Jobiglo

No results.

Senior Cybersecurity Incident Response Specialist (L3)

Richemont · RAS Hong Kong

Senior 🇬🇧 English
SIEM SOAR EDR XDR IDS/IPS NDR mail security identity security cloud security platforms MITRE ATT&CK SPL KQL SQL Python PowerShell Bash

Job description

About the role

As a Senior Associate / Technical Lead you will operate at the L3 layer of our Cybersecurity Incident Response function, acting as the primary technical escalation point for complex, high‑impact incidents across the Group. You will lead advanced investigations, drive threat‑hunting initiatives and mentor junior analysts to continuously improve detection and response capabilities.

Key responsibilities

  • Lead end‑to‑end investigations across endpoint, network, identity, cloud, email and application environments, determining scope, root cause and business impact.
  • Act as technical incident lead during major events, guiding containment, eradication, remediation and recovery actions.
  • Perform advanced forensic analysis, evidence collection, timeline reconstruction and suspicious file examination.
  • Develop, validate and enhance security detections in SIEM, EDR/XDR, identity and cloud platforms.
  • Conduct hypothesis‑driven threat‑hunting campaigns based on emerging threats and threat‑intel.
  • Review and quality‑assure L1/L2 investigations, ensuring evidence‑based, technically accurate documentation.
  • Mentor and provide hands‑on guidance to junior analysts, delivering training and knowledge‑sharing sessions.

Required profile

  • 5–8+ years of experience in security operations, incident response, threat hunting or digital forensics.
  • Strong knowledge of networking, operating systems, identity and cloud environments.
  • Proven ability to investigate attacker techniques (credential access, lateral movement, data exfiltration, etc.).
  • Experience reviewing complex investigations and improving playbooks, SOPs and analyst training.
  • Excellent English communication skills; additional languages are a plus.
  • Relevant certifications (e.g., CISSP, GCIH, GCFA, OSCP, SC‑200) are considered strong assets.

Required skills

  • SIEM, SOAR, EDR/XDR, IDS/IPS, NDR, mail security, identity security, cloud security platforms.
  • MITRE ATT&CK framework and attacker tactics, techniques and procedures.
  • Query languages such as SPL, KQL, SQL.
  • Scripting/automation with Python, PowerShell or Bash.
  • Digital forensic techniques: evidence collection, timeline analysis, endpoint artefacts.

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec Richemont.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.

Why are you reporting this job?

Thank you for your report. We will review this job.

Explore further

Salaries, guides and searches in Hong Kong.

Apply in 30 seconds

Enter your email to apply. An account will be created automatically.

Apply now →

By continuing, you accept our terms of use.

Already have an account? Login

A question about this job?

Ask it here: you will get the full job summary by e-mail, right away.

💬 Chat with us on Telegram

Published 2 weeks ago

Expires 1 month from now

29 views · 0 interested

Boost your chances

Upload your CV — we will match you with relevant openings.

Analyzing your CV...

Richemont

RAS Hong Kong