Job Description

We help the world run better

At SAP, we keep it simple: you bring your best to us, and well bring out the best in you. Were builders touching over 20 industries and 80% of global commerce, and we need your unique talents to help shape whats next. The work is challenging – but it matters. Youll find a place where you can be yourself, prioritize your wellbeing, and truly belong. Whats in it for you? Constant learning, skill growth, great benefits, and a team that wants you to grow and succeed.

Summary

We are seeking an experienced Senior Incident Response Analyst to join our security operations team. With nearly a decade or more of hands-on experience, you will lead complex security investigations, and drive high fidelity cases for incident response team. The ideal candidate combines deep technical expertise in digital forensics and endpoint security with strong cloud security capabilities, automation skills.

What Youll Do

You will triage security alerts from Enterprise Detection and SIEM platforms to determine scope, severity, and priority, conducting initial assessments and root cause analysis while coordinating escalations to IR Investigators when needed. In this role, you will validate suspected cyber-attacks, scope incidents, support forensic investigations, and provide remediation guidance including attack remediation strategies. Involved in continuous improvements of IR procedures, playbooks, runbooks, and SOPs.

Additionally, you will collaborate with other security stakeholders to enhance detection and alerting mechanisms, coordinate communication during escalations, and provide supporting evidence for forensic investigations.

What You Bring

You should have demonstrated experience in cyber-attack analysis managing cases with enterprise SIEM or Incident Management systems. Previous experience of supporting multi-function, cross-organizational teams is also highly desirable.

We are looking for analytical, critical thinkers, who have an eye for detail and are solution orientated. You should be quick to learn and adapt and operate in a dynamic environment.

You typically will have most of the following technical skills and experience:

  • 9-13 years of hands-on experience in cybersecurity incident response or similar investigator role, with proven experience leading security incidents in enterprise environments
  • Demonstrated experience working in “follow the sun” model SOC or incident response environments managing cases with enterprise SIEM and Incident Management systems
  • Strong experience with cloud security operations (AWS preferred) including GuardDuty, CloudTrail, and cloud incident response
  • Proficiency in Python scripting with a portfolio of automation projects (GitHub, GitLab, or similar)
  • Track record of mentoring junior team members and supporting multi-function, cross-organizational teams
  • Demonstrated improvement experience including playbook development and after lessons learned facilitation
  • Industry certifications such as GCIH, GCFA, GCFE, GREM (preferably)
  • Advanced security certifications such as CISSP or CCSP
  • Cloud security certification such as AWS Certified Security – Specialty

Solid Knowledge Of One Or More

  • Conduct advanced forensic investigations across multiple operating systems and enterprise environments, performing evidence collection and analysis following proper chain-of-custody procedures
  • Utilize industry-standard forensic tools for memory and disk analysis to identify indicators of compromise and attack methodologies
  • Develop and refine forensic playbooks, standard operating procedures, and response documentation
  • Monitor and respond to cloud security alerts, investigating suspicious activities including unauthorized access, privilege escalation, and data exfiltration
  • Configure and manage cloud infrastructure for forensic analysis, threat hunting, and security testing purposes
  • Integrate security tools and build automated response workflows to enhance detection and response capabilities
  • Utilize scripting and automation for platform-specific tasks and process efficiency
  • Map incidents to industry-standard threat frameworks and apply knowledge of advanced threat actor methodologies to identify sophisticated attacks

Bring out your best

SAP innovations help more than four hundred thousand customers worldwide work together more efficiently and use business insight more effectively. Originally known for leadership in enterprise resource planning (ERP) software, SAP has evolved to become a market leader in end-to-end business application software and related services for database, analytics, intelligent technologies, and experience management. As a cloud company with two hundred million users and more than one hundred thousand employees worldwide, we are purpose-driven and future-focused, with a highly collaborative team ethic and commitment to personal development. Whether connecting global industries, people, or platforms, we help ensure every challenge gets the solution it deserves. At SAP, you can bring out your best.

We win with inclusion

SAP’s culture of inclusion, focus on health and well-being, and flexible working models help ensure that everyone – regardless of background – feels included and can run at their best. At SAP, we believe we are made stronger by the unique capabilities and qualities that each person brings to our company, and we invest in our employees to inspire confidence and help everyone realize their full potential. We ultimately believe in unleashing all talent and creating a better world.

SAP is committed to the values of Equal Employment Opportunity and provides accessibility accommodations to applicants with physical and/or mental disabilities. If you are interested in applying for employment with SAP and are in need of accommodation or special assistance to navigate our website or to complete your application, please send an e-mail with your request to Recruiting Operations Team: Careers@sap.com.

For SAP employees: Only permanent roles are eligible for the SAP Employee Referral Program, according to the eligibility rules set in the SAP Referral Policy. Specific conditions may apply for roles in Vocational Training.

Qualified applicants will receive consideration for employment without regard to their age, race, religion, national origin, ethnicity, gender (including pregnancy, childbirth, et al), sexual orientation, gender identity or expression, protected veteran status, or disability, in compliance with applicable federal, state, and local legal requirements.

Successful candidates might be required to undergo a background verification with an external vendor.

AI Usage in the Recruitment Process

For information on the responsible use of AI in our recruitment process, please refer to our Guidelines for Ethical Usage of AI in the Recruiting Process.

Please note that any violation of these guidelines may result in disqualification from the hiring process.

Requisition ID: 449644 | Work Area: Information Technology | Expected Travel: 0 - 10% | Career Status: Professional | Employment Type: Regular Full Time | Additional Locations:


Job Details

Role Level: Not Applicable Work Type: Full-Time
Country: Philippines City: Pasig National Capital Region
Company Website: http://www.sap.com Job Function: Cybersecurity
Company Industry/
Sector:
IT Services And IT Consulting Software Development And Business Consulting And Services

What We Offer


About the Company

Searching, interviewing and hiring are all part of the professional life. The TALENTMATE Portal idea is to fill and help professionals doing one of them by bringing together the requisites under One Roof. Whether you're hunting for your Next Job Opportunity or Looking for Potential Employers, we're here to lend you a Helping Hand.

Report

Disclaimer: talentmate.com is only a platform to bring jobseekers & employers together. Applicants are advised to research the bonafides of the prospective employer independently. We do NOT endorse any requests for money payments and strictly advice against sharing personal or bank related information. We also recommend you visit Security Advice for more information. If you suspect any fraud or malpractice, email us at abuse@talentmate.com.


Recent Jobs
View More Jobs
Talentmate Instagram Talentmate Facebook Talentmate YouTube Talentmate LinkedIn