Computer Security Incident Response Expert

2 weeks ago


Singapore Crédit Agricole CIB Full time

**Description du poste**:
**Position**
Computer Security Incident Response Team Expert (CSIRT Expert)

CSIRT Expert is a technical expert role within the Asia Information System Security (ISS) Team, Singapore, functionally aligned to Group’s ISS CSIRT team in Head Office, France.
ASIA ISS team oversees and supervise the Information System Security related matters in the region, including cybersecurity monitoring (SOC), incident response (CSIRT) and responding to each country's regulation proactively.
The ASIA ISS CSIRT oversees detection, control and reporting of cyber incidents when it occurs and work closely with IT Operations team to recover and restore the systems that are affected by the security incident.
In this role, CSIRT Expert role will be responsible for responding and managing end to end Security Incident Management Lifecycle: Incident Identification, Triage, Containment, Eradication, Recovery and Lesson Learnt. Person will be technical point of contact to respond and drive the security incidents response in the region.

**Job Responsibilities
**The Expert has a wide spectrum of responsibilities and will be responsible for following activities (but not limited to) in day-to-day work:

- Identifying and detecting Incidents and taking immediate action on security incidents including (and not limited to) DoS attacks, malware attacks, phishing attacks, web attacks;
- End to end ownership in driving and leading Security Incident Response and Resolution activities;
- Participate and support performing forensics investigations as required to respond to the Security Incidents;
Responding to Security Threats and Intelligence alerts & notifications from Group CERT, Regional Regulators and authorized Threat Intelligence groups and ensuring appropriate preventive and detective actions are coordinated and deployed in liaison with IT Operations teams as per the defined approach and in timely manner;
- Owning end to end coordination, communications and deployment of action plans for Threat Advisories or lesson learnt from Security Incidents;
- Prepare detailed Incident Post-mortem report and Executive Summary to document the Security Incident chronology, root cause, remediation and lesson learnt;
- Creating and updating the incident response plan (IRP) and playbooks and ensuring periodical review of playbooks to ensure the relevancy of response actions in current context, including updated information of all stakeholders involved;
- Collaborate with other Geo’s CSIRT team members on security matters and act as a backup to manage security incident and other security activities in scope as needed;
Periodic review of security measures of Networks (Switches. Routers, Firewall, IPS, etc.) and Systems (Win*,*NIX, etc.) in support of management of vulnerabilities;
- Support and integrate with incident response, threat ntelligence, and overall security strategy as needed;
- Complete all mandatory trainings as required to attain and maintain competence;
- Niveau d'étude minimum
- Bac + 3 / L3
- Formation / Spécialisation
- Bachelor and above in relevant discipline
**Work Schedule**
v Work Hours: 8.45a.m. to 6. 30p.m (Monday to Friday) with one-hour lunch break.
- CSIRT team globally follows ‘follow-the-sun’ model and work on Critical incidents from other geographies during Asia business hours;
- Niveau d'expérience minimum
- 6 - 10 ans
- Compétences recherchées
- **Qualification Requirements**
Ø Bachelors graduate or equivalent technical degree in Information Technology or Computer Science;
Ø Must have minimum 10 years of experience in IT and 5-7 years of working experience in cyber security incident response role managing Security Incidents and performing log analysis and forensic analysis for an enterprise level environment;
Ø Working experience in financial organisation is preferred;
Ø Expertise in SIEM and SOC Processes;
Ø Strong functional knowledge of enterprise level Security Detection and Prevention technologies e.g. Firewalls, IPS/IDS, Network Packet Analysis and Endpoint log analysis, server log analysis, SIEMs, Vulnerability Scanning tools, Threat intel, Anti-Malware, Phishing Prevention and Endpoint Detection & Response (EDR); Scripting knowledge using Python, Perl, PowerShell;
Ø Must have strong understanding of different domains of IT Security cyber kill chain, IOCs, and attack frameworks
Ø Excellent in analytical and problem-solving skills, communication and documentation skills;
Ø Ability to work independently and priories work as well as a part of team with mínimal supervision;
Ø Demonstrate Strong sense of responsibility and initiative with excellent communication and interpersonal skills time management skills;
Ø Excellent written and oral English language skills;
Professional Certifications:

- Outils informatiques
- **Entreprise Crédit Agricole CIB**:



  • Singapore Crédit Agricole CIB Full time

    Job description **Business type**: - Types of Jobs - IT, Digital et Data **Job title**: - Computer Security Incident Response Expert **Contract type**: - Permanent Contract **Job summary**: **Position** Computer Security Incident Response Team Expert (CSIRT Expert) CSIRT Expert is a technical expert role within the Asia Information System Security...


  • Singapore MDIS Pte Ltd Full time

    We are now inviting applications for an Incident Response Expert position in the Division of Academic Computing & Information Services at MDIS Pte Ltd.About the RoleThe successful candidate will be responsible for leading investigations of IT security incidents, conducting root cause analysis and remediation, and developing forensic investigation procedures...


  • Singapore CROWDSTRIKE SINGAPORE PTE. LTD. Full time

    About the Role">The Incident Response and Cloud Security Expert will play a critical role in helping organizations respond to security incidents effectively.This includes:Developing and implementing effective incident response strategies for our clients.Leveraging expertise in cloud forensics and incident response to assist clients in identifying, responding...


