1,104,572open jobs
64,113companies
186,177added this week
Browse all
Salary
≈ $19k – $43k per year (Estimated)
Location
In office (Petaling Jaya)
Seniority
Senior · 2+ years exp

First seen by Alion on Sep 27, 2026.

Overview
Company
Impact
Profile match
StarHub is a Singaporean telecommunications company offering mobile, broadband, pay television and enterprise services. It has expanded into cybersecurity and regional managed network businesses. The company is listed on the Singapore Exchange.

Job Title: Senior Incident Response Specialist, Cyber Security

Role Mission: The Senior Analyst - Cyber Security Incident Response is responsible for monitoring, detecting, and analysing cybersecurity incidents through the Security Operations Centre (SOC) platform. The role supports the end-to-end incident lifecycle - including triage, investigation, containment, and closure - ensuring timely response to security events and maintaining StarHub’s cyber resilience. This role acts as the Level 2 (L2) Incident Responder, bridging SOC analysts and Incident Response management by performing deep technical analysis and coordinating with internal teams for resolution.

Accountabilities:

  • Perform end-to-end incident triage and investigation of security alerts escalated from L1 SOC analysts.
  • Ensure timely incident analysis, containment, and escalation aligned with MTTD and MTTR goals.
  • Support the SIEM platform (Elastic Stack) by fine-tuning existing rules and suggesting new detections.
  • Conduct log analysis and correlation across multiple data sources (network, endpoint, and cloud).
  • Create and maintain incident documentation, reports, and lessons learned.
  • Support incident response playbook execution during containment and recovery phases.
  • Collaborate with IT, network, and application teams for incident remediation and root cause analysis.
  • Provide insights for use case improvements and participate in use case validation and testing.
  • Escalate confirmed incidents to CSIRT / Assistant Manager - Incident Response for further action.
  • Participate in post-incident reviews, contributing to process and detection improvements.

Responsibilities:

  • Monitor alerts generated from the SOC/SIEM and perform initial to intermediate-level investigations.
  • Review and validate security events from multiple log sources and identify legitimate threats.
  • Perform deep-dive investigations for incidents involving malware, phishing, insider threats, and cloud breaches.
  • Assist in detection rule creation and tuning under the guidance of senior incident responders.
  • Use frameworks like MITRE ATT&CK for mapping and improving detection quality.
  • Conduct threat hunting using Elastic Stack and related tools.
  • Collaborate with MSSP, CSIRT, and IT infrastructure teams to ensure timely incident handling.
  • Support incident response reporting, evidence collection, and documentation for compliance and audit.
  • Contribute to automation opportunities in detection and response workflows.
  • Participate in training sessions, simulations, and tabletop exercises to enhance readiness.
  • Responsible for the log source onboarding and managing the continuous logs availability on the SIEM platform.

Areas of Impact:

  • Scope: Operational role responsible for incident triage, analysis, and escalation within enterprise-wide SOC operations. Involves intermediate-level SIEM management (Elastic Stack) focusing on log analysis and event correlation. Covers on-premises, cloud, and hybrid infrastructure environments.
  • Decision Rights: Authority to validate and escalate confirmed incidents to the CSIRT or Assistant Manager. Can recommend new use cases and detection rules, subject to review and approval. Authorized to perform containment actions under predefined playbooks or guidance.
  • Stakeholders: ISO / CSIRT Team, SOC L1 Team, IT Infrastructure / Cloud / Application Teams, Risk & Compliance Team, External MSSP / Security Vendors.
  • Resources: Elastic SIEM (Elasticsearch, Logstash, Kibana, Beats), EDR / NDR tools, Threat Intel Feeds, SOAR platforms, and support from SOC Analysts, CSIRT, and IT Operations teams.

Ideal Track Record:

