Relomote
Remote JobsRelocation Jobs
Add companySaved
Relomote

Relomote is a job board for remote, hybrid, and relocation jobs — every listing AI-classified for the countries it actually hires from, or the visa and relocation support it offers.

LinkedInCrunchbase

Remote jobs by category

  • Remote Engineering & Development jobs
  • Remote Customer Support jobs
  • Remote Design jobs
  • Remote Marketing jobs
  • Remote Sales jobs
  • Remote Product jobs
  • Remote Data & Analytics jobs
  • Remote People & Talent jobs
  • Remote Writing & Content Creation jobs
  • Remote Finance jobs
  • Remote Legal & Compliance jobs
  • Remote Operations & Admin jobs
  • Remote Data Entry jobs
  • Remote Virtual Assistant jobs
  • Remote Education/Training jobs
  • Remote Healthcare/Clinical jobs
  • Remote Other jobs

Remote jobs by location

  • Work from anywhere jobs
  • Remote jobs in Africa
  • Remote jobs in Asia
  • Remote jobs in Europe
  • Remote jobs in Latin America
  • Remote jobs in Middle East
  • Remote jobs in North America
  • Remote jobs in Oceania
  • All remote jobs →

Relocation & visa sponsorship

  • Visa sponsorship jobs
  • Relocation package jobs
  • Relocate to Europe
  • Relocate to Germany
  • Relocate to Netherlands
  • Relocate to Spain
  • Relocate to Portugal
  • Relocate to Greece
  • Relocate to United Kingdom
  • Relocate to Canada
  • Relocate to Australia
  • Relocate to Sweden
  • Relocate to Switzerland
  • Relocate to Japan
  • Relocate to United Arab Emirates
  • All relocation jobs →

© 2026 RelomoteAboutPrivacyTerms

Contact [email protected] · Built by Mahmoud

Relomote
Remote JobsRelocation Jobs
Add companySaved
CyberOne logo

Incident Response Specialist

CyberOne
Posted 2 weeks ago
🇵🇭Philippines🏠Remote📁Other
Is this job info correct?

Incident Response Specialist Job Title: Incident Response Specialist Location: PH - Fully Remote Employment Type: Full-time About The Role The Incident Response Specialist will play a key role in supporting customers through all stages of a cyber incident, from initial investigation through to containment, eradication, recovery and post-incident reporting. Working alongside senior Incident Responders and Incident Managers, you will conduct technical investigations, analyse evidence, identify attacker activity and support customers during some of their most critical cyber security events. The role also supports proactive security services including Incident Response Readiness Assessments, Tabletop Exercises, Threat Hunting and Threat Intelligence activities. This is an excellent opportunity for an experienced SOC Analyst or early-career Incident Responder looking to develop into a senior DFIR consultant. What You’ll Do Incident Response · Investigate cyber security incidents affecting customer environments. · Analyse endpoint, network, cloud and identity-based evidence. · Perform host-based investigations across Windows and Microsoft 365 environments. · Support containment, eradication and recovery activities. · Identify attacker tactics, techniques and procedures (TTPs) using the MITRE ATT&CK framework. · Collect, preserve and analyse forensic artefacts where appropriate. · Produce Indicators of Compromise (IOCs) and detection recommendations. · Support evidence collection for regulatory or legal requirements. Technical Investigation · Analyse Microsoft Defender XDR telemetry. · Investigate Microsoft Sentinel incidents. · Review Windows Event Logs and Sysmon data. · Analyse Entra ID sign-in and audit logs. · Investigate Exchange Online activity. · Perform malware triage and basic static analysis. · Review firewall, proxy, VPN and authentication logs. · Conduct threat hunting activities across customer environments. Customer Engagement · Participate in customer investigation calls. · Explain technical findings to both technical and non-technical audiences. · Produce high-quality investigation reports. · Provide remediation recommendations. · Support post-incident lessons learned workshops. Proactive Services Support delivery of: · Incident Response Readiness Assessments · Tabletop Exercises · Threat Hunting engagements · Threat Intelligence services · Security posture reviews · AI security investigations where required Continuous Improvement · Develop new investigation playbooks. · Improve Incident Response procedures. · Contribute to internal knowledge sharing. · Support development of detection content. · Assist with automation opportunities using Microsoft and AI technologies. Employees are expected to demonstrate a security-first mindset and ensure that information security considerations are incorporated into their day-to-day activities, decision-making, and interactions with customers, suppliers, and colleagues. What We’re Looking For Essential · Relevant experience in Cyber Security or Incident Response. · Strong English communication skills. Advantageous · SC-200 Microsoft Security Operations Analyst · SC-100 Cybersecurity Architect · AZ-500 Microsoft Azure Security Technologies · GCIH · GCFA · GNFA · CompTIA Security+ · CREST Practitioner or equivalent Locations Philippines Remote status Fully Remote

Similar jobs

Similar jobs

Augmendigital Talent logo

Lead Response Agent (Remote) (Chat Support Specialist)

Augmendigital Talent

🇵🇭PhilippinesMay 27, 2026, 9:33 PM UTC
Thomsonreuters logo

Proposal Specialist Lead

Thomsonreuters

🇵🇭Philippines8 hours ago
Thomsonreuters logo

Proposal Specialist

Thomsonreuters

🇵🇭Philippines8 hours ago
RO

Administration & Contract Officer (Construction / Real Estate Experience

Rovroutsourcing

🇵🇭Philippines8 hours ago
LevelUp logo

Customer Service Specialist [2631-399721]

LevelUp

🇵🇭Philippines8 hours ago
RE

Interior Designer

Remoteworkmate

🇵🇭Philippines8 hours ago