Incident Response Lead

Status
Open
Remote policy
Remote
Employment type
Not stated
Salary
Not stated
Categories
Incident-Response, Cyber-Incident-Response, Security-Operations-Center, Threat-Hunting, Digital-Forensics, Incident-Response-Lead, Lead-Security-Incident-Responder, Incident-Response-Leadership, Incident-Response-Manager, Detection-and-Response-Lead
Tech
awsazuregcppython
Source
himalayas
First observed
2026-08-25 04:25 UTC
Last seen
2026-08-25 04:25 UTC
Source claims posted
2026-08-25 04:15 UTC
Consecutive misses
0 of 10

What the posting says

Overview

The Incident Response Lead is responsible for leading cyber incident detection, investigation, containment, eradication, recovery, and post incident activities across Axiata Cyber Fusion Center (ACFC). The role provides technical leadership and coordination for cyber incident response, digital forensics, threat hunting, intelligence-driven defense, and continuous improvement of detection and response capabilities.

The incumbent will work closely with SOC analysts, Security Engineering, Threat Intelligence, Operational Companies (OpCos), Technology teams, and external partners to ensure timely and effective handling of cyber threats and incidents while strengthening the organization's cyber resilience.

Key Responsibilities

Cyber Incident Response & Management

Lead the end-to-end management of cyber security incidents, ensuring appropriate prioritization, investigation, containment, eradication, and recovery activities

Act as the primary escalation point for high-severity security incidents and coordinate incident response activities across OpCos and stakeholders

Direct cyber incident bridge calls and crisis management activities during major security incidents

Ensure incident response activities are executed in accordance with established SLAs, regulatory requirements, and organizational policies

Develop and maintain incident response playbooks, runbooks, escalation matrices, and standard operating procedures (SOPs)

Conduct post-incident reviews, root cause analysis, lessons learned sessions, and track remediation actions

Security Monitoring & Detection Enhancement

Provide guidance and oversight to SOC analysts and managed security service providers to improve detection accuracy, triage quality, and investigation effectiveness

Review and validate alerts escalated from monitoring teams to ensure accurate contextualization and prioritization

Drive continuous enhancement of security monitoring use cases, detection content, correlation rules, and threat detection frameworks

Collaborate with Security Engineering teams to improve visibility, telemetry, and detection coverage across enterprise environments

Digital Forensics & Malware Analysis

Lead forensic investigations involving endpoint, network, cloud, and mobile environments

Perform or oversee digital evidence acquisition, preservation, analysis, and reporting in accordance with forensic standards

Conduct advanced malware analysis and reverse engineering activities to determine attack methodologies, indicators of compromise (IOCs), and business impact

Support legal, regulatory, and compliance investigations where digital forensic expertise is required

Threat Intelligence & Threat Hunting

Analyze emerging cyber threats, vulnerabilities, adversary tactics, techniques, and procedures (TTPs) to improve defensive capabilities

Convert threat intelligence into actionable detection rules, hunting hypotheses, and response actions

Lead proactive threat hunting activities leveraging MITRE ATT&CK and intelligence-led methodologies

Coordinate with internal and external intelligence sources to assess risks affecting Axiata Group and OpCos

Automation & Continuous Improvement

Drive security orchestration, automation, and response (SOAR) initiatives to improve operational efficiency and reduce mean time to detect (MTTD) and mean time to respond (MTTR)

Identify opportunities for process optimization, workflow automation, and operational maturity enhancements

Evaluate emerging cyber security technologies and recommend adoption based on business and operational requirements

Contribute to the strategic development and maturity roadmap of ACFC's incident response capabilities

Security Testing & Readiness

Coordinate cyber security assessments, threat-led exercises, tabletop simulations, red team engagements, and breach attack simulations

Validate detection and response capabilities against identified threats and attack scenarios

Provide guidance and recommendations for remediation and risk reduction initiatives

Support cyber crisis exercises and preparedness activities across the Axiata Group

Leadership & Stakeholder Management

Provide technical leadership, coaching, and mentoring to SOC analysts and incident responders

Engage effectively with senior management, technology teams, risk, compliance, legal, and external partners during security incidents

Prepare executive-level incident reports, risk summaries, and operational metrics

Foster collaboration across multicultural and geographically distributed teams

Key Performance Indicators (KPIs)

Achievement of Incident Response SLA and KPI targets

Reduction in Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR)

Timely containment and eradication of high and critical severity incidents

Improvement in detection use case effectiveness and detection coverage

Successful execution of threat hunting and proactive detection initiatives

Enhancement of automation and orchestration within incident response processes

Quality and completeness of forensic investigations and incident reports

Completion of post-incident reviews and remediation tracking

Stakeholder satisfaction and effective coordination during major incidents

Contribution towards ACFC operational maturity and cyber resilience objectives

Person Specifications

Education

Bachelor's Degree in Cyber Security, Information Security, Computer Science, Information Technology, or related discipline

Master's degree or relevant advanced studies is an added advantage

Experience

Minimum 8 years of experience in Cyber Security Operations, Incident Response, or Cyber Defense functions

Minimum 5 years of hands-on experience managing cyber incidents in enterprise or regional environments

Experience operating within a SOC, Cyber Fusion Center, CSIRT, CERT, or Incident Response environment

Experience managing security incidents across multi-country or regional operations is highly preferred

Experience with cloud incident response (Azure, AWS, GCP) is highly desirable

Professional Certifications (Preferred)

GIAC Certified Incident Handler (GCIH)

GIAC Certified Forensic Analyst (GCFA)

GIAC Reverse Engineering Malware (GREM)

Certified Incident Handler (EC-Council ECIH)

Certified Ethical Hacker (CEH)

Certified Information Systems Security Professional (CISSP)

GIAC Certified Intrusion Analyst (GCIA)

CrowdStrike Certified Incident Responder (CCIR)

Microsoft Cybersecurity Architect Expert or equivalent

Technical Competencies

Strong knowledge of incident response lifecycle, digital forensics, malware analysis, and threat hunting methodologies

Deep understanding of MITRE ATT&CK framework, cyber kill chain, and adversary emulation techniques

Strong knowledge of Advanced Persistent Threats (APT), ransomware, business email compromise, insider threats, and cloud-focused attacks

Experience with:

o SIEM platforms (Microsoft Sentinel, Splunk, QRadar)

o EDR/XDR platforms (CrowdStrike, Microsoft Defender, Carbon Black)

o SOAR platforms

o Network Detection & Response (NDR)

o Threat Intelligence platforms

o Email Security platforms

o Cloud Security technologies

Strong understanding of:

o TCP/IP networking

o Network security monitoring

o Firewalls, IDS/IPS

o DNS, Proxy and Web Security

o Endpoint Security technologies

Experience performing log analysis, packet analysis, forensic investigations, and advanced threat investigations

Working knowledge of scripting and automation languages such as Python, PowerShell, Bash, or KQL

Experience in Telecom incident Response will be added advantage

Experience in FinTech incident Response will be added advantage

Behavioral Competencies

Strong analytical and problem-solving capabilities

Ability to perform effectively under pressure during major cyber security incidents

Excellent stakeholder management and communication skills

Strong report writing and executive presentation abilities

Ability to lead and coordinate cross-functional teams across multiple countries and cultures

Results-oriented with a continuous improvement mindset

Originally posted on Himalayas

Quality

Completeness: 65%

Not enough history yet to judge honesty signals.

Timeline

  1. *
    #347388 2026-08-25 04:25 UTC
    Published