
Incident Response Lead
- Singapore
- Permanent
- Full-time
- Serving as a point of escalation and incident commander, manage a team of incident responders for ISIRT response and interact with cybersecurity leadership and business stakeholders
- Coordinate and ensure ISIRT incidents are prioritized at all hours of the day
- Implement a cross-functional team of analysts working closely with cybersecurity, IT and developers
- Review ISIRT incidents that may be related to ransomware, host compromise, account compromise, phishing, anomalous user behavior, third parties and data leakage
- Ensure the ISIRT response team is following processes embraced by leadership and adhering to best practices
- Measure and give feedback to the team to improve mean time to respond, key performance indicators (KPIs) and service-level objectives
- Proactively adjust to upcoming company changes affecting the operation to modify ISIRT response processes
- Possess advanced knowledge of attackers' methods of escalation; lateral movement; and tactics, techniques and procedures
- Present incident analysis and trend reporting to leadership, highlighting KPIs
- Review events and process effectiveness and make recommendations for change to leadership
- Require participation in ISIRT tabletop exercises designed to identify gaps, improve skills, enhance communication and engage with key stakeholders
- Oversee IR playbooks, policies, procedures and guidelines to ensure they align with industry best practices
- Collaborate with infrastructure, IT, vulnerability, threat intelligence and application security leads
- Participate in monitoring internal and external events and stay tightly aligned with infrastructure and third-party, hosted, on-premises and end-user systems
- Review and communicate ISIRT incident details from initial investigation through root cause analysis and post-mortem
- Security Expertise: Over 2 years of experience in IT and/or OT security technologies.
- Security Operations: Hands-on experience in Security Operations Center (SOC) and Information Security Incident Response Team (ISIRT) processes, procedures, and tools.
- Tool Proficiency: Familiar with SIEM, SOAR, EDR, forensic tools, and ticketing platforms.
- Leadership: Proven ability to lead teams both onsite and remotely.
- Composure Under Pressure: Self-aware and able to remain calm, organized, and collaborative under high-pressure situations; skilled in prioritizing and responding within defined SLAs.
- Communication: Strong written and verbal communication skills across all organizational levels.
- Decision-Making: Excellent judgment and quick decision-making capabilities in complex scenarios.
- Security Knowledge: Solid understanding of threats, vulnerabilities, ISIRT incident response principles, and chain of custody.
- Compliance & Standards: Familiar with industry standards and frameworks including NIST, ISO 27001, NIS 2, and CRA.
- Professional Integrity: Demonstrated track record of integrity, pride in work, curiosity, flexibility, and professionalism.
- A variety of exciting challenges with ample opportunities for development and training in a truly global landscape
- A culture that pioneers a spirit of innovation where our industry experts drive visible results
- An equal opportunity employment experience that values diversity and inclusion
- Market competitive compensation and benefits with flexible working arrangements