As a DFIR Associate Manager, you will lead and support the investigation of high-impact cybersecurity incidents while helping clients improve their cyber resilience. You will also have direct opportunities to pursue advanced industry certifications (such as OSCP, OSDA, CDSA, CPTS, GCFA, GCFE, GMON, GCIH, GREM, CRTO, and CRTL) with full sponsorship and upskilling support to accelerate your career advancement.
Salary Package: Competitive compensation package aligned with industry standards!
Additional Perks: Day 1 HMO and Life Insurance coverage, flexible working arrangements, company-sponsored training and certifications!
Work Setup: Hybrid - Cubao, Quezon City
Responsibilities
- Lead and support response efforts during critical cybersecurity incidents, investigating ransomware attacks, malware infections, insider threats, data breaches, BEC, DDoS, and APTs.
- Conduct detailed forensic investigations of endpoints, servers, cloud environments, and mobile devices to determine scope, impact, root cause, and remediation requirements.
- Collaborate with security teams and stakeholders to coordinate response activities, communicate findings, and develop enhanced incident response playbooks and procedures.
- Conduct proactive threat hunting, optimize security tools and detection capabilities, and mentor team members through knowledge-sharing sessions.
Qualifications
- College Graduate with a minimum of 5 years of hands-on Digital Forensics and Incident Response (DFIR) experience.
- Strong mastery of the Incident Response Lifecycle, digital forensics methodologies, MITRE ATT&CK framework, Windows/Linux operating systems, and networking/security fundamentals.
- Hands-on expertise in memory, disk, and network forensics, static/dynamic malware analysis, and industry-standard tools (FTK, Autopsy, Volatility, EnCase, Magnet AXIOM, SIFT, REMnux, etc.).
- Nice-to-Have: Mobile forensics experience, threat intelligence/hunting, Python/PowerShell scripting, and GIAC or equivalent industry certifications.