Senior Cybersecurity Incident Response Specialist (L3)
Richemont · RAS Hong Kong
Job description
About the role
As a Senior Associate / Technical Lead you will operate at the L3 layer of our Cybersecurity Incident Response function, acting as the primary technical escalation point for complex, high‑impact incidents across the Group. You will lead advanced investigations, drive threat‑hunting initiatives and mentor junior analysts to continuously improve detection and response capabilities.
Key responsibilities
- Lead end‑to‑end investigations across endpoint, network, identity, cloud, email and application environments, determining scope, root cause and business impact.
- Act as technical incident lead during major events, guiding containment, eradication, remediation and recovery actions.
- Perform advanced forensic analysis, evidence collection, timeline reconstruction and suspicious file examination.
- Develop, validate and enhance security detections in SIEM, EDR/XDR, identity and cloud platforms.
- Conduct hypothesis‑driven threat‑hunting campaigns based on emerging threats and threat‑intel.
- Review and quality‑assure L1/L2 investigations, ensuring evidence‑based, technically accurate documentation.
- Mentor and provide hands‑on guidance to junior analysts, delivering training and knowledge‑sharing sessions.
Required profile
- 5–8+ years of experience in security operations, incident response, threat hunting or digital forensics.
- Strong knowledge of networking, operating systems, identity and cloud environments.
- Proven ability to investigate attacker techniques (credential access, lateral movement, data exfiltration, etc.).
- Experience reviewing complex investigations and improving playbooks, SOPs and analyst training.
- Excellent English communication skills; additional languages are a plus.
- Relevant certifications (e.g., CISSP, GCIH, GCFA, OSCP, SC‑200) are considered strong assets.
Required skills
- SIEM, SOAR, EDR/XDR, IDS/IPS, NDR, mail security, identity security, cloud security platforms.
- MITRE ATT&CK framework and attacker tactics, techniques and procedures.
- Query languages such as SPL, KQL, SQL.
- Scripting/automation with Python, PowerShell or Bash.
- Digital forensic techniques: evidence collection, timeline analysis, endpoint artefacts.
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in Hong Kong.
Salaries by job title
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
A question about this job?
Ask it here: you will get the full job summary by e-mail, right away.
Published 2 weeks ago
Expires 1 month from now
30 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
Richemont
RAS Hong Kong
Related job offers
-
Security Supervisor
Mandarin Oriental RAS Hong Kong -
Security Policy and Risk Analyst
The Hong Kong Jockey Club RAS Hong Kong -
Security Officer – Shatin Racecourse
The Hong Kong Jockey Club RAS Hong Kong -
Regional Head of Cybersecurity
Rise Associates Asia Limited Île de Hong Kong -
Penetration Testing Engineer
China Mobile Hong Kong Île de Hong Kong