  • Singapore Cygnify Full time

    Threat Intelligence and Incident Response ExpertCygnify is seeking a skilled Threat Intelligence and Incident Response Expert to join our team in Singapore. As a Threat Intelligence and Incident Response Expert, you will be responsible for monitoring, detecting, and responding to security incidents to ensure the protection of our financial systems and...


  • Singapore SINGAPORE AIRLINES LIMITED Full time

    Job Description:The Security Monitoring and Response Expert will play a critical role in identifying and mitigating potential security threats to our corporate networks, systems, and digital assets. This position requires a strong background in security operations, incident response, and threat intelligence.Key Responsibilities:Monitor security-relevant data...


  • Singapore SKY & F PTE. LTD. Full time

    Activities to detect, contain, respond and recover from a security incident to minimize damage and reduce recovery time and costs - Lead and support detailed investigations and analysis of security related findings, alerts and events across the Azure logical and physical infrastructure - Perform Root Cause Analysis (RCA), develop mitigation strategies and...

  • IT Security Analyst

    2 weeks ago


    Singapore Synapxe Full time

    Job SummarySynapxe is seeking a skilled Cybersecurity Analyst to join our team. The successful candidate will be responsible for identifying, investigating, and responding to cybersecurity incidents to protect our organization's information systems and data.The ideal candidate will have experience in threat analysis, digital forensic investigations, and...


  • Singapore Singtel Group Full time

    We're driven by our commitment to valuing our clients, growing our people, and creating our future. As a Threat Detection and Response Lead, you'll play a crucial role in helping us achieve these goals.The successful candidate will be responsible for working closely with multiple teams on the development of Cyber Operations and formulating incident response...


  • Singapore AETOS SECURITY MANAGEMENT PTE. LTD. Full time

    Key ResponsibilitiesMonitor attendance records of AETOS employees and provide detailed reports to management.Manage security access control points and administer clearance for individuals and vehicles.Respond to alarm alerts, activate response teams, and prepare incident reports.Monitor video analytics CCTV systems and respond accordingly.


  • Singapore CRIMSONLOGIC PTE LTD Full time

    Key AccountabilitiesMonitor and analyze security events in a timely mannerIdentify potential security risks and threatsEscalate incidents to the Tier 2 SOC analyst and team lead if required


  • Singapore DRW Full time

    We are looking for a Digital Forensics and Incident Response Expert to join our team in Singapore. As a member of our global Security Operations team, you will be responsible for investigating insider threats, driving automated detection, response, and configuration through scripting and programming languages, and evaluating new technologies.About the...


  • Singapore MSD Full time

    Cyber Security Incident Response Specialist - Opportunity to **be a part of the Information Technology Risk Management and Security’s Cyber Fusion Center in Singapore!**: - **Based in Singapore,** the regional hub for Asia Pacific (AP) and top-ranked biopharmaceutical company on The Straits Times and Statista’s list of Best Employers in Singapore for...


  • Singapore SINGAPORE AIRLINES LIMITED Full time

    About the Job:We are seeking a highly experienced Security Incident Response Director to lead and direct the efforts of our Group Information Security Team in responding to cyber security threats and incidents. This role requires a high level of technical expertise, business acumen, and leadership skills to effectively manage and mitigate cyber security...


  • Singapore ENSIGN INFOSECURITY (CYBERSECURITY) PTE. LTD. Full time

    **Duties and Responsibilities** - Lead and coordinate the activities of security operations and effective response to information security threats within clients’ technology environments - Lead security incident response processes, identify and measure critical security operations metrics and continually improve service delivery to clients - Provide...


  • Singapore Synapxe Full time

    About the RoleSynapxe is seeking an experienced Cybersecurity Analyst to join our team. The successful candidate will be responsible for identifying, investigating, and responding to cybersecurity incidents, ensuring the integrity and confidentiality of our organization's information systems and data.The ideal candidate will have a solid understanding of...


  • Singapore MSD Full time

    Cyber Security Incident Response Associate Specialist - Opportunity to **be a part of the Information Technology Risk Management and Security’s Cyber Fusion Center in Singapore!**: - **Based in Singapore,** the regional hub for Asia Pacific (AP) and top-ranked biopharmaceutical company on The Straits Times and Statista’s list of Best Employers in...


  • Singapore BANK OF MONTREAL SINGAPORE BRANCH Full time

    **Job Description Additionally, the Incident Response (IR) Specialist accountable to lead the response effort for security incidents including review of alert post-escalation, investigation of the incident, containment of the threat, and remediation of issues leading to the threat affecting BMO. **Job Requirements - Minimum 4 years of Enterprise Incident...


  • Singapore Sedha Consulting Full time

    Job Title: Incident Response SpecialistJob SummarySedha Consulting is seeking an experienced Incident Response Specialist to join our team. As a key member of the incident response team, you will be responsible for conducting detailed investigations into security breaches and analyzing data to reconstruct events and understand the methods and pathways of...


  • Singapore LANTU EMPLOYMENT AGENCY PTE. LTD. Full time

    LANTU EMPLOYMENT AGENCY PTE. LTD. is seeking an experienced Security Incident Response Analyst to join their team in Singapore. This is a full-time on-site role that requires excellent analytical and problem-solving skills.About the RoleMaintaining strong relationships with the end client SOC team to ensure seamless incident response and managementPerforming...


  • Singapore Hays Full time

    **Your new company** The client is a local security solution provider working mainly with projects within the government. Their service ranges from design and development to implementation and post-implementation maintenance. **Your new role** You will be involving in activities to detect, contain, respond and recover from security incident, this includes...