588,947open jobs
26,464companies
82,741added this week
Browse all
Salary
$17k – $43k per year (Estimated)
Location
Remote (Philippines)
Employment
Full-Time
Overview
Company
Impact
Profile match

Job Title:Incident Response Specialist

Location:PH - Fully Remote

Employment Type: Full-time

About The Role

The Incident Response Specialist will play a key role in supporting customers through all stages of a cyber incident, from initial investigation through to containment, eradication, recovery and post-incident reporting.

Working alongside senior Incident Responders and Incident Managers, you will conduct technical investigations, analyse evidence, identify attacker activity and support customers during some of their most critical cyber security events.

The role also supports proactive security services including Incident Response Readiness Assessments, Tabletop Exercises, Threat Hunting and Threat Intelligence activities.

This is an excellent opportunity for an experienced SOC Analyst or early-career Incident Responder looking to develop into a senior DFIR consultant.

What You’ll Do

Incident Response

· Investigate cyber security incidents affecting customer environments.

· Analyse endpoint, network, cloud and identity-based evidence.

· Perform host-based investigations across Windows and Microsoft 365 environments.

· Support containment, eradication and recovery activities.

· Identify attacker tactics, techniques and procedures (TTPs) using the MITRE ATT&CK framework.

· Collect, preserve and analyse forensic artefacts where appropriate.

· Produce Indicators of Compromise (IOCs) and detection recommendations.

· Support evidence collection for regulatory or legal requirements.

Technical Investigation

· Analyse Microsoft Defender XDR telemetry.

· Investigate Microsoft Sentinel incidents.

· Review Windows Event Logs and Sysmon data.

· Analyse Entra ID sign-in and audit logs.

· Investigate Exchange Online activity.

· Perform malware triage and basic static analysis.

· Review firewall, proxy, VPN and authentication logs.

· Conduct threat hunting activities across customer environments.

Customer Engagement

· Participate in customer investigation calls.

· Explain technical findings to both technical and non-technical audiences.

· Produce high-quality investigation reports.

· Provide remediation recommendations.

· Support post-incident lessons learned workshops.

Proactive Services

Support delivery of:

· Incident Response Readiness Assessments

· Tabletop Exercises

· Threat Hunting engagements

· Threat Intelligence services

· Security posture reviews

· AI security investigations where required

Continuous Improvement

· Develop new investigation playbooks.

· Improve Incident Response procedures.

· Contribute to internal knowledge sharing.

· Support development of detection content.

· Assist with automation opportunities using Microsoft and AI technologies.

Employees are expected to demonstrate a security-first mindset and ensure that information security considerations are incorporated into their day-to-day activities, decision-making, and interactions with customers, suppliers, and colleagues.

What We’re Looking For

Essential

· Relevant experience in Cyber Security or Incident Response.

· Strong English communication skills.

Advantageous

· SC-200 Microsoft Security Operations Analyst

· SC-100 Cybersecurity Architect

· AZ-500 Microsoft Azure Security Technologies

· GCIH

· GCFA

· GNFA

· CompTIA Security+

· CREST Practitioner or equivalent

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
588,947 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Manila
In office • 3+ years exp
PowerShell
AI/ML
Copilot
DevOps
Azure
Incident Management
SLI/SLO/SLA
IAM
Cybersecurity
Microsoft Entra ID
Management
Power Automate
SharePoint
Apply
Remote/Hybrid • 5+ years exp • Bachelor's Degree
JavaScript
DevOps
Rest API
Azure
Git
Management
Agile
Apply
$65k – $94k per year • Remote • 5+ years exp • Bachelor's Degree
Java
Java
Spring Boot
Spring Security
Apache Tomcat
Apache Camel
Mobile
JUnit
MVC
DevOps
GCP
Azure
CI/CD
Git
AWS
Docker
Kubernetes
Management
Agile
Scrum
Kanban
Apply
In office • 8+ years exp
Python
JavaScript
TypeScript
Python
FastAPI
AI/ML
Model Context Protocol
Prompt Engineering
Multimodal AI
RAG
OpenAI
Agentic Workflows
Frontend
React.js
DevOps
Rest API
Azure
CI/CD
Apply
In office • 5+ years exp
DevOps
Terraform
OpenShift
Azure DevOps
Azure
CI/CD
GitOps
Kubernetes
Bicep
IAM
Apply
Project Manager 17 days ago
$80k – $161k per year (Estimated) • Remote/Hybrid • Full-Time • 5+ years exp • London
AI/ML
Copilot
DevOps
Azure
AWS
Cybersecurity
ISO 27001
GDPR
Management
Agile
Scrum
Apply
$10k – $25k per year (Estimated) • Remote • Full-Time • 5+ years exp • Manila
AI/ML
Copilot
Management
Outlook
Apply
$93k – $213k per year (Estimated) • Remote/Hybrid • Full-Time • London
SQL
AI/ML
Copilot
DevOps
Azure
Apply
Cyber Defence Analyst 3 months ago
$12k – $30k per year (Estimated) • In office • Full-Time • Manila
AI/ML
Copilot
Apply
$8k – $19k per year (Estimated) • In office • Full-Time • 3+ years exp • Manila
AI/ML
Copilot
Cybersecurity
ISO 27001
Analytics
Power BI
Apply
$7.5k – $21k per year (Estimated) • In office • Full-Time • 1+ year exp • Bachelor's Degree • Manila
Apply
$7k – $16k per year (Estimated) • In office • Full-Time • 3+ years exp • Manila
Management
Outlook
Apply
$15k – $33k per year (Estimated) • Remote/Hybrid • Full-Time • 3+ years exp • Manila
DevOps
Azure
Management
Jira
ServiceNow
Marketing
Salesforce
Apply
$13k – $31k per year (Estimated) • Remote/Hybrid • Full-Time • 3+ years exp • Manila
SQL
DevOps
Azure
Windows Server
Incident Management
Management
Jira
ServiceNow
Apply
$15k – $33k per year (Estimated) • Remote/Hybrid • Full-Time • 3+ years exp • Manila
SQL
PowerShell
Databases
MS SQL
DevOps
Windows Server
Incident Management
Management
Jira
ServiceNow
Agile
Scrum
Marketing
Salesforce
Apply
See all jobs
This is one of many
588,947 more open roles from verified company boards, updated every day.