As a member of the ETMSA , you will be integral to responding to and managing cybersecurity threats and incidents throughout their lifecycle – from Preparation to Identification, Containment, Eradication, Recovery, and Lessons Learned – collaborating with a global team of incident responders.
You will apply your comprehensive skills in cyber defense, digital forensics, log analysis, and intrusion analysis to address security incidents across our endpoints, network, and cloud infrastructure. In this role, you will be responsible for prevention, detection, response, and remediation activities, ensuring that information assets and technologies are adequately protected by leveraging various technologies such as 下一頁-Generation Firewalls (NGFW), Endpoint Detection and Response (EDR), Intrusion Detection/Prevention Systems (IDS/IPS), Data Loss Prevention (DLP), and more.
You will also leverage your collaboration and communication skills to work effectively with all relevant stakeholders in multicultural and global environments.
Responsibilities
Report to Director to facilitate all phases in the incident response lifecycle
Be involved in various incident prevention projects to improve Security posture
Preparation
Understand different regulatory and compliance requirements like critical time to report, escalation flows, etc.
Take part in self-assessment exercises like Tabletop Exercises, Attack Simulations, Red/Purple Team exercises to make sure the incident response process is working smoothly
Develop incident response runbooks, playbooks and SOPs with reference to different regulatory requirements
Evaluate the incident response readiness of different layers – people, process, technology
Detection & Analysis
Respond to the cyber security incidents escalated from various channels including the 24/7 SOC team.
Respond to cyber security incidents in compliance with the local authority / regulatory requirements.
Assess the risk, impact and scope of the identified security threats
Perform deep-dive incident analysis of various data sources by analysing and investigating security related logs against medium-term threats and IOCs
Containment, Eradication and Recovery
Communicate with the stakeholders and provide guidance, recommendations to contain and eradicate the security incident
Participate in root cause analysis using forensic and other custom tools to identify any sources of compromise and/or malicious activities taking place.
Document and present investigative findings for high profile events and other incidents of interest.
Post incident activities
Provide lessons learnt meeting to the stakeholders
Lead and keep track on the follow-up activities
Document the incident in the case management system and provide incident reports
Always ready to jump in, in the event of security incidents.
Requirements
At least 2 years experience in the Cyber Security industry
Strong technical and analytical skills
Familiar with the cyber security incident response process
Familiarity with AI tools and their application in automating security tasks and processes.
Hands-on experience on performing incident response activities
Have scripting experience like Bash, PowerShell, Python, Go, etc, and the ability to use these skills to aid in responding to incidents involving Windows, Linux, macOS, as well as cloud environment
Have knowledge of cybersecurity tools and software like NGFW, EDR, IDS/IPS, EDR, DLP, SIEM, other log management platforms, etc.
Be familiar with the MITRE ATT&CK Framework and/or Cyber Kill Chain
Be passionate on exploring new technologies and having creative initiative to boost the team capabilities
Holders of security related certifications is a plus (e.g.Azure, AWS, CISSP, GCIH, GCIA, GCFA, GNFA, GREM, or other equivalent)
Awareness of regulatory and compliance requirements like GDPR, MAS, PSD2 etc is a plus.
Preferably
Fast learner with can do attitude and ready to get the hands dirty
A strong team player who can collaborate with compassion
Passionate to learn and willing to put in the extra effort
Understand the concept of ownership and accountability coupled with sense of urgency and prioritisation
Confidence in handling incidents and managing relevant senior and technical stakeholders
Possess business acumen/mindset (not only technical) when making critical decisions
#J-18808-Ljbffr
工作資料:
公司名稱: Crypto.com
職位: Incident Response Engineer
工作地點: 香港
國家: HK
如何提交申請:
在閱讀並了解職位資料中說明的入職標準及最低資格要求後, Incident Response Engineer at the office 香港 以上,請立即準備好求職信、履歷表(CV)、畢業證書副本及其他證明文件。請透過下方的「下一頁」連結提交申請。
詳情: At AIA we’ve started an exciting movement to create a healthier, more sustainable future for everyone. It’s about finding new ways to not only better people’s lives, but to better the communities and...
詳情: OverviewThe F&A team comprises multiple functions from Financials Control & Business Performance Management, Procurement, Digital Transformation, Tax, Treasury and Operations. Together, the team optim...
詳情: Ultima Markets in 香港 is seeking a detail-oriented professional to manage employee claims and maintain filing systems. The ideal candidate will possess a diploma in Business Administration or Hu...
詳情: Pathos Consultancy Limited in 香港 is seeking a Project Manager to lead end-to-end project lifecycle management. The ideal candidate will have a Bachelor’s degree and 5–8 years of experience in p...
詳情: Contract Project Manager - MPF Operations Support MPF/ORSO operational tasks.Coordinate and manage assigned projects related to MPF and ORSO operations.Analyze workflows and identify operational ineff...