All jobs
StarHub

Senior Incident Response Specialist

StarHub

Petaling Jaya, MY, Malaysia · RemoteSeniorFull-timeSystems Sign in for match

About the role

Responsibilities

  • Monitor alerts generated from the SOC/SIEM and perform initial to intermediate-level investigations.
  • Review and validate security events from multiple log sources and identify legitimate threats.
  • Perform deep-dive investigations for incidents involving malware, phishing, insider threats, and cloud breaches.
  • Assist in detection rule creation and tuning under the guidance of senior incident responders.
  • Use frameworks like MITRE ATT&CK for mapping and improving detection quality.
  • Conduct threat hunting using Elastic Stack and related tools.
  • Collaborate with MSSP, CSIRT, and IT infrastructure teams to ensure timely incident handling.
  • Support incident response reporting, evidence collection, and documentation for compliance and audit.
  • Contribute to automation opportunities in detection and response workflows.
  • Participate in training sessions, simulations, and tabletop exercises to enhance readiness.
  • Responsible for the log source onboarding and managing the continuous logs availability on the SIEM platform.

Areas of Impact:

  • Scope: Operational role responsible for incident triage, analysis, and escalation within enterprise-wide SOC operations. Involves intermediate-level SIEM management (Elastic Stack) focusing on log analysis and event correlation. Covers on-premises, cloud, and hybrid infrastructure environments.
  • Decision Rights: Authority to validate and escalate confirmed incidents to the CSIRT or Assistant Manager. Can recommend new use cases and detection rules, subject to review and approval. Authorized to perform containment actions under predefined playbooks or guidance.
  • Stakeholders: ISO / CSIRT Team, SOC L1 Team, IT Infrastructure / Cloud / Application Teams, Risk & Compliance Team, External MSSP / Security Vendors.
  • Resources: Elastic SIEM (Elasticsearch, Logstash, Kibana, Beats), EDR / NDR tools, Threat Intel Feeds, SOAR platforms, and support from SOC Analysts, CSIRT, and IT Operations teams.

Ideal Track Record:

  • 2–3 years of experience in a SOC or Incident Response (L2) environment.
  • Intermediate hands-on experience with SIEM platforms (Elastic Stack preferred).
  • Exposure to incident triage, malware analysis, phishing response, and log correlation.
  • Strong understanding of use case creation and MITRE ATT&CK framework mapping.
  • Demonstrated ability to analyze complex alerts and distinguish false positives from true incidents.
  • Familiarity with security tools such as EDR, NDR, Cyber security tools and threat intelligence platforms.
  • Good communication and documentation skills for stakeholder updates.
  • Certifications such as CEH, CompTIA Security+, GCIA, or Elastic Certified Analyst preferred.