Cyber Crime | Incident Response Analyst II @ Astreya
3 weeks ago
Astreya Home - WORKING INOVATION Astreya is a leading global provider of game-changing IT Managed Services and Technology Solutions to some of the world’s most View all jobs at Astreya
Our IRC (Incident Response Center) is the first layer of defense responsible for quick detection and incident response using various monitoring and automation tools, conducting thorough investigation of alerts, classification and triage. The IRC Analyst is responsible for delivering operations within the IRC across all datacenter sites in the respective regions. IRC analysts are expected to respond to all alarms/alerts set in Data Center Infrastructure Management (DCIM), Server Automation Operations System (SAOS), CCTV, Access Control Systems (ACS), and other functions (EHS, Security, etc), providing deep understanding and intelligence of the criticality and impact of the incidents to the resolver groups.
Incident & Problem Management
Investigate and respond to alerts, incident response (war room, remote bridges) and report, and on-going maintenance, tuning, and improvements of the detection signals
Respond to incidents and critical situations in a calm, problem-solving manner, and conduct in-depth investigation of alerts
Be the first layer of defense responsible for quick detection and incident response using various monitoring and automation tools, conduct thorough investigation of alerts, classification and triage.
Provide deep understanding and intelligence of the criticality and impact of the incidents to the resolver groups.
Ensure detailed records of alarm handling activities, including actions taken, resolutions in ticketing tools and file incident reports.
Be available to coordinate as an incident commander in event of an issue.
Support program managers and facilitate project deliverables, improve overall operational and engineering initiatives.
Conduct root cause analysis (RCA) to determine recurring problems to their source.
Employ in-depth questioning and analysis techniques such as five whys to determine the underlying cause of the incident or problem.
Perform duties in compliance with SOP.
Server, DCIM, Network and Traffic Alarms Operations
Continuously monitor alarm dashboards and systems.
Investigate and respond to alarms such as but not limited to Network, DC Environment, Server Health, Facility Security and Safety.
Identify and acknowledge incidents associated with alarms.
Assess incidents to determine their criticality and impact on operations.
Engage the resolver group who will be resolving the incident and escalate to higher tiers or management when necessary, following established escalation paths.
Maintain clear and concise communication with relevant teams, stakeholders, and incident responders/resolvers.
Documented procedures to resolve incidents promptly and effectively.
Ensure detailed records of alarm handling activities, including actions taken and resolutions in ticketing tools.
Perform duties in compliance with SOP.
Threat Intelligence & Critical Event Management
Monitor Everbridge's Visual Command Center (VCC), InternationalSOS e-mails, and other open source tools for real-time incidents impacting ByteDance assets and travelers.
Monitor directed tools or queries for specific requests from stakeholders.
Notifications about violence, inclement weather, threats to life, property and assets etc.
Coordinate emergency response efforts, including liaising with law enforcement if needed.
Conduct research to verify the accuracy and relevance of the information through additional sources.
Create heatmap of the affected area to highlight areas impacted by a specific event or series of events.
Collaborate with other security and operational teams for a coordinated response.
Implement incident containment and mitigation strategies.
Document incident details, response actions, and lessons learned.
Perform duties in compliance with SOP.
Physical Security and Safety
Basic monitoring of Closed-Circuit Television (CCTV) systems and Access Control Systems (ACS).
Monitor safety alarms and communication channels for events such as but not limited to electrical incidents, fire & environmental hazards, equipment failure, chemical exposure, water leaks, that pose a risk to the safety of personnel or the data center infrastructure.
Conduct audits of camera footage to ensure proper functioning, video quality, and coverage of critical areas.
Respond to access control incidents and anomalies.
Report findings to the security and safety engineers, and relevant stakeholders promptly.
Perform duties in compliance with SOP.
Badge Management
Perform badge enrolment and ensure that all requests go through proper approval process and to assess accuracy and completeness of request in compliance with SOP.
Access card programming due to access requests such as but not limited to new or temporary access requests via email/ticket, off-boarding by revoking badge access.
Generating access logs reports.
Conduct access log audit.
Identify areas of improvement within current service delivery processes.
Implement changes that lead to measurable enhancements in service quality, efficiency, and customer satisfaction.
Establish a culture of continuous improvement within the organization.
Establish mechanisms for ongoing feedback collection from customers and employees.
Integrate feedback into future continuous improvement efforts.
Required Qualifications/Skills:
2 years+ experience in command center, service center, or similar 24x7 operations center environment
Ability to quickly triage multiple incidents and assign the right priority based on risk and confidence levels
Knowledge of technical elements associated with systems such as IP Networks, DC Environment and Server Health.
