Incident Response Analyst II
15 hours ago
Job Description
Incident Response Center (Analyst)Job Title – IRC Analyst
SummaryThe IRC (Incident Response Center) is the first layer of defense responsible for quick detection and incident response using various monitoring and automation tools, conducting thorough investigation of alerts, classification, and triage. The IRC Analyst is responsible for delivering operations within the IRC across all client data center sites globally. IRC analysts are expected to respond to all alarms/alerts set in the data center environment, including Infrastructure Management (DCIM), Server Automation Operations System (SAOS), CCTV, Access Control Systems (ACS), and Building Management Systems (BMS), providing deep understanding and intelligence of the criticality and impact of incidents to resolver groups.
ResponsibilitiesIncident & Problem Management
Analysts are responsible for the full lifecycle of incident management, from detection through to resolution and root cause analysis (RCA). This includes acting as incident commanders, maintaining SLAs, documenting actions, and providing insights to support continuous improvement efforts across teams and systems.
Investigate, report, and respond to alerts, incident response (war room, remote bridges).
Respond to incidents and critical situations in a calm, problem-solving manner, and conduct in-depth investigation of alerts.
Be the first line of defense using monitoring and automation tools to conduct investigation, classification, and triage, all within prescribed SLAs.
Provide deep understanding and intelligence of incident criticality and impact to resolver groups.
Ensure detailed records of alarm handling activities, including actions taken and resolutions in ticketing tools; file incident reports.
Act as incident commander during major incidents.
Understand internal/external communication methods and stakeholder responsibilities.
Support program managers and facilitate project deliverables, improving operational and engineering initiatives.
Conduct root cause analysis (RCA) to determine recurring problems.
Use in-depth questioning and analysis to determine the underlying cause of incidents or problems (Who, What, Where, When, Why).
Perform duties in compliance with SOPs, MOPs, Runbooks, and Playbooks.
Server, DCIM, Network and Traffic Alarms Operations
This function involves real-time monitoring of infrastructure alarms, determining the severity of alerts, escalating appropriately, and maintaining clear communications with resolver teams. It ensures uptime and system integrity across servers, network infrastructure, and environmental systems.
Continuously monitor alarm dashboards and systems.
Investigate and respond to alarms related to Network, Data Center Environment, Server Health, Facility Security, and Safety.
Identify and acknowledge incidents associated with alarms.
Assess incidents to determine their criticality and operational impact.
Engage resolver groups and escalate to higher tiers or management following established paths.
Maintain communication with teams, stakeholders, and incident responders.
Follow documented procedures to resolve incidents promptly and effectively.
Ensure accurate records of alarm handling and resolution activities in ticketing tools.
Comply with SOPs, MOPs, Runbooks, and Playbooks.
Threat Intelligence, Critical Event Management
Analysts monitor global threat feeds and operational alerts to protect ByteDance personnel and assets. Responsibilities include triaging alerts related to weather, security, travel, and regional instability, then coordinating appropriate response actions, escalating to law enforcement if necessary, and compiling response reports.
Monitor Everbridge Visual Command Center (VCC), InternationalSOS emails, and open-source tools for real-time incidents affecting ByteDance assets and travelers.
Monitor tools or queries for specific stakeholder requests.
Report on violence, severe weather, or threats to life, property, and assets.
Coordinate emergency responses, including with law enforcement if required.
Verify incident information accuracy through secondary sources.
Generate heatmaps to highlight affected areas during significant events.
Collaborate with security and operational teams for a coordinated response.
Implement incident containment and mitigation strategies.
Document incident details, response actions, and lessons learned.
Follow SOPs, MOPs, Runbooks, and Playbooks.
Physical Security and Safety
The analyst monitors access control systems, CCTV, and safety-related alarms (e.g., fire, electrical, leaks). Responsibilities include reviewing footage, responding to security anomalies, and reporting incidents to security engineering teams while ensuring compliance with safety procedures
Monitor Closed-Circuit Television (CCTV) and Access Control Systems (ACS).
Track alarms for safety events including electrical issues, fire hazards, equipment failures, and water leaks.
Review camera footage for quality and area coverage.
Investigate and report access control incidents.
Report findings to the Security and Safety Engineering teams.
Follow SOPs, MOPs, Runbooks, and Playbooks.
Familiarity with Lenel and Genetec systems.
Cloud Incident Response and Monitoring
As hybrid environments become more critical to business operations, IRC Analysts will be expected to monitor and support both on-premises infrastructure and cloud-based systems. Analysts will assist in identifying and responding to cloud-related incidents across platforms such as AWS, GCP, and Azure. Responsibilities include:
Real-time monitoring of cloud infrastructure using tools such as AWS CloudWatch, Azure Monitor, and GCP Stackdriver.
Incident triage and escalation of alerts related to cloud-based services and resources (e.g., compute, storage, networking).
Coordination with Cloud Engineers and DevOps teams during cross-environment incidents to ensure rapid resolution and clear communications.
Identification and classification of cloud service anomalies, including misconfigurations, degraded services, and unauthorized access attempts.
