Incident Response Lead

๐Ÿข Axonect ยท all Axonect jobs
๐Ÿ“ Malaysia
๐Ÿ“… Posted 2026-08-25 ยท via Himalayas
๐Ÿท Incident-Response,Cyber-Incident-Response,Security-Operations-Center,Threat-Hunting,Digital-Forensics,Incident-Response-Lead,Lead-Security-Incident-Responder,Incident-Response-Leadership,Incident-Response-Manager,Detection-and-Response-Lead
Apply on original site โ†—

Overview

The Incident Response Lead is responsible for leading cyber incident detection, investigation, containment, eradication, recovery, and post incident activities across Axiata Cyber Fusion Center (ACFC). The role provides technical leadership and coordination for cyber incident response, digital forensics, threat hunting, intelligence-driven defense, and continuous improvement of detection and response capabilities.

The incumbent will work closely with SOC analysts, Security Engineering, Threat Intelligence, Operational Companies (OpCos), Technology teams, and external partners to ensure timely and effective handling of cyber threats and incidents while strengthening the organization's cyber resilience.
Key Responsibilities
Cyber Incident Response & Management

- Lead the end-to-end management of cyber security incidents, ensuring appropriate prioritization, investigation, containment, eradication, and recovery activities

- Act as the primary escalation point for high-severity security incidents and coordinate incident response activities across OpCos and stakeholders

- Direct cyber incident bridge calls and crisis management activities during major security incidents

- Ensure incident response activities are executed in accordance with established SLAs, regulatory requirements, and organizational policies

- Develop and maintain incident response playbooks, runbooks, escalation matrices, and standard operating procedures (SOPs)

- Conduct post-incident reviews, root cause analysis, lessons learned sessions, and track remediation actions

Security Monitoring & Detection Enhancement

- Provide guidance and oversight to SOC analysts and managed security service providers to improve detection accuracy, triage quality, and investigation effectiveness

- Review and validate alerts escalated from monitoring teams to ensure accurate contextualization and prioritization

- Drive continuous enhancement of security monitoring use cases, detection content, correlation rules, and threat detection frameworks

- Collaborate with Security Engineering teams to improve visibility, telemetry, and detection coverage across enterprise environments

Digital Forensics & Malware Analysis

- Lead forensic investigations involving endpoint, network, cloud, and mobile environments

- Perform or oversee digital evidence acquisition, preservation, analysis, and reporting in accordance with forensic standards

- Conduct advanced malware analysis and reverse engineering activities to determine attack methodologies, indicators of compromise (IOCs), and business impact

- Support legal, regulatory, and compliance investigations where digital forensic expertise is required

Threat Intelligence & Threat Hunting

- Analyze emerging cyber threats, vulnerabilities, adversary tactics, techniques, and procedures (TTPs) to improve defensive capabilities

- Convert threat intelligence into actionable detection rules, hunting hypotheses, and response actions

- Lead proactive threat hunting activities leveraging MITRE ATT&CK and intelligence-led methodologies

- Coordinate with internal and external intelligence sources to assess risks affecting Axiata Group and OpCos

Automation & Continuous Improvement

- Drive security orchestration, automation, and response (SOAR) initiatives to improve operational efficiency and reduce mean time to detect (MTTD) and mean time to respond (MTTR)

- Identify opportunities for process optimization, workflow automation, and operational maturity enhancements

- Evaluate emerging cyber security technologies and recommend adoption based on business and operational requirements

- Contribute to the strategic development and maturity roadmap of ACFC's incident response capabilities

Security Testing & Readiness

- Coordinate cyber security assessments, threat-led exercises, tabletop simulations, red team engagements, and breach attack simulations

- Validate detection and response capabilities against identified threats

โ† All remote jobs