Job Description

Job Title: Incident Response Specialist

Location: PH - Fully Remote

Employment Type: Full-time

About The Role

The Incident Response Specialist will play a key role in supporting customers through all stages of a cyber incident, from initial investigation through to containment, eradication, recovery and post-incident reporting.

Working alongside senior Incident Responders and Incident Managers, you will conduct technical investigations, analyse evidence, identify attacker activity and support customers during some of their most critical cyber security events.

The role also supports proactive security services including Incident Response Readiness Assessments, Tabletop Exercises, Threat Hunting and Threat Intelligence activities.

This is an excellent opportunity for an experienced SOC Analyst or early-career Incident Responder looking to develop into a senior DFIR consultant.

What You’ll Do

Incident Response

  • Investigate cyber security incidents affecting customer environments.
  • Analyse endpoint, network, cloud and identity-based evidence.
  • Perform host-based investigations across Windows and Microsoft 365 environments.
  • Support containment, eradication and recovery activities.
  • Identify attacker tactics, techniques and procedures (TTPs) using the MITRE ATT&CK framework.
  • Collect, preserve and analyse forensic artefacts where appropriate.
  • Produce Indicators of Compromise (IOCs) and detection recommendations.
  • Support evidence collection for regulatory or legal requirements.

Technical Investigation

  • Analyse Microsoft Defender XDR telemetry.
  • Investigate Microsoft Sentinel incidents.
  • Review Windows Event Logs and Sysmon data.
  • Analyse Entra ID sign-in and audit logs.
  • Investigate Exchange Online activity.
  • Perform malware triage and basic static analysis.
  • Review firewall, proxy, VPN and authentication logs.
  • Conduct threat hunting activities across customer environments.

Customer Engagement

  • Participate in customer investigation calls.
  • Explain technical findings to both technical and non-technical audiences.
  • Produce high-quality investigation reports.
  • Provide remediation recommendations.
  • Support post-incident lessons learned workshops.

Proactive Services

Support delivery of:

  • Incident Response Readiness Assessments
  • Tabletop Exercises
  • Threat Hunting engagements
  • Threat Intelligence services
  • Security posture reviews
  • AI security investigations where required

Continuous Improvement

  • Develop new investigation playbooks.
  • Improve Incident Response procedures.
  • Contribute to internal knowledge sharing.
  • Support development of detection content.
  • Assist with automation opportunities using Microsoft and AI technologies.

Employees are expected to demonstrate a security-first mindset and ensure that information security considerations are incorporated into their day-to-day activities, decision-making, and interactions with customers, suppliers, and colleagues.

Essential

What We’re Looking For

  • Relevant experience in Cyber Security or Incident Response.
  • Strong English communication skills.

Advantageous

  • SC-200 Microsoft Security Operations Analyst
  • SC-100 Cybersecurity Architect
  • AZ-500 Microsoft Azure Security Technologies
  • GCIH
  • GCFA
  • GNFA
  • CompTIA Security+
  • CREST Practitioner or equivalent


Job Details

Role Level: Not Applicable Work Type: Full-Time
Country: Philippines City: Manila National Capital Region
Company Website: https://www.cyberone.security Job Function: Cybersecurity
Company Industry/
Sector:
Computer and Network Security

What We Offer


About the Company

Searching, interviewing and hiring are all part of the professional life. The TALENTMATE Portal idea is to fill and help professionals doing one of them by bringing together the requisites under One Roof. Whether you're hunting for your Next Job Opportunity or Looking for Potential Employers, we're here to lend you a Helping Hand.

Report

Disclaimer: talentmate.com is only a platform to bring jobseekers & employers together. Applicants are advised to research the bonafides of the prospective employer independently. We do NOT endorse any requests for money payments and strictly advice against sharing personal or bank related information. We also recommend you visit Security Advice for more information. If you suspect any fraud or malpractice, email us at abuse@talentmate.com.


Recent Jobs
View More Jobs
Talentmate Instagram Talentmate Facebook Talentmate YouTube Talentmate LinkedIn