log sources and identify legitimate threats.
  • Perform deep-dive investigations for incidents involving malware, phishing, insider threats, and cloud breaches.
  • Assist in detection rule creation and tuning under the guidance of senior incident responders.
  • Use frameworks like MITRE ATT&CK for mapping and improving detection quality.
  • Conduct threat hunting using Elastic Stack and related tools.
  • Collaborate with MSSP, CSIRT, and IT infrastructure teams to ensure timely incident handling.
  • Support incident response reporting, evidence collection, and documentation for compliance and audit.
  • Contribute to automation opportunities in detection and response workflows.
  • Participate in training sessions, simulations, and tabletop exercises to enhance readiness .
  • Responsible for the log source onboarding and managing the continuous logs availability on the SIEM platform.

Areas of Impact:

  • Scope: Operational role responsible for incident triage, analysis, and escalation within enterprise-wide SOC operations. Involves intermediate-level SIEM management (Elastic Stack) focusing on log analysis and event correlation. Covers on-premises, cloud, and hybrid infrastructure environments.
  • Decision Rights: Authority to validate and expand confirmed incidents to the CSIRT or Assistant Manager. Can recommend new use cases and detection rules, subject to review and approval. Authorized to perform containment actions under predefined playbooks or guidance.
  • Stakeholders: ISO / CSIRT Team, SOC L1 Team, IT Infrastructure / Cloud / Application Teams, Risk & Compliance Team, External MSSP / Security Vendors.
  • Resources: Elastic SIEM (Elasticsearch, Logstash, Kibana, Beats), EDR / NDR tools, Threat Intel Feeds, SOAR platforms, and support from SOC Analysts, CSIRT, and IT Operations teams.

Ideal Track Record:

  • 2–3 years of experience in a SOC or Incident Response (L2) environment.
  • Intermediate hands-on experience with SIEM platforms (Elastic Stack preferred).
  • Exposure to incident triage, malware analysis, phishing response, and log correlation.
  • Strong understanding of use case creation and MITRE ATT&CK framework mapping.
  • Demonstrated ability to analyze complex alerts and distinguish false positives from true incidents.
  • Familiarity with security tools such as EDR, NDR, Cyber security tools and threat intelligence platforms.
  • Good communication and documentation skills for stakeholder updates.
  • Certifications such as CEH, CompTIA Security+, GCIA, or Elastic Certified Analyst preferred.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Incident Response Specialist
Senior Incident Response Specialist

StarHub • Singapore

On-site
SGD 120,000 - 180,000
Senior Analyst, Threat Detection and Response
Senior Analyst, Threat Detection and Response

WhiteCrow Research • Singapore

On-site
SGD 120,000 - 180,000
Cyber Security Resident Engineer - Incident Response & SIEM
Cyber Security Resident Engineer - Incident Response & SIEM

Ensign InfoSecurity • Singapore

On-site
SGD 70,000 - 100,000
Senior Analyst, Threat Detection and Response
Senior Analyst, Threat Detection and Response

SATS Ltd. • Singapore

On-site
SGD 90,000 - 150,000
Senior Cyber Incident Responder
Senior Cyber Incident Responder

Starhub Ltd • Singapore

On-site
SGD 38,000 - 56,000
Security Analyst - Contract
Security Analyst - Contract

QUESS SELECTION & SERVICES PTE. LTD. • Singapore

On-site
SGD 120,000 - 180,000
Senior Cyber Incident Response Lead | SIEM & Forensics
Senior Cyber Incident Response Lead | SIEM & Forensics

StarHub • Singapore

On-site
SGD 120,000 - 180,000
Cyber Security Resident Engineer
Cyber Security Resident Engineer

Ensign InfoSecurity • Singapore

On-site
SGD 70,000 - 100,000
Senior Security Analyst
Senior Security Analyst

CrimsonLogic Pte Ltd • Singapore

On-site
SGD 60,000 - 90,000
Senior Cyber Security Consultant
Senior Cyber Security Consultant

Singtel • Singapore

On-site
Confidential