Department Manager - Cyber Incident Management
On-siteSuan Luang, Bangkok, Thailand
Job Summary
Lead end-to-end incident response lifecycle management at CP Axtra, serving as Incident Commander for Severity-1 and Severity-2 events to drive real-time containment decisions, stakeholder communications, and escalation paths. Build and maintain a library of 15 scenario-specific playbooks covering ransomware, credential compromise, and insider threats, while executing quarterly tabletop exercises and annual red team engagements to validate operational effectiveness. Manage SOC operational KPIs including MTTD under 30 minutes and MTTR under four hours, driving post-incident reviews that produce tracked remediation actions rather than generic recommendations. Coordinate with legal, compliance, and communications teams during regulatory incidents, maintain threat intelligence pipelines to operationalize IOCs within 24 hours, and oversee MSSP/MDR provider relationships through monthly SLA reviews. Fluent in Thai with five years of cybersecurity leadership experience, you will mentor SOC analysts and ensure lessons learned feed into technical controls and governance processes.
Required Qualifications
- 5+ years in cyber security with at least 2 years leading incident response or SOC operations
- Demonstrated experience as Incident Commander during real security incidents — you've made containment decisions under pressure, not just participated in tabletops
- Strong knowledge of attack frameworks (MITRE ATT&CK, Cyber Kill Chain) and ability to map real incidents to TTPs for detection improvement
- Experience with EDR/XDR platforms (Cortex XDR, CrowdStrike, or equivalent) and SIEM — you can investigate alongside your analysts, not just manage from a dashboard
- Excellent communication skills — ability to translate technical incident details into business impact language for executives and non-technical stakeholders
- Fluent in Thai; working English proficiency for vendor coordination and threat intelligence consumption
Desired Qualifications
- GCIH, GCFA, GCIA, or equivalent incident response / forensics certifications
- Experience managing MSSP/MDR relationships and holding third-party SOCs accountable to SLAs
- Familiarity with Thai regulatory incident reporting requirements (PDPA breach notification timelines, sector-specific reporting)
- Experience with incident response in retail or e-commerce environments — POS malware, card skimming, credential stuffing at scale
- Purple team experience — working with offensive security teams to validate detection and response capabilities
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.