Outstanding verbal and written communication skills required, work with minimal direction, meeting goals, attention to details and an eye for continuous improvements
Ability to successfully interact at all levels of the organization, including with clients, while functioning as a team player required.
Basic working knowledge of data protection policies such as GDPR and the need to keep sensitive information secure.
XOC Analyst is expected to work at ByteDance datacenter site. This is an on-site role.
Willingness to work flexible schedules/shifts/areas, including weekends, nights, and holidays.
Excellent verbal and written communication skills in English
Effectively utilize the ticket management systems
Understanding of networking components and infrastructures
Understanding of Data Center best practices (i.e. basic fault tolerance, cable routing, calculating power usage)
Preferred Qualifications:
Diploma/Degree in Information Technology.
Works well under pressure and within time/budget constraints to solve problems and complete deliverables.
Experience with Ticketing, Grafana, Servers and Data Center Systems.
Working knowledge and/or certifications in CompTIA Server+, Schneider Electric Data Center Certified Associate (DCCA).
Knowledge of Lenel and Avigilon systems is a plus.
Hands on experience in electrical, HVAC, and data center infrastructures
Working knowledge of networking components and infrastructures
Ability to adapt to changing priorities, conditions, and circumstances
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.
#J-18808-Ljbffr
-
Principal Consultant, Incident Response
4 weeks ago
Singapore Cyber Crime Full timePrincipal Consultant, Incident Response (Unit 42)Palo Alto Networks Implement Zero Trust, Secure your Network, Cloud workloads, Hybrid Workforce, Leverage Threat Intelligence & Security Consulting. Cybersecurity Services & Education for CISO’s, Head of Infrastructure, Network Security Engineers, Cloud... View all jobs at Palo Alto Networks At Palo Alto...
-
Principal consultant, incident response
4 weeks ago
Singapore Cyber Crime Full timePrincipal Consultant, Incident Response (Unit 42) Palo Alto Networks At Palo Alto Networks everything starts and ends with our mission: Being the cybersecurity partner of choice, protecting our digital way of life. Our vision is a world where each day is safer and more secure than the one before. Who We Are We take our mission of protecting the digital way...
-
Principal Consultant, Incident Response
4 weeks ago
Singapore Cyber Crime Full timePrincipal Consultant, Incident Response (Unit 42)Palo Alto Networks At Palo Alto Networks everything starts and ends with our mission: Being the cybersecurity partner of choice, protecting our digital way of life. Our vision is a world where each day is safer and more secure than the one before. Who We Are We take our mission of protecting the digital way...
-
Cyber Crime | Vulnerability Assessments Analyst
3 weeks ago
Singapore Cyber Crime Full timeVulnerability Assessments Analyst - Red Team, AVP (C12)3 CHANGI BUSINESS PARK CRESCENT CHANGI BUSINESS PARK SINGAPORE Citi Citi is a leading global bank for institutions with cross-border needs, a global provider in wealth management and a U.S. personal bank. The Vulnerability Assessments Analyst - Red Team, AVP will participate in the Adversary Emulation...
-
Cyber Crime | IT Security Officer @ Singtel
5 days ago
Singapore Cyber Crime Full timeSingtel The Singtel Group, Asia's leading communications group provides a diverse range of services including fixed, mobile, data, internet, TV, infocomms technology (ICT) and digital solutions. NCS is a leading technology services firm that operates across the Asia Pacific region in over 20 cities, providing consulting, digital services, technology...
-
Cyber Crime | Security Engineer @ Singtel
3 weeks ago
Singapore Cyber Crime Full timeSingtel The Singtel Group, Asia's leading communications group provides a diverse range of services including fixed, mobile, data, internet, TV, infocomms technology (ICT) and digital solutions. NCS is a leading technology services firm that operates across the Asia Pacific region in over 20 cities, providing consulting, digital services, technology...
-
Cyber Crime | Intern, Group Technology
3 weeks ago
Singapore Cyber Crime Full timeCapitaLand CapitaLand Group (CapitaLand) is one of Asia’s largest diversified real estate groups. Headquartered in Singapore, CapitaLand’s portfolio spans across diversified real estate classes which include integrated developments, retail, office, and more. As an intern in the IT Security team, you will gain hands-on experience in cybersecurity...
-
Principal Threat Researcher
4 weeks ago
Singapore Cyber Crime Full timePalo Alto Networks Implement Zero Trust, Secure your Network, Cloud workloads, Hybrid Workforce, Leverage Threat Intelligence & Security Consulting. Cybersecurity Services & Education for CISO’s, Head of Infrastructure, Network Security Engineers, Cloud... At Palo Alto Networks everything starts and ends with our mission: Being the cybersecurity partner...
