Cybersecurity Incident Response Engineer

1 week ago


Singapore NodeFlair Full time

**Job Summary**:
**Salary**
S$12,700 - S$16,400 / Monthly

**Job Type**

**Seniority**

Mid

**Years of Experience**
At least 5 years

**Tech Stacks**
OpenID Strategy Powershell OAuth SAML Windows Server LDAP Microsoft Jupyter VMware Puppet Azure Linux Splunk Ansible Python

**Overview**:
With over 18,000 employees worldwide, the Microsoft Customer Experience & Success (CE&S) organization is responsible for the strategy, design, and implementation of Microsoft’s end-to-end customer experience. Come join CE&S and help us build a future where customers come to us not only because we provide industry-leading products and services, but also because we provide a differentiated and connected customer experience.

The Global Customer Success (GCS) organization is leading the effort to create the desired customer experience through support offer creation, driving digital transformation across our tools, and delivering operational excellence across CE&S.

The Detection and Response Team (DART) is hiring for a Cybersecurity Incident Response Infrastructure Specialist to join the team. The DART team provides holistic security incident response leadership and investigations for its customers and helps our customers become cyber-resilient.

This role is a crucial part of a collaborative team that works together to serve as infrastructure specialists and assist our customers collect data critical to the success of an investigation, containment and recovery in the midst of a cyber-attack. You will also implement containment measures, and proactively address threats while also ensuring large-scale infrastructure recovery.

This role is flexible in that you can work up to 100% from home.

Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.

**Responsibilities**:
**Security Software Deployment**
- Lead the deployment and configuration of security tooling at scale across the Microsoft Defender suite of products.
- Provide expert-level support for various identity platforms as well as identity management (IdM) solutions.
- Provide direct feedback to both development teams and product groups for continued product improvements.
- Troubleshoot issues related to the deployment of security tooling.

**Threat Containment**
- Develop and implement threat containment strategies to prevent the escalation of security incidents within the Active Directory, network, and client environments.
- Work in coordination with the larger incident response team to contain and mitigate security threats promptly.
- Implement security measures following both Microsoft and industry standards to contain threats both on-premises and in the cloud.

**Recovery**
- Recovery of Active Directory Forests from destructive based cyber-attacks.
- Recovery of key Infrastructure components across the Microsoft technologies both on-premises and cloud
- Recovery of authentication services such as Active Directory Federation Services and Active Directory Certificate Services.

**Threat Hunting**
- Conduct threat hunting across customer’s networks with indicators of compromise, hunting for evidence of a compromise
- Conduct incident response within various Cloud platforms
- Identify attacker tools, tactics, and procedures to develop indicators of compromise
- Identify and investigate intrusions to determine the cause and extent of the breach, by leveraging EDR solutions and threat intelligence sources

**Troubleshooting Active Directory L300/400: Replication, Group Policy, DFSR**
- Able to understand complex Active Directory environments and resolve issues relating to AD health.
- Experience of supporting complex multi-forest AD topologies
- Experience in authoring and triaging Group Policies in large, regulated environments
- Ability to identify defects or misconfiguration in AD services

**Troubleshooting Windows Server OS Roles (DNS, DFS, Clustering, Storage, Networking)**
- Experience triaging Server roles to restore systems to production state
- Understanding of core networking technologies (DNS, Routing/Switching, Firewalls)

**Troubleshooting Virtualization Platforms (VMware, Hyper-V etc)**
- Experience administering virtual platforms
- Experience in backup/recovery of virtual platforms

**Managing and Configuring Endpoint Security Platforms**
- Experience administering Endpoint Security Platforms: (Microsoft Defender Suite, CS, Falcon etc)
- Experience configuring Endpoint Security Platforms: (IOCs, Agent settings, deployment methods)
- Analyzing endpoint security telemetry using (KQL, Python, Jupyter etc)
- Exhaust all investigative leads in the expectation of discovering novel attacker techniques. Investigate and research these tech



  • Singapore StarHub Full time

    Join to apply for the Lead, Cybersecurity Incident Response role at StarHub Job Description The Assistant Manager - Incident Response and Threat Hunting is responsible for leading the detection, investigation, and mitigation of cybersecurity incidents. This role involves proactive threat hunting, forensic analysis, and developing response strategies to...


  • Singapore beBeeCybersecurity Full time

    Job Description:Cyber Response is a key area in our organization's cybersecurity business, focusing on assisting clients who have experienced a security incident. Our team investigates the root cause of the breach, helps clients recover from the incident, and provides recommendations to prevent future breaches.We work with an experienced team of...


  • Singapore beBeeConsultant Full time $150,000 - $200,000

    Job OpportunityAt Palo Alto Networks, we are looking for a seasoned cybersecurity professional to join our team as a Principal Consultant in Incident Response.The successful candidate will be responsible for leading incident response engagements with our largest clients and managing complex projects from start to finish.We seek an individual with exceptional...


  • Singapore beBeeCybersecurity Full time $80,000 - $120,000

    Job DescriptionWe are seeking a highly skilled Cybersecurity Professional to join our team. As a key member of our Cyber Response team, you will play a critical role in assisting clients who have experienced a cyber security incident.Our team investigates the root cause of the incident and the extent of the breach, helping clients to recover from the...


  • Singapore ASM Full time

    We’re not like most. We don’t just overcome obstacles - we don’t see them. Instead, we see the potential in every person, and every situation. We don’t wait for opportunity to appear - we create it. Meet ASM. A company that has been searching for people just like you._ **Who is ASM?** ASM is a leading, global supplier of semiconductor wafer...


  • Singapore beBeeLeadership Full time

    Job Title: Cybersecurity Incident Response Leader In this role, you will be responsible for leading and managing incident response engagements to help our clients address their complex information security needs. You will work with a team of cybersecurity experts to respond to cyber security incidents and assist clients in addressing their concerns around...


  • Singapore beBeeResponse Full time $120,000 - $180,000

    Incident Response SpecialistThe role of Incident Response Specialist requires strategic leadership and coordination to ensure effective incident management. The successful candidate will oversee a team responsible for monitoring and responding to critical incidents, while ensuring seamless communication with stakeholders.This position demands strong...


  • Singapore beBeeIncident Full time

    Job DescriptionWe are seeking a highly skilled professional to lead our incident response team. The successful candidate will be responsible for managing a 24/7 virtual team, monitoring and responding to major incidents, and ensuring staff members prioritize their work related to suspected and confirmed incidents.The ideal candidate will have strong...


  • Singapore beBeeCybersecurity Full time $120,000 - $180,000

    Job SummaryThis role is a senior-level position responsible for leading the organization's cybersecurity incident response and threat intelligence efforts. The ideal candidate will have extensive experience in managing complex cybersecurity incidents, developing and implementing incident response plans, and collaborating with internal and external...

  • Senior Cybersecurity

    2 weeks ago


    Singapore ITCAN Pte Ltd Full time

    Responsible for the daily real time monitoring and analysis of security events /threats from multiple sources - Triage security incidents including unauthorized access, phishing, malware infection etc. - Refine current use cases implemented on the SIEM solution to reduce/minimize false positives - First point of contact for Cybersecurity incident and...