Jobiglo

No results.

Incident Response Specialist

CyberOne · Metro Manila

New Remote
Remote 🇬🇧 English
Microsoft Defender XDR Microsoft Sentinel Windows Event Logs Sysmon Entra ID Exchange Online Malware triage Static analysis Threat hunting MITRE ATT&CK SC-200 SC-100 AZ-500 GCIH GCFA GNFA CompTIA Security+ CREST Practitioner

Job description

About the role

The Incident Response Specialist will support customers throughout the full lifecycle of a cyber incident, from initial investigation to containment, eradication, recovery and post‑incident reporting. Working with senior responders and incident managers, you will analyse evidence, identify attacker activity and help customers navigate critical security events.

Key responsibilities

  • Investigate cyber security incidents across endpoint, network, cloud and identity environments.
  • Analyse Microsoft Defender XDR telemetry, Microsoft Sentinel alerts and Windows Event Logs/Sysmon data.
  • Perform host‑based investigations on Windows and Microsoft 365 platforms, including Entra ID and Exchange Online logs.
  • Support containment, eradication and recovery actions and produce Indicators of Compromise.
  • Apply the MITRE ATT&CK framework to identify attacker TTPs and develop detection recommendations.
  • Conduct threat‑hunting activities and assist with forensic artefact collection for regulatory or legal purposes.
  • Participate in customer calls, explain findings to technical and non‑technical audiences, and deliver high‑quality investigation reports.
  • Contribute to proactive services such as Incident Response Readiness Assessments, tabletop exercises, threat intelligence and AI‑driven security investigations.

Required profile

  • Relevant experience in cyber security or incident response.
  • Strong English communication skills.
  • Optional certifications such as SC‑200, SC‑100, AZ‑500, GCIH, GCFA, GNFA, CompTIA Security+ or CREST Practitioner are a plus.

Required skills

  • Microsoft Defender XDR and Microsoft Sentinel.
  • Windows Event Logs, Sysmon, Entra ID and Exchange Online log analysis.
  • Malware triage and basic static analysis.
  • Firewall, proxy and VPN log review.
  • Threat hunting and use of the MITRE ATT&CK framework.
  • Forensic artefact collection, IOC generation and detection recommendation development.

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec CyberOne.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.
Source : ats:teamtailor

Why are you reporting this job?

Thank you for your report. We will review this job.

Explore further

Salaries, guides and searches in the Philippines.

Apply in 30 seconds

Enter your email to apply. An account will be created automatically.

By continuing, you accept our terms of use.

Already have an account? Login

💬 Chat with us on Telegram Chat on WhatsApp

Published 4 days ago

Expires 1 month from now

12 views · 0 interested

Boost your chances

Upload your CV — we will match you with relevant openings.

Analyzing your CV...

CyberOne

Metro Manila