Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Cyber Incident Response Specialist L3 image - Rise Careers
Job details

Cyber Incident Response Specialist L3

Company:

Sopra Steria is a listed European tech leader specializes in Consulting, Digital Service, and Software. We have 60,000 employees worldwide located in different regions (Europe, North America and Asia), whereby Singapore is the HQ for APAC. EvaGroup Asia Pacific is part of Sopra Steria I2S APAC, in charge of Infrastructure, Cloud and Cybersecurity services.

 

For this position, we are looking for a Cyber Team Lead to assist one of our client – a leading global investment bank.

 

Background:

APAC Production Security teams are responsible for multiple IT Security activities for in the Asia Pacific region, such as:

1.       IT Production Security Governance, PMO & Risks

2.       Network Security and Security Design & Architecture

3.       Vulnerability & Compliance Management

4.       IAM Production

5.       Production CSIRT, Detection & SIEM Engineering

6.       Production support of the Security platforms

 

Team is looking for Cybersecurity expert/SME in Detection Engineering & Security Investigation areas, part of Production SOC & Security Investigation & Incident Response team.

 

Responsibilities:

  • Lead technical activities (security use case definition, design, implementation & enrichment) in the team of IT Production Security Investigation & Incident Response based on real-world attack scenarios and framework like MITRE ATT&CK, ensuring robust security detection posture across various layers.
  • Understand ongoing security threats in the wild and propose security use case to detect and when possible, protect or mitigate.
  • Lead technical activities (definition, R&D/threat hunting) in the team of IT Production Security Investigation & Incident Response and oversee the detection capabilities of the 24/7 regional IT Production SOC
  • Respond to Cyber / IT security incidents and evaluates the type and severity of security events.
  • Identify recurring security issues and risks and develops mitigation plans and recommends process improvements.
  • Partner with global, regional and local stakeholders to ensure organizational and procedural efficiency and readiness for detection of suspicious events and reaction
  • Continuously improve the processes to strengthen the current SOC framework via review of policies and operational playbooks

 

Contributing Responsibilities:

  • Partner with the APAC Business CSIRT for integrated security monitoring and alert/incident handling operations.
  • Contribute to local security incident response outside the direct scope of responsibilities (i.e.,- local IT production in some APAC business entities)
  • Contribute to the compliance with regulatory requirements and internal policies
  • Contribute to the reporting of all incidents according to the Incident Management System
  • Contribute to the control frameworks in day‐to‐day business activities, such as Control Plan;
  • Participate to Audit interview and provide the require evidence
  • Candidate MUST have 7 or more years of experience on overall cybersecurity incident response with 4+ years specifically on security use case design, development, coding
  • Experience in security use case design/development with understanding of Java language
  • Good working knowledge of Linux (RedHat/Ubuntu)
  • Working knowledge to interpret security logs or instructions into threat models. SecOPS-DevOPS mindset & skills.
  • Experience and knowledge in investigating incidents, remediation, tracking and follow-up for incident closure with concerned teams, stakeholders.
  • Thorough understanding of technologies and security concepts, with knowledge & hands on experience in SIEM Product and Security Incident Management
  • Experience of performing security monitoring and incident response activities in an advanced Security Operation Centers (SOC) environment (log analysis, event analysis, incident investigation, reporting)
  • Comfortable working with and making the most of large data sets (collection, analysis, response), creating content/use cases/models and bringing an automation mindset
  • Experience in SIEM on ELK(Elastic Logstash Kibana) stack is a plus
  • Professional credentials in one of the relevant IT Security disciplines is a plus (SANS / CISSP / OSCP)
  • Experience in common scripting languages such as Python, PowerShell, Bash, SQL is a plus

Personal Attributes Requirements:

  • Strong problem-solving skills
  • Good communication skills (English is MUST, French is added advantage)
  • Positive attitude, willing to upskill and carry out in-depth troubleshooting
  • Has the ability to work autonomously and think on feet, be-proactive.
  • Good interpersonal skills and team player
  • High energy level coupled with a desire to take on responsibility
  • Able to multi-task & deliver within agreed deadlines
  • Regular team buildings
  • 18 leave days / year
  • Insurance: GP, Hospitalisation, Dental and Optical Insurance
  • Annual bonus
  • Working hours: from 9am to 6pm, Monday to Friday
  • Training and certifications paths

Average salary estimate

$110000 / YEARLY (est.)
min
max
$100000K
$120000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Cyber Incident Response Specialist L3, Sopra Steria I2S

Join Sopra Steria as a Cyber Incident Response Specialist L3 and take your cybersecurity career to the next level! In this dynamic role, you will lead a capable team dedicated to protecting a prestigious global investment bank. Your expertise will help shape our strategies in areas like detection engineering, incident response, and vulnerability management. As part of the APAC Production Security teams, you'll craft security use cases grounded in real-world attack scenarios, using frameworks like MITRE ATT&CK to bolster our defenses. Your keen understanding of ongoing threats will allow you to propose proactive solutions, ensuring our detection frameworks are strong and adaptive. Your role will involve direct interaction with global and local stakeholders, providing you with a platform to implement necessary process improvements that drive our operational efficiency forward. With over 7 years of cybersecurity experience and strong technical skills – particularly in security use case design and development with languages like Java and Python – you're prepared to thrive in a fast-paced environment. Sopra Steria provides an engaging atmosphere, complete with opportunities for continuous learning, generous leave days, and excellent insurance and bonus schemes. If you are a collaborative team player ready to tackle complex security challenges and be part of a supportive and innovative environment, we’re excited to hear from you!

