Hiring.Camp

Senior Incident Response (IR) Analyst

Trendmicro

·

2 days ago

Location
Kuala Lumpur, Malaysia
Type
Full-time
Seniority
Senior
Experience
5+ years
Education
Bachelor
Source
Workday

Description

TrendAI™, the global AI security leader and enterprise business unit of Trend Micro, empowers organizations with full AI visibility and consolidated security that inspires confidence, drives innovation, and eliminates risk.


At TrendAI™, we’re always seeking exceptional talent; people who want to collaborate with the best and push boundaries together. Here, your work goes beyond building a career. You will help protect what matters and play a vital role in shaping a safer, more trustworthy AI-powered future.


AI Fearlessly.

Department: Regional Incident Response (AMEA)

Reports To: Manager of the Incident Response Team

About the Role

We are seeking an experienced Senior Incident Response Analyst to join our security team. The ideal candidate will lead and support end-to-end incident response engagements, from initial detection and triage through containment, eradication, and recovery.

This role requires strong technical expertise, sound judgment under pressure, and the ability to communicate clearly with both technical teams and business stakeholders during high-stakes incidents.

We are especially interested in candidates with hands-on experience applying AI tools to security operations and incident response, as we continue to expand AI-driven detection, triage, and analysis capabilities across the team.

Key Responsibilities

  • Lead investigations into security incidents, including malware infections, data breaches, and advanced persistent threats (APTs)

  • Perform forensic analysis on compromised systems, network traffic, and log data (e.g., WAF, firewall, endpoint, cloud, and application logs)

  • Evaluate, pilot, and integrate AI-based tools (e.g., AI-powered SIEM/XDR triage, anomaly detection, LLM-assisted log analysis and report generation) into the incident response lifecycle

  • Provide timely, accurate incident reports and executive summaries to stakeholders and customers

  • Identify indicators of compromise (IOCs) and threat actor tactics, techniques, and procedures (TTPs), including AI-enabled attack methods.

  • Mentor and guide junior analysts on investigation methodology, best practices, and use of AI-assisted tooling

  • Create and implement improvements to detection, monitoring, and response capabilities, including AI/automation-driven enhancements

  • Maintain awareness of the evolving threat landscape, including emerging vulnerabilities, attack techniques, and AI-related threats (e.g., AI-generated phishing, adversarial ML)

  • Support post-incident reviews and root cause analysis to strengthen organizational security posture

Required Qualifications

  • 5+ years of experience in incident response and digital forensics

  • Demonstrated experience with AI-related projects or activities in a security context (e.g., deploying or tuning AI-based detection/triage tools, using generative AI/LLMs to accelerate investigations or reporting, building automation that leverages machine learning models)

  • Prior experience working directly with clients/customers during live incident engagements

  • Strong understanding of network protocols, operating systems (Windows/Linux), and cloud environments (AWS, Azure, GCP)

  • Proven experience conducting cloud forensics investigations across major cloud service providers (AWS, Azure, GCP), including:

    • Acquiring and analyzing cloud-native artifacts (VM snapshots/disk images, memory captures, container images, serverless function logs)

    • Analyzing cloud control plane and audit logs (e.g., Azure Activity Log, AWS CloudTrail, GCP Audit Logs) to reconstruct attacker activity and timelines

    • Understanding shared responsibility models and their impact on evidence availability and collection methods

    • Investigating incidents involving cloud storage (e.g., S3 buckets, Azure Blob Storage), managed databases, and Kubernetes/container orchestration environments

    • Working with volatile and ephemeral cloud resources where traditional forensic imaging techniques may not apply

  • Hands-on experience with SIEM platforms, EDR/XDR tools, and log analysis (e.g., Splunk, CrowdStrike, Microsoft Sentinel), including AI-enabled features of these platforms

  • Relevant certifications such as GCIH, GCFA, GNFA, CISSP, CEH, OSCP, or cloud-specific credentials.