  • 2-3 years of experience in a SOC or Incident Response (L2) environment.
  • Intermediate hands-on experience with SIEM platforms (Elastic Stack preferred).
  • Exposure to incident triage, malware analysis, phishing response, and log correlation.
  • Strong understanding of use case creation and MITRE ATT&CK framework mapping.
  • Demonstrated ability to analyze complex alerts and distinguish false positives from true incidents.
  • Familiarity with security tools such as EDR, NDR, Cyber security tools and threat intelligence platforms.
  • Good communication and documentation skills for stakeholder updates.
  • Certifications such as CEH, CompTIA Security+, GCIA, or Elastic Certified Analyst preferred.
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
1,104,572 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
Petaling Jaya
≈ $20k – $45k per year (Estimated) • In office • 5+ years exp • Bachelor's Degree • Shah Alam
YARA
DevOps
Splunk
Linux
Windows
TCP/IP
DNS
VPN
Cybersecurity
Wireshark
Crowdstrike
Microsoft Sentinel
YARA
SentinelOne
Microsoft Defender
MITRE ATT&CK
Cyber Kill Chain
Diamond Model
IBM QRadar
Carbon Black
SIEM
Management
ITIL
Apply
≈ $19k – $51k per year (Estimated) • Hybrid • Full-Time • 8+ years exp • Bachelor's Degree • Johor Bahru
AI/ML
Anomaly Detection
Machine Learning
DevOps
Windows
VLAN
Cybersecurity
NIST CSF
Defense in Depth
IoT
OPC UA
Apply
≈ $85k – $168k per year (Estimated) • Hybrid • Full-Time • 5+ years exp • London
Go
JavaScript
Databases
PostgreSQL
Frontend
React.js
DevOps
CI/CD
AWS
IAM
Cybersecurity
ISO 27001
SOC 2
Apply
In office • Full-Time • Yokohama
Cybersecurity
Qualys Cloud Platform
ISO 27001
Apply
≈ $56k – $142k per year (Estimated) • Remote (Spain) • Full-Time • Bachelor's Degree • Seville
Apply
Remote (EAEU) • 3+ years exp • Minsk
Databases
MySQL
ElasticSearch
DevOps
Terraform
Docker Compose
Kibana
CI/CD
AWS
Docker
Bitbucket
AWS Lambda
Amazon EC2
Incident Management
Amazon S3
IAM
Amazon ECS
Amazon CloudWatch
DNS
Apply
≈ $7.5k – $21k per year (Estimated) • Remote (likely EAEU) • 1+ year exp • Almaty
DevOps
Zabbix
Kibana
Grafana
Graylog
Apply
$170k – $200k per year • Equity • In office • TS/SCI • 8+ years exp • Bachelor's Degree • Chantilly
JavaScript
TypeScript
Node JS
Databases
ElasticSearch
Frontend
Angular
Sass
DevOps
Git
Linux
Management
Agile
Apply
$200k – $220k per year • Equity • In office • TS/SCI • 10+ years exp • Bachelor's Degree • Chantilly
Python
JavaScript
Node JS
Databases
MongoDB
RabbitMQ
ElasticSearch
DevOps
Rest API
Ansible
CloudFormation
Prometheus
Jenkins
AWS
Docker
Kubernetes
Grafana
Configuration Management
Linux
Analytics
Apache NiFi
Management
Agile
Apply
$21k – $41k per year (net) • Hybrid • Full-Time • 2+ years exp • Rostov-on-Don
Databases
ElasticSearch
DevOps
Zabbix
Prometheus
CI/CD
Docker
Kubernetes
Grafana
Linux
Windows
VPN
Cybersecurity
Wazuh
OWASP Top 10
Apply
Head, IAM 8 days ago
≈ $21k – $59k per year (Estimated) • In office • 8+ years exp • Petaling Jaya
DevOps
IAM
Cybersecurity
DLP
Management
Google Workspace
Apply
≈ $19k – $50k per year (Estimated) • In office • 15+ years exp • Bachelor's Degree • Petaling Jaya
Cybersecurity
ISO 27001
Apply
≈ $58k – $137k per year (Estimated) • In office • 10+ years exp
DevOps
CI/CD
Platform Engineering
IAM
Wi-Fi
Cybersecurity
Zero Trust
PKI
SIEM
Management
ITSM
Apply
≈ $19k – $49k per year (Estimated) • In office • Full-Time • Petaling Jaya
DevOps
GCP
Azure
CI/CD
AWS
Bitbucket
SLI/SLO/SLA
Cybersecurity
Nessus
Qualys Cloud Platform
SonarQube
OWASP Top 10
CVSS
Fortify
Management
Jira
ServiceNow
Apply
In office • 5+ years exp
Apply
Software Engineering 6 hours ago
In office • Bachelor's Degree • Petaling Jaya
JavaScript
PHP
PHP
Laravel
Databases
MySQL
Frontend
React.js
Apply
In office • Full-Time • 10+ years exp • Petaling Jaya
DevOps
SLI/SLO/SLA
Management
Microsoft Office
Apply
≈ $14k – $32k per year (Estimated) • Equity • Hybrid • Full-Time • 7+ years exp • Petaling Jaya
Analytics
Power BI
Microsoft Excel
Management
Outlook
Apply
≈ $14k – $29k per year (Estimated) • In office • 2+ years exp • Petaling Jaya
AI/ML
AI Agents
DevOps
SLI/SLO/SLA
Apply
Project Manager 1 day ago
≈ $17k – $35k per year (Estimated) • Hybrid • Full-Time • 8+ years exp • Bachelor's Degree • Petaling Jaya
Apply
See all jobs
This is one of many
1,104,572 more open roles from verified company boards, updated every day.