Frequently Asked Questions (FAQs) for Cyber Incident Response Specialist L3 Role at Sopra Steria I2S
What are the responsibilities of a Cyber Incident Response Specialist L3 at Sopra Steria?

As a Cyber Incident Response Specialist L3 at Sopra Steria, you'll lead a team in technical activities related to IT production security investigation and incident response. This includes defining and enriching security use cases, responding to cyber incidents, evaluating their severity, and collaborating with stakeholders for organizational efficiency.

Join Rise to see the full answer
What qualifications are needed for the Cyber Incident Response Specialist L3 position at Sopra Steria?

Candidates must have at least 7 years of experience in cybersecurity incidents, with 4 years focused on security use case design and development. Proficiency in Java and Linux, a strong understanding of security concepts, and experience with SIEM and Security Incident Management are essential qualifications for this role.

Join Rise to see the full answer
How does Sopra Steria support the professional growth of Cyber Incident Response Specialist L3 employees?

Sopra Steria actively promotes professional development for Cyber Incident Response Specialist L3 roles through structured training and certification paths. Employees also benefit from mentorship opportunities and regular team-building activities that foster continuous learning and collaboration.

Join Rise to see the full answer
What soft skills are important for a Cyber Incident Response Specialist L3 at Sopra Steria?

Soft skills such as strong problem-solving capabilities, effective communication in English (and French as an advantage), and the ability to work autonomously are vital for a Cyber Incident Response Specialist L3 at Sopra Steria. Teamwork and a high energy level are equally essential to thrive within a dynamic team environment.

Join Rise to see the full answer
What does the work-life balance look like for a Cyber Incident Response Specialist L3 at Sopra Steria?

As a Cyber Incident Response Specialist L3 at Sopra Steria, you can expect a beneficial work-life balance with working hours from 9 AM to 6 PM, Monday to Friday. Employees enjoy 18 leave days per year along with insurance benefits, making it an appealing environment to maintain both personal and professional commitments.

Join Rise to see the full answer
Common Interview Questions for Cyber Incident Response Specialist L3
Can you explain your process for designing security use cases?

When designing security use cases, I start by analyzing potential threats using industry frameworks like MITRE ATT&CK. I then collaborate with my team to outline specific scenarios and develop detection rules based on real data. Continuous testing and refinement of these use cases help ensure their effectiveness.

Join Rise to see the full answer
How do you prioritize incident response tasks in a high-pressure environment?

Prioritizing incident response tasks involves assessing the severity and potential impact of security incidents. I categorize incidents based on their urgency and risk level, ensuring that critical issues are addressed immediately while maintaining communication with involved stakeholders throughout the process.

Join Rise to see the full answer
Describe your experience with security monitoring tools.

I have extensive experience working with various SIEM tools, including the ELK stack, focusing on log analysis and event investigation to enhance security postures. My role has required leveraging these tools for real-time monitoring and reporting, which has significantly improved incident detection capabilities.

Join Rise to see the full answer
What strategies do you use for threat hunting?

My threat hunting strategies involve leveraging shared intelligence sources, behavioral analysis, and historical event data to look for anomalies and potential threats. I often utilize automated scripts for log analysis, enabling proactive identification of suspicious activities before they escalate into incidents.

Join Rise to see the full answer
Can you discuss a challenging incident you managed and its outcome?

One challenging incident involved a sophisticated phishing attack aimed at a key employee. I swiftly coordinated with my team to implement immediate countermeasures, including isolating affected systems. Our quick actions not only contained the threat but also led to developing a training program to prevent similar incidents.

Join Rise to see the full answer
How do you work with teams across different regions or departments during an incident?

Effective communication is key when working with cross-functional teams during an incident. I ensure alignment by utilizing established communication channels, providing regular updates, and clarifying roles and responsibilities. This collaborative approach ensures that all parties are informed and can respond effectively.

Join Rise to see the full answer
What role does documentation play in incident response?

Documentation is essential in incident response as it provides a structured record of incidents, actions taken, and lessons learned. This not only aids in compliance but also helps inform future incident management strategies and improves the overall security posture of the organization.

Join Rise to see the full answer
How do you keep your cybersecurity knowledge current?

To stay updated in cybersecurity, I regularly participate in webinars, join professional networking groups, and enroll in relevant training courses. Following industry news and trends is also crucial, as it helps me adapt existing strategies and anticipate emerging threats.

Join Rise to see the full answer
What do you consider the most critical skills for a Cyber Incident Response Specialist?

