Cybersecurity Incident Response SME proactively monitors, detects, and responds to cybersecurity incidents. The role involves ownership of the entire Cybersecurity incident lifecycle, ensuring the security and resilience of StarHub IT assets.
Requirements
- Monitor, triage, and investigate alerts from multiple log sources
- Create, refine, and manage SIEM detection rules
- Conduct log analysis and event correlation
- Drive use case ideation and validation
- Manage and maintain Elastic Stack components
- Lead integration efforts with tools such as EDR, firewalls, cloud platforms, and ticketing systems
- Collaborate with IT, Network, and Cloud teams for incident follow-up, containment, and recovery
- Present incident findings, root cause analyses, and remediation plans to key stakeholders
- Document and enhance incident response playbooks and standard operating procedures
- Conduct post-incident reviews and implement lessons learned
Benefits
- Competitive salary
- Benefits package
- Opportunities for professional growth and development