Incident Response Specialist
RemotePhilippines
Job Summary
Investigate cyber security incidents affecting customer environments by analysing endpoint, network, cloud, and identity-based evidence across Windows and Microsoft 365 systems. Conduct technical investigations using Microsoft Defender XDR, Sentinel, and Windows Event Logs to identify attacker tactics, techniques, and procedures while collecting forensic artefacts and producing Indicators of Compromise. Support containment, eradication, and recovery activities, then explain technical findings and provide remediation recommendations during customer investigation calls. Develop new investigation playbooks, improve Incident Response procedures, and contribute to internal knowledge sharing while supporting threat hunting and readiness assessments.
Required Qualifications
- Relevant experience in Cyber Security or Incident Response
- Strong English communication skills
Desired Qualifications
- SC-200 Microsoft Security Operations Analyst
- SC-100 Cybersecurity Architect
- AZ-500 Microsoft Azure Security Technologies
- GCIH
- GCFA
- GNFA
- CompTIA Security+
- CREST Practitioner or equivalent
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.