Computer Security Incident Response Expert

1 week ago


Singapore Crédit Agricole CIB Full time

Job description

**Business type**:

- Types of Jobs - IT, Digital et Data

**Job title**:

- Computer Security Incident Response Expert

**Contract type**:

- Permanent Contract

**Job summary**:
**Position**
Computer Security Incident Response Team Expert (CSIRT Expert)

CSIRT Expert is a technical expert role within the Asia Information System Security (ISS) Team, Singapore, functionally aligned to Group’s ISS CSIRT team in Head Office, France.
- ASIA ISS team oversees and supervise the Information System Security related matters in the region, including cybersecurity monitoring (SOC), incident response (CSIRT) and responding to each country's regulation proactively.
- The ASIA ISS CSIRT oversees detection, control and reporting of cyber incidents when it occurs and work closely with IT Operations team to recover and restore the systems that are affected by the security incident.
- In this role, CSIRT Expert role will be responsible for responding and managing end to end Security Incident Management Lifecycle: Incident Identification, Triage, Containment, Eradication, Recovery and Lesson Learnt. Person will be technical point of contact to respond and drive the security incidents response in the region.

**Responsibilities**:
The Expert has a wide spectrum of responsibilities and will be responsible for following activities (but not limited to) in day-to-day work:

- Identifying and detecting Incidents and taking immediate action on security incidents including (and not limited to) DoS attacks, malware attacks, phishing attacks, web attacks;
- End to end ownership in driving and leading Security Incident Response and Resolution activities;
- Participate and support performing forensics investigations as required to respond to the Security Incidents;
Responding to Security Threats and Intelligence alerts & notifications from Group CERT, Regional Regulators and authorized Threat Intelligence groups and ensuring appropriate preventive and detective actions are coordinated and deployed in liaison with IT Operations teams as per the defined approach and in timely manner;
- Owning end to end coordination, communications and deployment of action plans for Threat Advisories or lesson learnt from Security Incidents;
- Prepare detailed Incident Post-mortem report and Executive Summary to document the Security Incident chronology, root cause, remediation and lesson learnt;
- Creating and updating the incident response plan (IRP) and playbooks and ensuring periodical review of playbooks to ensure the relevancy of response actions in current context, including updated information of all stakeholders involved;
- Collaborate with other Geo’s CSIRT team members on security matters and act as a backup to manage security incident and other security activities in scope as needed;
Periodic review of security measures of Networks (Switches. Routers, Firewall, IPS, etc.) and Systems (Win*,*NIX, etc.) in support of management of vulnerabilities;
- Support and integrate with incident response, threat ntelligence, and overall security strategy as needed;
- Complete all mandatory trainings as required to attain and maintain competence;

**Supplementary Information**:

- Comply with all applicable legal, regulatory and internal Compliance requirements, including, but not limited to, the Compliance manual and Compliance policies and procedures as issued from time to time; Financial Security requirements, including, but not limited to, the prevention of Financial Crime and Fraud including reporting obligations to the Money Laundering Reporting Officer, zone wide.
- Support and run annual “table-top incidents” exercise with management.
- Vulnerability management: Ensure vulnerability remediation process is known followed and at the expected level of performance

Position location

**Geographical area**:

- Asia, Singapore

**City**:

- Singapour

**Minimal education level**:

- Bachelor Degree / BSc Degree or equivalent

**Academic qualification / Speciality**:

- Bachelor and above in relevant discipline

**Level of mínimal experience**:
6-10 years

**Experience**:
**Work Schedule**
v Work Hours: 8.45a.m. to 6. 30p.m (Monday to Friday) with one-hour lunch break.
- CSIRT team globally follows ‘follow-the-sun’ model and work on Critical incidents from other geographies during Asia business hours;**Required skills**:
**Qualification Requirements**

Ø Bachelors graduate or equivalent technical degree in Information Technology or Computer Science;
- Ø Must have minimum 10 years of experience in IT and 5-7 years of working experience in cyber security incident response role managing Security Incidents and performing log analysis and forensic analysis for an enterprise level environment;
- Ø Working experience in financial organisation is preferred;
- Ø Expertise in SIEM and SOC Processes;
- Ø Strong functional knowledge of enterprise level Security Detection and Prevention technologies e.g. Firewalls, IPS/IDS, Network Pa



  • Singapore Crédit Agricole CIB Full time

    **Description du poste**: **Position** Computer Security Incident Response Team Expert (CSIRT Expert) CSIRT Expert is a technical expert role within the Asia Information System Security (ISS) Team, Singapore, functionally aligned to Group’s ISS CSIRT team in Head Office, France. ASIA ISS team oversees and supervise the Information System Security related...


  • Singapore SKY & F PTE. LTD. Full time

    Activities to detect, contain, respond and recover from a security incident to minimize damage and reduce recovery time and costs - Lead and support detailed investigations and analysis of security related findings, alerts and events across the Azure logical and physical infrastructure - Perform Root Cause Analysis (RCA), develop mitigation strategies and...


  • Singapore F-secure Full time

    I'm interested F-Secure delivers research-led cyber security to defend organizations, society and people from real-world attacks and build resilience into their approach. Our people are a mix of technical and creative experts - diverse, talented, and passionate people - working tirelessly to help us advance the industry with new ways of thinking. They lead...


  • Singapore Sygnia Full time $90,000 - $120,000 per year

    Sygnia is a top tier cyber technology and services company, providing high-end consulting and incident response support for organizations worldwide. Sygnia works with companies to proactively build their cyber resilience and to respond and defeat attacks within their networks. It is the trusted advisor and cyber security service provider of IT and security...


  • Singapore beBeeLeadership Full time

    Job Title: Cybersecurity Incident Response Leader In this role, you will be responsible for leading and managing incident response engagements to help our clients address their complex information security needs. You will work with a team of cybersecurity experts to respond to cyber security incidents and assist clients in addressing their concerns around...


  • Singapore beBeeCybersecurity Full time $80,000 - $120,000

    Incident Response SpecialistCybersecurity incidents can have a significant impact on an organization's operations, reputation, and bottom line. As an Incident Response Specialist, you will play a critical role in helping clients respond to and recover from these incidents.Job Description:Your primary responsibility will be to investigate and analyze the root...


  • Singapore ENSIGN INFOSECURITY (CYBERSECURITY) PTE. LTD. Full time

    **Duties and Responsibilities** - Lead and coordinate the activities of security operations and effective response to information security threats within clients’ technology environments - Lead security incident response processes, identify and measure critical security operations metrics and continually improve service delivery to clients - Provide...


  • Singapore BANK OF MONTREAL SINGAPORE BRANCH Full time

    **Job Description Additionally, the Incident Response (IR) Specialist accountable to lead the response effort for security incidents including review of alert post-escalation, investigation of the incident, containment of the threat, and remediation of issues leading to the threat affecting BMO. **Job Requirements - Minimum 4 years of Enterprise Incident...


  • Singapore Hays Full time

    **Your new company** The client is a local security solution provider working mainly with projects within the government. Their service ranges from design and development to implementation and post-implementation maintenance. **Your new role** You will be involving in activities to detect, contain, respond and recover from security incident, this includes...


  • Singapore Robert Half Full time

    **The Company** Our client is a global financial services firm with presence in more than 30 countries. Due to business expansion, they are currently looking for a Cyber Security Incident Response Team (CSIRT) Manager to join the team. **The Role** Reporting to the Head of Security, you will strategize, plan and drive security improvement initiatives,...