The Incident Response Lead is responsible for leading cyber incident detection, investigation, containment, eradication, recovery, and post incident activities across Axiata Cyber Fusion Center (ACFC). The role provides technical leadership and coordination for cyber incident response, digital forensics, threat hunting, intelligence-driven defense, and continuous improvement of detection and response capabilities.
The incumbent will work closely with SOC analysts, Security Engineering, Threat Intelligence, Operational Companies (OpCos), Technology teams, and external partners to ensure timely and effective handling of cyber threats and incidents while strengthening the organization's cyber resilience.
Key Responsibilities
Cyber Incident Response & Management
Lead the end-to-end management of cyber security incidents, ensuring appropriate prioritization, investigation, containment, eradication, and recovery activities
Act as the primary escalation point for high-severity security incidents and coordinate incident response activities across OpCos and stakeholders
Direct cyber incident bridge calls and crisis management activities during major security incidents
Ensure incident response activities are executed in accordance with established SLAs, regulatory requirements, and organizational policies
Develop and maintain incident response playbooks, runbooks, escalation matrices, and standard operating procedures (SOPs)
Conduct post-incident reviews, root cause analysis, lessons learned sessions, and track remediation actions
Security Monitoring & Detection Enhancement
Provide guidance and oversight to SOC analysts and managed security service providers to improve detection accuracy, triage quality, and investigation effectiveness
Review and validate alerts escalated from monitoring teams to ensure accurate contextualization and prioritization
Drive continuous enhancement of security monitoring use cases, detection content, correlation rules, and threat detection frameworks
Collaborate with Security Engineering teams to improve visibility, telemetry, and detection coverage across enterprise environments
Digital Forensics & Malware Analysis
Lead forensic investigations involving endpoint, network, cloud, and mobile environments
Perform or oversee digital evidence acquisition, preservation, analysis, and reporting in accordance with forensic standards
Conduct advanced malware analysis and reverse engineering activities to determine attack methodologies, indicators of compromise (IOCs), and business impact
Support legal, regulatory, and compliance investigations where digital forensic expertise is required
Threat Intelligence & Threat Hunting
Analyze emerging cyber threats, vulnerabilities, adversary tactics, techniques, and procedures (TTPs) to improve defensive capabilities
Convert threat intelligence into actionable detection rules, hunting hypotheses, and response actions
Lead proactive threat hunting activities leveraging MITRE ATT&CK and intelligence-led methodologies
Coordinate with internal and external intelligence sources to assess risks affecting Axiata Group and OpCos
Automation & Continuous Improvement
Drive security orchestration, automation, and response (SOAR) initiatives to improve operational efficiency and reduce mean time to detect (MTTD) and mean time to respond (MTTR)
Identify opportunities for process optimization, workflow automation, and operational maturity enhancements
Evaluate emerging cyber security technologies and recommend adoption based on business and operational requirements
Contribute to the strategic development and maturity roadmap of ACFC's incident response capabilities
Security Testing & Readiness
Coordinate cyber security assessments, threat-led exercises, tabletop simulations, red team engagements, and breach attack simulations
Validate detection and response capabilities against identified threats and attack scenarios
Provide guidance and recommendations for remediation and risk reduction initiatives
Support cyber crisis exercises and preparedness activities across the Axiata Group
Leadership & Stakeholder Management
Provide technical leadership, coaching, and mentoring to SOC analysts and incident responders
Engage effectively with senior management, technology teams, risk, compliance, legal, and external partners during security incidents
Prepare executive-level incident reports, risk summaries, and operational metrics
Foster collaboration across multicultural and geographically distributed teams
Key Performance Indicators (KPIs)
Achievement of Incident Response SLA and KPI targets
Reduction in Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR)
Timely containment and eradication of high and critical severity incidents
Improvement in detection use case effectiveness and detection coverage
Successful execution of threat hunting and proactive detection initiatives
Enhancement of automation and orchestration within incident response processes
Quality and completeness of forensic investigations and incident reports
Completion of post-incident reviews and remediation tracking
Stakeholder satisfaction and effective coordination during major incidents
Contribution towards ACFC operational maturity and cyber resilience objectives
Person Specifications
Education
Bachelor's Degree in Cyber Security, Information Security, Computer Science, Information Technology, or related discipline
Master's degree or relevant advanced studies is an added advantage
Experience
Minimum 8 years of experience in Cyber Security Operations, Incident Response, or Cyber Defense functions
Minimum 5 years of hands-on experience managing cyber incidents in enterprise or regional environments
Experience operating within a SOC, Cyber Fusion Center, CSIRT, CERT, or Incident Response environment
Experience managing security incidents across multi-country or regional operations is highly preferred
Experience with cloud incident response (Azure, AWS, GCP) is highly desirable
Professional Certifications (Preferred)
GIAC Certified Incident Handler (GCIH)
GIAC Certified Forensic Analyst (GCFA)
GIAC Reverse Engineering Malware (GREM)
Certified Incident Handler (EC-Council ECIH)
Certified Ethical Hacker (CEH)
Certified Information Systems Security Professional (CISSP)
GIAC Certified Intrusion Analyst (GCIA)
CrowdStrike Certified Incident Responder (CCIR)
Microsoft Cybersecurity Architect Expert or equivalent
Technical Competencies
Strong knowledge of incident response lifecycle, digital forensics, malware analysis, and threat hunting methodologies
Deep understanding of MITRE ATT&CK framework, cyber kill chain, and adversary emulation techniques
Strong knowledge of Advanced Persistent Threats (APT), ransomware, business email compromise, insider threats, and cloud-focused attacks
Experience with: o SIEM platforms (Microsoft Sentinel, Splunk, QRadar) o EDR/XDR platforms (CrowdStrike, Microsoft Defender, Carbon Black) o SOAR platforms o Network Detection & Response (NDR) o Threat Intelligence platforms o Email Security platforms o Cloud Security technologies
Strong understanding of: o TCP/IP networking o Network security monitoring o Firewalls, IDS/IPS o DNS, Proxy and Web Security o Endpoint Security technologies
Semua Iklan Pekerjaan adalah tertakluk kepada Terms of Service GrabJobs. Kami membenarkan pengguna membenderakan siaran yang mungkin melanggar syarat tersebut. Iklan Pekerjaan juga mungkin dibenderakan oleh pasukan penyederhana GrabJobs. Walau bagaimanapun, tiada sistem penyederhanaan yang sempurna dan membenderakan siaran tidak memastikan bahawa ia akan dialih keluar.
Jadilah orang yang pertama menerima Others Full-Time Jobs terkini di Malaysia.
Sediakan makluman pekerjaan:
Dengan mengaktifkan makluman kerja, saya bersetuju menerima GrabJobs Terms & Privacy Policy. Saya boleh berhenti melanggan makluman kerja pada bila-bila masa.
Langkau
Anda mencapai bilangan maksimum makluman kerja anda.
GrabJobs ialah portal pekerjaan no1 di Malaysia, menghubungkan anda dengan beribu-ribu pekerjaan dengan pantas!
Cari kerja terbaik di Malaysia, mohon dalam 1 klik dan dapatkan pekerjaan hari ini!