Cyber Incident Response and Recovery Investigator

2 days ago


Bengaluru Karnataka, India SAP Full time

**We help the world run better**

At SAP, we enable you to bring out your best. Our company culture is focused on collaboration and a shared passion to help the world run better. How? We focus every day on building the foundation for tomorrow and creating a workplace that embraces differences, values flexibility, and is aligned to our purpose-driven and future-focused work. We offer a highly collaborative, caring team environment with a strong focus on learning and development, recognition for your individual contributions, and a variety of benefit options for you to choose from.

**Summary**

An SAP Global Cyber Incident Response and Recovery Investigator is a crucial front-line defender and core part of SAP’s digital enterprise. Our Cyber Incident Investigators are responsible for triaging security events detected by security monitoring operations tools, analyzing all available data to determine severity and priority, doing an initial assessment whether a cyber-attack is occurring. Then the Investigator will escalate to a Global Security Operations Investigator in scoping the extent of a suspected attack, coordinating efforts to contain attacks, and supporting forensic investigation to determine the details around the attack.

**What you'll do**

Our Global Cyber Security Incident Response and Recovery Investigator are our first line of response for security event and incidents with a global scope. They are responsible for triaging security alerts detected by Enterprise Detection and SIEM, analyzing available data to determine scope, severity, and priority to determine follow on actions, which could include escalation to a GSO Investigator. In escalation cases, they then work in a supportive capacity to further validate if a cyber-attack is occurring, scoping the extent of a suspected attack, coordinating efforts to contain attacks, supporting forensic investigations to determine the details around an attack, and providing guidance on remediation actions.

In this role, you will not only conduct an initial assessment of the event, but also help scope and determine root cause analysis, support development of attack remediation strategies and coordinate the communication and handling of escalations of security activities. This role also triages operational response processes like those intervening in phishing campaigns. You will also assist in the review and updating of incident handling processes, standard operating procedures, playbooks and runbooks.

You will work with Detection and SIEM teams to make improvements to detection and alerting mechanisms and support forensic investigations to determine incident details and provide supporting evidence.

**What you bring**

You should have demonstrated experience in cyber-attack analysis and of working in a similar 24/7 environments managing cases with enterprise SIEM or Incident Management systems. Previous experience of supporting multi-function, cross-organizational teams is also highly desirable.

We are looking for analytical, critical thinkers, who have an eye for detail and are solution orientated. You should be quick to learn and adapt and operate in a dynamic environment.

You typically will have most of the following technical skills and experience:

- 8+ years’ experience in a similar incident Investigator role or equivalent combination of education, certifications, and trainings
- Security certification (e.g. Security+, GCIA, GCIH, CISSP)
- Knowledge APT actors; their tools, techniques, and procedures (TTPs)
- Knowledge of TTP methods and frameworks
- Solid knowledge of one or more:

- Windows/AD file system, registry functions and memory artifacts
- Unix/Linux file systems and memory artifacts
- Mac file systems and memory artifacts
- Cybersecurity automation
- SIEM
- Experience with one or more scripting languages (Powershell, Python, Bash, etc.)
- Experience with integration of threat hunting and cyber threat intelligence into the incident response process
- Experience with information security compliance audit frameworks and requirements e.g. ISO, FISMA, FedRAMP, SOC, SOX, PCI, GDPR and Data Privacy

**Bring out your best**

**We win with inclusion**

SAP’s culture of inclusion, focus on health and well-being, and flexible working models help ensure that everyone - regardless of background - feels included and can run at their best. At SAP, we believe we are made stronger by the unique capabilities and qualities that each person brings to our company, and we invest in our employees to inspire confidence and help everyone realize their full potential. We ultimately believe in unleashing all talent and creating a better and more equitable world.

