company-logo-image

Lead, Incident Response (Platform)

ashley-avatar-image

AI-generated summary

beta

This job is about leading the detection and response to cybersecurity threats at a tech company in Malaysia. You might like this job because you will shape security strategies, tackle incidents, and work closely with various teams to protect valuable assets.

Undisclosed

Singapore, Central

Job Description

Job Description

(This role is based in Malaysia, Petaling Jaya)
Cybersecurity Incident Response SME 
proactively monitor, detect, and respond to cybersecurity incidents identified through the Security Operations Center (SOC) platform. The role involves ownership of the entire Cybersecurity incident lifecycle — from Monitoring, detection and triage to in-depth investigation, containment, and closure — ensuring the security and resilience of StarHub IT assets

Job Responsibilities

  1. Monitor, triage, and investigate alerts from multiple log sources (network, endpoint, cloud, and application).
  2. Create, refine, and manage SIEM detection rules to capture the latest attack patterns.
  3. Conduct log analysis and event correlation to identify potential intrusions or malicious behavior.
  4. Drive use case ideation and validation to improve threat detection coverage and accuracy.
  5. Manage and maintain Elastic Stack components (Elasticsearch, Logstash, Kibana, Beats) for operational efficiency.
  6. Lead integration efforts with tools such as EDR, firewalls, cloud platforms, and ticketing systems.
  7. Collaborate with IT, Network, and Cloud teams for incident follow-up, containment, and recovery.
  8. Present incident findings, root cause analyses, and remediation plans to key stakeholders (internal leadership and external partners).
  9. Document and enhance incident response playbooks and standard operating procedures (SOPs).
  10. Conduct post-incident reviews and implement lessons learned to strengthen the organization’s security posture.

Accountablities

  1.  End-to-end management of cybersecurity incidents, ensuring timely detection, triage, investigation, and resolution.
  2. Achieving and maintaining target MTTD (Mean Time to Detect) and MTTR (Mean Time to Respond) benchmarks.
  3. Effective administration and optimization of the Elastic SIEM platform, including rule creation, tuning, and integrations.
  4. Development of accurate and relevant detection use cases aligned with evolving threat patterns and organizational needs.
  5. Ensuring timely escalation and coordination with internal and external stakeholders during major incidents.
  6. Providing transparent and comprehensive incident reporting to leadership and relevant teams.
  7. Drive operational excellence through monitoring, alerting, timely investigation and continuous fine tuning the alerts
  8. Partner with Data Engineering, Architecture, Security, Infrastructure & Tooling teams to ensure aligned technical cyber security discussions

Qualifications

  1. 5–8 years of experience in Security Operations Center (SOC), Incident Response, or Detection Engineering roles.
  2. Proven success in SIEM administration, particularly Elastic Stack (ELK) environments.
  3. Hands-on expertise in incident triage, log analysis, and detection rule engineering.
  4. Demonstrated ability to design and operationalize MITRE ATT&CK-aligned use cases.
  5. Experience in cross-department collaboration and incident coordination with IT and business teams.
  6. Strong presentation and communication experience in stakeholder-level incident discussions.
  7. Relevant certifications such as CISSP,GCIH, GCIA, CEH, or Elastic Certified Engineer preferred.


Job Requirements


Company Benefits

#NoMeetingThuPMs

No meetings afternoon once a week #NoMeetingThuPMs to enable staff to focus on ideas generation or professional learning.

Renew and Recharge

In last two weeks of December employees are encouraged to avoid scheduling meetings to allow them to unwind, reflect and prepare for the upcoming year

Mental Wellness Programme

Partnering ThoughtFull to offer a company-wide mental wellness programme to provide on-demand mental wellness resources.


Additional Info

Company Activity

Last active - 1 week ago

Job Specialisation


Company Profile

StarHub-logo-image

StarHub

StarHub is a leading homegrown Singapore company that delivers world-class communications, entertainment and digital services. With our extensive fibre and wireless infrastructure and global partnerships, we bring to people, homes and enterprises quality mobile and fixed services, a broad suite of premium content, and a diverse range of communication solutions. We develop and deliver to corporate and government...
Upload Resume