J
Posted 1mo agoSuanluang, Bangkok, Thailand

Department Manager - Cyber Incident Management (Incident Response)

MiddleOn-site (Suanluang)Salary undisclosed
Required Skills
AWSGCPAzure
Job Description

You will own the end-to-end incident response lifecycle at CP Axtra — from detection and triage through containment, eradication, and recovery, all the way to post-incident review and capability improvement. You are the Incident Commander during major security events, the person in the war room making real-time decisions about containment actions, stakeholder communications, and escalation paths.

Beyond crisis response, you'll build and mature the incident response programme itself. This means developing playbooks tailored to CP Axtra's specific threat scenarios (ransomware hitting POS systems, credential stuffing on the e-commerce login, insider threats in finance systems), running realistic tabletop exercises, and driving post-incident reviews that produce actual operational improvements — not just reports that gather dust.

You'll manage the SOC team's operational effectiveness, own the KPIs that matter (MTTD, MTTR, false positive rates), and work closely with the Security Architect and GRC teams to ensure lessons learned feed back into both technical controls and governance processes.

Key Responsibilities:

·       Serve as Incident Commander for all Severity-1 and Severity-2 security incidents — lead war rooms, make containment decisions, coordinate cross-functional response, and manage executive communications

·       Build and maintain the incident response playbook librar

Similar Openings in DevOps & Cloud

View all in category