-
Vulnerability assessments analyst
3 weeks ago
Singapore Cyber Crime Full timeVulnerability Assessments Analyst - Red Team, AVP (C12) 3 CHANGI BUSINESS PARK CRESCENT CHANGI BUSINESS PARK SINGAPORE Citi Citi is a leading global bank for institutions with cross-border needs, a global provider in wealth management and a U. S. personal bank. The Vulnerability Assessments Analyst - Red Team, AVP will participate in the Adversary Emulation...
-
Principal Threat Researcher
4 weeks ago
Singapore Cyber Crime Full timePalo Alto Networks Implement Zero Trust, Secure your Network, Cloud workloads, Hybrid Workforce, Leverage Threat Intelligence & Security Consulting. Cybersecurity Services & Education for CISO’s, Head of Infrastructure, Network Security Engineers, Cloud... View all jobs at Palo Alto Networks At Palo Alto Networks everything starts and ends with our...
-
Consulting director
2 months ago
Singapore Cyber Crime Full timePalo Alto Networks Implement Zero Trust, Secure your Network, Cloud workloads, Hybrid Workforce, Leverage Threat Intelligence & Security Consulting. Cybersecurity Services & Education for CISO’s, Head of Infrastructure, Network Security Engineers, Cloud... At Palo Alto Networks everything starts and ends with our mission: Being the cybersecurity partner...
-
Cyber incident responder
3 weeks ago
Singapore UBS Full timeYour role Are you keen on working in a world-class Cyber Security Operations Center for one of the best Swiss private banks?Do you have related experience and are willing to take it further by learning how to defend an enterprise against cyber-attacks?We are looking for an incident response expert who will: Respond to cyber security incidents covering all...
-
Cyber Incident Responder
5 months ago
Singapore UBS Full timeYour role Are you keen on working in world class Cyber Security Operations Center for one of the best Swiss private banks? Do you have related experience and are willing to take it further by learning how to defend an enterprise against cyber-attacks? We are looking for an incident response expert who will: • respond to cyber security incidents covering...
-
Cyber Crime | Assistant Director
3 weeks ago
Singapore Cyber Crime Full timeWhat the role is As an Assistant Director, you will lead a department with various functions and operations. You will review policies and manage resources to meet the organisational vision and goals. This position will also require you to play a key role in inspiring a team of staff and enhancing staff capabilities. What you will be working on Manage...
-
Singapore MUFG Bank, Ltd Full timeJob Description The IRMD Cyber Threat and Incident Response is to ensure that key activities in the department relating to Incident Response, Detection mechanisms are in place. Strengthen security policies and standards for the Asia region, to ensure that the security operations, processes, and workflow are compliance with regulations and MUFG's...
-
Cyber Security Specialist
4 weeks ago
Singapore SECURITY & RISK SOLUTIONS PTE. LTD. Full timeJob DescriptionSafeguarding clients' local and remote sites, staff, assets, and sensitive information is a critical responsibility for the ideal candidate.Lead security operations by monitoring, detecting, and responding to incidents in a timely and effective manner.Embark on proactive security measures to protect clients' interests.Tech Stack:Operate...
-
Incident response expert
2 months ago
Singapore Sygnia Full timeSygnia is a top tier cyber technology and services company, providing high-end consulting and incident response support for organizations worldwide. Sygnia works with companies to proactively build their cyber resilience and to respond and defeat attacks within their networks. It is the trusted advisor and cyber security service provider of IT and security...
-
Incident response expert
2 months ago
Singapore Sygnia, Inc. Full timeSygnia is a top tier cyber technology and services company, providing high-end consulting and incident response support for organizations worldwide. Sygnia works with companies to proactively build their cyber resilience and to respond and defeat attacks within their networks. It is the trusted advisor and cyber security service provider of IT and security...
-
Cyber Threat Analyst Expert
1 month ago
Singapore Citi Full timeCiti is seeking a highly skilled Senior SOC Cyber Threat Analyst to join our Cyber Threat team in the Security Operations Center (SOC). The Global SOC operates in a 24x7, follow the sun model and is the firm's first line of defense against evolving cyber threats, ensuring the safety and integrity of our digital assets.About the RoleThis role requires an...
-
Sygnia | Incident Response Expert
3 weeks ago
Singapore Sygnia Full timeSygnia is a top tier cyber technology and services company, providing high-end consulting and incident response support for organizations worldwide. Sygnia works with companies to proactively build their cyber resilience and to respond and defeat attacks within their networks. It is the trusted advisor and cyber security service provider of IT and security...