  • Familiarity with WAF, load balancer, and application gateway logs (e.g., Azure Application Gateway, Cloudflare, AWS WAF)

  • Solid understanding of the MITRE ATT&CK framework and threat intelligence concepts

  • Experience conducting forensic investigations and chain-of-custody procedures, including in distributed and multi-cloud environments

  • Excellent written and verbal communication skills, with the ability to translate technical findings for non-technical audiences

  • Ability to work under pressure and manage multiple concurrent investigations

  • Bachelor's degree in Computer Science, Information Security, or related field (or equivalent experience)

Preferred Qualifications

  • Experience with scripting/automation (Python, PowerShell) for investigation tasks, including integrating AI libraries or APIs into workflows

  • Practical exposure to concepts such as model training, prompt engineering, or AI governance/risk as applied to cybersecurity

  • Experience with cloud-native security tools and container security

  • Familiarity with cloud-native forensic and incident response tooling (e.g., AWS Detective, Azure Sentinel, Google Chronicle, Magnet AXIOM Cloud)

#LI-ZA1
#LI-Hybrid
 

We embrace change, empower people, and encourage innovation. Join Trend Micro and Thrive with us.

Skills

PythonAWSAzureGCPKubernetesLinuxMachine LearningCybersecuritySIEMSplunkCISSP

Similar Jobs

30

Senior Incident Response Consultant

Pondurance · McLean, VA · Remote

1 week ago

Senior Incident Response Engineer

Rappi Jobs · COL-Bogotá, Colombia

1 week ago

Incident Response Senior Engineer

Twilio · Remote - Ireland · Remote

2 weeks ago

Senior Incident Response Analyst (R-19347)

Dun & Bradstreet · Florham Park - New Jersey - United States · Onsite

2 weeks ago

Cloud Security Incident Response Senior Analyst

Cba · Eveleigh, NSW - 5-7 Central Ave, Australia +1

2 weeks ago

Senior Incident Response Analyst

Tetrad Digital Integrity LLC · Arlington, VA · Hybrid

3 weeks ago

Incident Response Senior Consultant

Crowe Careers · Sarasota, United States of America +4

4 weeks ago

Senior Incident Response Engineer (Romania)

Sophos · Romania · Remote

1 month ago

Incident Response Senior Engineer

Twilio · Knockatee, WH,IE, IE +1 · Remote

1 month ago

Senior Incident Response Consultant 2

Sophos · Romania · Remote

1 month ago

Senior Incident Response Analyst (R-19347)

Dun & Bradstreet · Center Valley - Pennsylvania - United States · Onsite

1 month ago

Senior Incident Response Analyst

Leidos · 9614 Arlington VA Non-specific Customer Site, United States of America

1 month ago

Senior Incident Response Engineer

NVISO · Greece · Hybrid

1 month ago

Senior Incident Response Engineer

NVISO · Greece · Hybrid

1 month ago

Senior Incident Response Engineer

NVISO · Greece · Hybrid

1 month ago

Cyber Incident Response Senior Analyst

Bbh · Jersey City, United States of America

1 month ago

Senior Incident Response Engineer

NVISO · Belgium · Hybrid

1 month ago

Senior Incident Response Engineer

NVISO · Belgium · Hybrid

1 month ago

Senior Incident Response Engineer

NVISO · Belgium · Hybrid

1 month ago

Senior Incident Response Manager, Public Safety

Axon · New York, New York, United States

2 months ago

Senior Incident Response Analyst

NetCentrics Corporation · CDAO +4

2 months ago

Incident Response Senior Consultant - Weekend Shift (Remote)

Crowdstrike · USA TX Remote, United States of America · Remote

3 months ago

Senior Incident Response & Digital Forensics Consultant

NVISO · Belgium · Hybrid

3 months ago

Senior Incident Response Analyst

Computershare · Melbourne, Australia

3 months ago

Senior Incident Response & Digital Forensics Consultant

NVISO · Brussels

3 months ago

Senior Incident Response Engineer

Radicl Defense · Boulder, CO · Remote

3 months ago

Senior Incident Response Analyst

Leidos · 9614 Arlington VA Non-specific Customer Site, United States of America

4 months ago

Cyber Defense- Cyber Incident Response - Senior Associate

Pwc · Chicago - One North Wacker Drive, United States of America +6

4 months ago

Senior Incident Response Forensic Investigator

DXC Technology · BG108 - Sofia Business Park, Bldg. 15 (BG108), Bulgaria

4 months ago

Senior Incident Response Engineer

RELX Jobs · Home based-New Jersey, United States of America +1 · Remote

4 months ago