Understanding of cloud-native architectures such as virtual private clouds (VPC), IAM, container orchestration (e.g., Kubernetes), and serverless functions.
Documentation of root cause analysis (RCA) and corrective actions for cloud incidents, feeding back into playbooks and runbooks.
Basic scripting and automation skills (Python, Bash, or PowerShell) for incident analysis and tooling.
Awareness of cloud security protocols, including encryption, IAM policies, and compliance standards like ISO 27001 and SOC 2.
Required Qualifications / Soft Skills
2+ years of experience in a NOC, command center, or similar 24/7 operations environment
Ability to quickly triage and prioritize multiple incidents based on risk
Knowledge of systems including IP Networks, DC Environment, and Server Health
Strong written and verbal communication skills
Works well under pressure and within deadlines
Excellent communication and collaboration abilities
Strong analytical and problem-solving skills
Ability to work independently and as part of a team
Familiarity with data protection laws such as GDPR
This is an on-site role at client facilities
Must be willing to work variable shifts, including nights, weekends, and holidays
Preferred Qualifications
Degree in Information Technology
Networking knowledge (IP, DNS, load balancing)
Experience with Grafana, ticketing systems, and DC infrastructure.
Certifications such as CompTIA Server+ or Schneider Electric DCCA
Experience with Lenel, Genetec, or Avigilon systems is a plus
Proficiency with programming/scripting tools
-
Incident Response Analyst II
14 hours ago
Singapore Astreya Full time $60,000 - $120,000 per yearIncident Response Center (Analyst) Job Title – IRC AnalystSummaryThe IRC (Incident Response Center) is the first layer of defense responsible for quick detection and incident response using various monitoring and automation tools, conducting thorough investigation of alerts, classification, and triage. The IRC Analyst is responsible for delivering...
-
Senior Incident Response Analyst
1 day ago
Singapore TikTok Full timeResponsibilities TikTok is the leading destination for short-form mobile video. Our mission is to inspire creativity and bring joy. TikTok has global offices including Los Angeles, New York, London, Paris, Berlin, Dubai, Singapore, Jakarta, Seoul and Tokyo. Why Join Us At TikTok, our people are humble, intelligent, compassionate and creative. We create to...
-
Incident Response Lead
2 weeks ago
Singapore Tetra Pak Full timeOverview Join to apply for the Incident Response Lead role at Tetra Pak . At Tetra Pak we commit to making food safe and available, everywhere; and we protect what's good – protecting food, protecting people, and protecting the planet. By doing so we touch millions of people's lives every day. And we need people like you to make it happen. We empower you...
-
Threat and Incident Response Analyst
6 days ago
Carpenter Street, Singapore, Singapore Propine Digital Tech Full time $80,000 - $120,000 per yearWork should be challenging.Your work should challenge the status quo.You should be defining the future, not being dependent on it.You don't like it safe and prefer to swim in the deep end while figuring things out.You want to be avant-garde.If this resonates with you, then you'll fit right in here at Propine.Propine is re-inventing capital markets using...
-
Command Center Analyst Ii
7 days ago
Singapore DIGITAL INVESTMENT MANAGEMENT PTE. LTD. Full time**Position Title: Command Center Analyst II** **Location: Singapore** **Your role** The Global Command Center Analyst - II is responsible for the day-to-day monitoring of network and infrastructure operations. Provides customer service, troubleshooting, as well as incident escalation for all internal and external customers contacting the Global Command...
-
Digital Forensics
1 week ago
Singapore OCBC Full timeDigital Forensics & Incident Response (DFIR) Analyst As Singapore's longest established
-
Incident Response Consultant
5 days ago
Singapore F-secure Full timeI'm interested F-Secure delivers research-led cyber security to defend organizations, society and people from real-world attacks and build resilience into their approach. Our people are a mix of technical and creative experts - diverse, talented, and passionate people - working tirelessly to help us advance the industry with new ways of thinking. They lead...
-
Incident Response Team Analyst
2 weeks ago
Singapore Meta Full time**Incident Response Team Analyst Responsibilities**: - Bring operational excellence to a team that evaluates threat, risk and user privacy in a world centered around time critical emergency escalations - Review and assess inbound emergency escalations - Make immediate decisions based on a variety of complex factors that will include imminence, sensitive...
-
Incident Response Team Analyst, Apac
1 day ago
Singapore Meta Full time**Incident Response Team Analyst, APAC Responsibilities**: - Bring operational excellence to a team that evaluates threat, risk and user privacy in world centered around time critical emergency escalations - Review and assess inbound emergency escalations - make immediate decisions based on variety of complex factors that will include imminence, sensitive...
-
Incident Response Analyst
1 week ago
Singapore ByteDance Full timeFounded in 2012, ByteDance's mission is to inspire creativity and enrich life. With a suite of more than a dozen products, including TikTok, Helo, and Resso, as well as platforms specific to the China market, including Toutiao, Douyin, and Xigua, ByteDance has made it easier and more fun for people to connect with, consume, and create content. Why Join...