The most critical skills for a Cyber Incident Response Specialist include strong analytical abilities, technical proficiency in cybersecurity tools and protocols, and excellent communication skills. These skills enable effective incident detection, response, and collaboration across teams, leading to a more resilient security posture overall.

Join Rise to see the full answer
Give an example of how you have used data analytics in your previous roles.

In my last role, I utilized data analytics to analyze incident trends over time. By identifying patterns in security breaches, I was able to make informed recommendations for improving our security measures, which resulted in a noticeable decrease in repeat incidents.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 6 days ago

Join Sopra Steria as a Support Atelier Digital and play a pivotal role in transforming aerospace business operations through innovative digital solutions.

Photo of the Rise User
Sopra Steria I2S Remote No location specified
Posted 6 days ago

Join Sopra Steria as a Cybersecurity Analyst and leverage your expertise in a dynamic, hybrid working environment.

Posted 10 days ago

We are looking for a skilled SAP S/4Hana Consultant to support our clients in their transition to SAP S/4Hana at DBSync.

Photo of the Rise User

We are seeking a skilled Premier Support Services Engineer to enhance city technology services at the Department of Technology in San Francisco.

Photo of the Rise User
Ardent Hybrid Huntsville, AL
Posted 4 days ago

Join Ardent as an IT Systems Engineer and contribute to critical missions supporting the Department of Justice.

Photo of the Rise User
Posted 9 days ago

As a Linux System Administrator at CesiumAstro, you'll play a critical role in managing IT infrastructure for groundbreaking communication systems tailored for aerospace applications.

Join Lucky Strike Entertainment as an LMS System Administrator, where you'll enhance training delivery through effective management of our Learning Management System.

Photo of the Rise User
Posted 4 days ago

Join Novacore as a Database Administrator and be at the forefront of transforming the commercial insurance landscape.

FHU is looking for a seasoned IT Generalist to enhance their technology infrastructure and support innovative solutions in a people-first environment.

Photo of the Rise User
Posted 4 days ago

Sony Corporation of America is looking for a Principal, Security Data Architect to drive data architecture initiatives within their Corporate Information Security Division.

Headquartered in Paris, France, Sopra Steria is a digital transformation company that provides comprehensive portfolios of end-to-end service offerings on the market: consulting, systems integration, software development, infrastructure managemen...

6 jobs
MATCH
VIEW MATCH
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
April 10, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
C
Someone from OH, Middletown just viewed Operations Analyst at Core Specialty Insurance
Photo of the Rise User
12 people applied to IT Intern - Seasonal at Carowinds
Photo of the Rise User
47 people applied to IT Intern at USAA
A
Someone from OH, Strongsville just viewed Graphic Design Intern at Anvil NorthWest
W
Someone from OH, Uhrichsville just viewed Director Operations at WVUMedicine
Photo of the Rise User
Someone from OH, Cincinnati just viewed Game Director, Scripps Sports at The E.W. Scripps Company
Photo of the Rise User
Someone from OH, Lorain just viewed 3D Modeler / Graphic Designer - Freelance at Twine
o
Someone from OH, Oxford just viewed Digital Media & Marketing Student Intern at osu
Photo of the Rise User
8 people applied to Junior Security Engineer at Epic
Photo of the Rise User
Someone from OH, Beachwood just viewed Dispensary Tech at Ayr Wellness
Photo of the Rise User
56 people applied to Cybersecurity Intern at Dewberry
Photo of the Rise User
Someone from OH, Springfield just viewed Front Desk Clerk at Marriott International
L
Someone from OH, Akron just viewed Junior Graphic Designer at Little Spoon
Photo of the Rise User
Someone from OH, Columbus just viewed Licensing and Regulatory Compliance Analyst at Sportradar
Photo of the Rise User
Someone from OH, Mansfield just viewed US_EN_Operations_Warehouse Loader (Part Time) at Red Bull
Photo of the Rise User
Someone from OH, Dublin just viewed Salesforce Administrator at Multiverse
Photo of the Rise User
Someone from OH, Pickerington just viewed Salesforce Solution Analyst at GoodLeap
S
Someone from OH, Pickerington just viewed Salesforce Project Manager at Studio Science
Photo of the Rise User
Someone from OH, Dayton just viewed Medical Receptionist at LifeStance Health
Photo of the Rise User
13 people applied to SOC Analyst at Prosegur
Photo of the Rise User
59 people applied to Cyber Crime Analyst at TEKsystems
Photo of the Rise User
12 people applied to IT Support Intern at SoundCloud
C
Someone from OH, Massillon just viewed RN Ambulatory - Outpatient Infusion Therapy at CCF
Photo of the Rise User
Someone from OH, Columbus just viewed HR Business Partner (Maternity Cover) at Marshmallow
Photo of the Rise User
Someone from OH, Columbus just viewed Community Outreach Canvasser $24/Hr at Confidential
Photo of the Rise User
Someone from OH, Cincinnati just viewed Email Marketing Coordinator at Creative Circle
Photo of the Rise User
Someone from OH, Columbus just viewed UX Researcher, Amazon Autos at Amazon
Photo of the Rise User
Someone from OH, Cincinnati just viewed AI training and enablement at Writer