- Experience
- 2–3 yrs
- Salary
- —
- Openings
- 1
- Posted
- 3 કલાક પેહલા
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Job Overview
The Senior Incident Responder at StarHub plays a critical role in the Security Operations Centre (SOC), overseeing cybersecurity event monitoring, detection, and detailed incident analysis. Tasked with managing the entire incident response cycle, this role ensures prompt handling from initial triage through investigation, containment, and incident closure, safeguarding StarHub's cyber defense posture. As a Level 2 responder, this position serves as a technical interface between SOC analysts and Incident Response leadership, coordinating effectively to resolve complex threats.
Key Responsibilities
- Carry out comprehensive triage and investigative processes for security alerts escalated from Level 1 analysts.
- Ensure swift incident analysis and containment actions, aligning with defined Metrics such as Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR).
- Maintain and enhance the SIEM platform, particularly Elastic Stack, by refining current detection rules and proposing novel ones.
- Analyze logs from diverse sources including network, endpoints, and cloud environments, correlating data effectively.
- Document incidents thoroughly, prepare reports, and extract lessons learned post-incident.
- Execute defined playbooks during incident containment and recovery stages.
- Collaborate closely with IT, network, and application teams to facilitate remediation and root cause investigations.
- Offer input to enhance detection use cases and actively participate in their validation and testing phases.
- Escalate confirmed incidents to the Cyber Security Incident Response Team (CSIRT) or Assistant Manager for further action.
- Engage in post-incident reviews to improve detection and response processes continuously.
- Monitor and investigate alerts from SOC/SIEM, conducting initial to intermediate incident reviews.
- Validate security events from multiple log sources, differentiating genuine threats.
- Conduct in-depth investigations on malware, phishing, insider threats, and cloud breach incidents.
- Assist in the creation and adjustment of detection rules under senior guidance.
- Apply frameworks such as MITRE ATT&CK to enhance detection capabilities.
- Perform threat hunting activities using Elastic Stack and complementary tools.
- Work with Managed Security Service Providers (MSSP), CSIRT, and infrastructure teams to ensure timely incident resolution.
- Support compliance and audit requirements through detailed incident reporting and evidence management.
- Identify automation opportunities within detection and response workflows.
- Participate in training, simulations, and exercises to boost operational preparedness.
- Manage log source onboarding and maintain continuous log availability on the SIEM platform.
Required Qualifications and Skills
- A minimum of 2 to 3 years of practical experience within SOC or L2 Incident Response roles.
- Hands-on skills with SIEM technologies, with a preference for Elastic Stack expertise.
- Proficiency in incident triage, malware forensics, phishing mitigation, and multi-source log correlation.
- Strong knowledge of use case development and the MITRE ATT&CK framework.
- Capability to critically analyze complex alerts, identifying false positives versus genuine incidents.
- Familiarity with endpoint detection and response (EDR), network detection and response (NDR), cybersecurity tools, and threat intelligence platforms.
- Effective communication and documentation aptitude for stakeholder engagement.
- Certifications such as Certified Ethical Hacker (CEH), CompTIA Security+, GIAC Intrusion Analyst (GCIA), or Elastic Certified Analyst are advantageous.
Level
Senior
Industry
Telecommunications