Search by job, company or skills

Incident Response Analyst

1-3 Years
  • Posted 5 hours ago
  • Be among the first 10 applicants

Job Description

Educational Background

  • Bachelor's degree in Information Technology, Computer Science, Engineering, or any related course/discipline.

Work Experience

  • 1–2 years of experience in cybersecurity with a focus on incident response, including relevant internships.
  • Hands-on experience with incident response tools and technologies such as SIEM, EDR, and forensic analysis tools

Duties and Responsibilities

Support PLDT Group's cyber incident response operations by assisting in the timely detection, containment, and mitigation of security incidents, breaches, and emerging threats. Collaborate closely with the Cyber Security Response Team and internal security units to facilitate effective and timely incident resolution, minimizing business disruption. Participate in post-incident reviews and contribute to integrating lessons learned into response playbooks and security practices to

enhance the organization's overall cyber resilience.

Incident Detection and Analysis:

  • Monitor security alerts and events from various sources, including SIEM platforms, threat intelligence feeds, and security tools, to identify potential security incidents.
  • Analyze incidents to assess their impact, scope, and the tactics, techniques, and procedures (TTPs) used by attackers.
  • Conduct investigations to determine root causes, including performing forensic analysis on affected systems and networks.

Incident Containment and Eradication:

  • Implement containment strategies to prevent the spread of security incidents, such as isolating affected systems and blocking malicious traffic.
  • Collaborate with key stakeholders and security teams to eradicate threats by removing malware, closing vulnerabilities, and securing compromised accounts.
  • Ensure all containment and eradication actions are thoroughly documented, and that affected systems are fully cleaned and restored.

Incident Recovery:

  • Support the secure restoration of affected systems and networks to normal operations.
  • Collaborate with IT and relevant stakeholders to apply necessary patches, updates, and security measures following an incident.
  • Participate in post-incident reviews to capture lessons learned and identify opportunities for improvement.

Collaboration and Communication

  • Work closely with key stakeholders, including Internal Cyber Security Operations, Threat Intelligence, Incident Investigation, IT, and Network teams, to ensure a coordinated and effective incident response.
  • Communicate incident status, findings, and actions promptly to the Incident Response Head and other relevant stakeholders.
  • Provide valuable input and recommendations to enhance incident response processes and tools.

Documentation and Reporting

  • Accurately document all aspects of incident response activities, including timelines, actions taken, and outcomes.
  • Assist in preparing detailed incident reports that include thorough analysis and actionable recommendations to prevent future occurrences.
  • Ensure all documentation is up-to-date, precise, and readily accessible for audits and reviews.

Tool and Technology Use

  • Utilize a wide range of security tools and technologies, including SIEM platforms, endpoint detection and response (EDR) tools, and forensic analysis software, to support incident response efforts.
  • Stay current with the latest tools, techniques, and technologies, and actively participate in training and development to continuously enhance technical skills.

Continuous Improvement

  • Contribute to the ongoing enhancement of incident response processes by identifying improvement opportunities and suggesting actionable changes.
  • Stay informed about emerging cyber threats, attack vectors, and response methodologies.
  • Pursue relevant training, certifications, and professional development to maintain and advance incident response expertise.

Operational Support

  • Perform other related functions and responsibilities as assigned, supporting team and organizational goals with flexibility and responsiveness.

More Info

Job Type:
Industry:
Function:
Employment Type:

Job ID: 152485665

Similar Jobs

Philippines

Skills:

ServicenowIpsWafFirewallnacEASService Management ToolsSecurity Monitoring

Beware of Scammers

We don’t charge money for job offers