Logo for CyberOne

Incident Response Specialist

Role overview

Qualifications

  • Relevant experience in Cyber Security or Incident Response
  • Strong English communication skills
  • SC-200 Microsoft Security Operations Analyst
  • SC-100 Cybersecurity Architect

Responsibilities

  • Investigate cyber security incidents affecting customer environments
  • Analyze endpoint, network, cloud, and identity-based evidence
  • Support containment, eradication, and recovery activities
  • Produce high-quality investigation reports

About the company

CyberOne logo

CyberOne

CyberOne is trusted by some of the world's most admired brands and organisations to secure their most important asset, their employee, customer and business data. Bringing together the industry's brightest talent and best technologies, our comprehensive end-to-end cyber security services offer a complete protection and recovery service, ensuring resilience against an ever-evolving and increasing threat landscape, delivering relentless 24x7 round-the-clock threat monitoring and incident response, so clients can focus on what they do best. We harness the class-leading Microsoft Security portfolio and combine it with our proprietary technology, to give complete comprehensive Cyber Security resilience. CyberOne delivers the entire Microsoft Security stack as a fully managed service, called Assure 365. Covering all your Security administration and key technology areas such as Identity, MXDR, Endpoint, XDR and Data Security as a Service ensures our clients have time to focus on their strategic, governance and risk objectives. CyberOne is accredited and authorised by the world’s leading standards bodies including the National Cyber Security Centre (NCSC), part of GCHQ in the UK and CREST, across all key areas including Security Operations Centre, Incident Response and Penetration Testing. We are a highly accredited Microsoft Security partner and have a unique approach to delivering MXDR and Security Managed Services to our global client base. Since 2005, CyberOne's mission has been to reduce business risk whilst increasing its operational resilience. We are client and service-centric and our shared values help to support this goal: Customer Defence Focussed, Relentless Innovation, Act Kind - Be Kind, Be Awesome - Demand Awesome and Execute 100%. Cyber security is not just about providing a service, it’s about building a partnership and a secure foundation for your business to thrive. Securing today, safeguarding tomorrow.

Company details

Company size51 - 200

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Job Title: Incident Response Specialist

Location: PH - Fully Remote

Employment Type: Full-time

About The Role

The Incident Response Specialist will play a key role in supporting customers through all stages of a cyber incident, from initial investigation through to containment, eradication, recovery and post-incident reporting.

Working alongside senior Incident Responders and Incident Managers, you will conduct technical investigations, analyse evidence, identify attacker activity and support customers during some of their most critical cyber security events.

The role also supports proactive security services including Incident Response Readiness Assessments, Tabletop Exercises, Threat Hunting and Threat Intelligence activities.

This is an excellent opportunity for an experienced SOC Analyst or early-career Incident Responder looking to develop into a senior DFIR consultant.


What You’ll Do

Incident Response

· Investigate cyber security incidents affecting customer environments.

· Analyse endpoint, network, cloud and identity-based evidence.

· Perform host-based investigations across Windows and Microsoft 365 environments.

· Support containment, eradication and recovery activities.

· Identify attacker tactics, techniques and procedures (TTPs) using the MITRE ATT&CK framework.

· Collect, preserve and analyse forensic artefacts where appropriate.

· Produce Indicators of Compromise (IOCs) and detection recommendations.

· Support evidence collection for regulatory or legal requirements.

Technical Investigation

· Analyse Microsoft Defender XDR telemetry.

· Investigate Microsoft Sentinel incidents.

· Review Windows Event Logs and Sysmon data.

· Analyse Entra ID sign-in and audit logs.

· Investigate Exchange Online activity.

· Perform malware triage and basic static analysis.

· Review firewall, proxy, VPN and authentication logs.

· Conduct threat hunting activities across customer environments.

Customer Engagement

· Participate in customer investigation calls.

· Explain technical findings to both technical and non-technical audiences.

· Produce high-quality investigation reports.

· Provide remediation recommendations.

· Support post-incident lessons learned workshops.

Proactive Services

Support delivery of:

· Incident Response Readiness Assessments

· Tabletop Exercises

· Threat Hunting engagements

· Threat Intelligence services

· Security posture reviews

· AI security investigations where required

Continuous Improvement

· Develop new investigation playbooks.

· Improve Incident Response procedures.

· Contribute to internal knowledge sharing.

· Support development of detection content.

· Assist with automation opportunities using Microsoft and AI technologies.

Employees are expected to demonstrate a security-first mindset and ensure that information security considerations are incorporated into their day-to-day activities, decision-making, and interactions with customers, suppliers, and colleagues.

What We’re Looking For

Essential

· Relevant experience in Cyber Security or Incident Response.

· Strong English communication skills.

Advantageous

· SC-200 Microsoft Security Operations Analyst

· SC-100 Cybersecurity Architect

· AZ-500 Microsoft Azure Security Technologies

· GCIH

· GCFA

· GNFA

· CompTIA Security+

· CREST Practitioner or equivalent

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Incident Response Analyst Related jobs

Other jobs at CyberOne

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.