Assistant Manager, Cybersecurity Incident Response
Core
End-to-end management of cybersecurity incidents including detection, triage, investigation, and resolution using Elastic SIEM.
Role type
Senior IC cybersecurity incident response manager
Builds
Production security monitoring and incident response capabilities
Domain
Cybersecurity / Telecommunications
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure
Required skills
SIEM administration, Elastic Stack (ELK), incident triage, log analysis, detection rule engineering, MITRE ATT&CK use case design, stakeholder coordination, incident reporting, playbook documentation, post-incident review
Preferred skills
CISSP, GCIH, GCIA, CEH, Elastic Certified Engineer
Technologies
Elastic Stack (Elasticsearch, Logstash, Kibana, Beats), EDR, firewalls, cloud platforms, ticketing systems
Responsibilities
Monitor, triage, and investigate alerts from multiple log sources; Create, refine, and manage SIEM detection rules; Conduct log analysis and event correlation; Drive use case ideation and validation; Manage and maintain Elastic Stack components; Lead integration efforts with security tools; Collaborate with IT, Network, and Cloud teams for incident containment; Present incident findings and remediation plans to stakeholders; Document and enhance incident response playbooks; Conduct post-incident reviews
Seniority
Senior, hands-on IC with management of incidents