**EOE AA M/F/Vet/Disability**:
Qualified applicants will receive consideration for employment without regard to their age, race, religion, national origin, ethnicity, age, gender (including pregnancy, childbirth, et al), sexual orientation, gender identity or expression, protected veteran status, or disa



  • Bengaluru, Karnataka, India SAP Full time

    **We help the world run better** At SAP, we enable you to bring out your best. Our company culture is focused on collaboration and a shared passion to help the world run better. How? We focus every day on building the foundation for tomorrow and creating a workplace that embraces differences, values flexibility, and is aligned to our purpose-driven and...


  • Bengaluru, Karnataka, India Carrier Full time

    **Role**: Incident Response Analyst **Location**: Bangalore **Full/ Part time**: Full time **Build a career with confidence** Carrier Global Corporation, global leader in intelligent climate and energy solutions is committed to creating solutions that matter for people and our planet for generations to come. From the beginning, we've led in inventing new...


  • Bengaluru, Karnataka, India Finastra USA Corporation Full time

    **Responsibilities**: **Job Summary** **Responsibilities** Acts as Security Incident Handler for high-impact cyber security incidents and advanced attacks in accordance with Cyber Kill Chain methodology and incident response process. Understands Incident Response processes and participate in analysis, containment, and eradication/remediation of security...

  • Disaster Recovery

    2 weeks ago


    Bengaluru, Karnataka, India Kyndryl Full time

    **Who We Are** At Kyndryl, we design, build, manage and modernize the mission-critical technology systems that the world depends on every day. So why work at Kyndryl? We are always moving forward - always pushing ourselves to go further in our efforts to build a more equitable, inclusive world for our employees, our customers and our communities. **The...


  • Bengaluru, Karnataka, India Rockwell Automation Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    Rockwell Automation is a global technology leader focused on helping the world's manufacturers be more productive, sustainable, and agile. With more than 28,000 employees who make the world better every day, we know we have something special. Behind our customers - amazing companies that help feed the world, provide life-saving medicine on a global scale,...


  • Bengaluru, Karnataka, India Autodesk Full time ₹ 9,00,000 - ₹ 12,00,000 per year

    Job Requisition ID # 25WD91177 Position Overview The Incident Response Analyst is responsible for monitoring, identifying, assessing, containing, and responding to various information security events in a large and complex environment, as well as analyse, triage, and report on these incidents and investigations. The candidate must have knowledge of...


  • Bengaluru, Karnataka, India Autodesk Full time ₹ 9,00,000 - ₹ 12,00,000 per year

    Job Requisition ID # 25WD91175Position Overview The Incident Response Analyst is responsible for monitoring, identifying, assessing, containing, and responding to various information security events in a large and complex environment, as well as analyse, triage, and report on these incidents and investigations. The candidate must have knowledge of system...


  • Bengaluru, Karnataka, India beBeeCyberSecurity Full time ₹ 12,00,000 - ₹ 36,00,000

    Cybersecurity Incident Response RoleAs a member of our Cyber Team, you will be responsible for building and maintaining positive working relationships with teams and clients to deliver exceptional results.You will have a deep understanding of computer intrusion activities, incident response techniques, tools, and procedures.Knowledge of Windows, Active...


  • Bengaluru, India Careernet Full time

    Job Overview: Incident Response: Respond to and manage cybersecurity incidents, including threat detection, containment, eradication, recovery, and post-incident activities Threat Hunting: Proactively hunt for threats within our environment, utilizing tools such as Anomali ThreatStream to identify potential security risks. Digital Forensics: Conduct digital...


  • Bengaluru, Karnataka, India Proterial Full time ₹ 5,00,000 - ₹ 8,00,000 per year

    Location:Remote - Karnataka, IndiaJob ID:R0104263Date Posted: Company Name:HITACHI ENERGY TECHNOLOGY SERVICES PRIVATE LIMITEDProfession (Job Category):IT, Telecom & InternetJob Schedule:Full timeRemote:YesJob Description:The opportunity:The world is rapidly moving towards more efficient power distribution to support renewable, greener technologies. At...