Department Manager - Cyber Incident Management
Indexed description
Beyond crisis response, you'll build and mature the incident response programme itself. This means developing playbooks tailored to CP Axtra's specific threat scenarios (ransomware hitting POS systems, credential stuffing on the e-commerce login, insider threats in finance systems), running realistic tabletop exercises, and driving post-incident reviews that produce actual operational improvements — not just reports that gather dust.
You'll manage the SOC team's operational effectiveness, own the KPIs that matter (MTTD, MTTR, false positive rates), and work closely with the Security Architect and GRC teams to ensure lessons learned feed back into both technical controls and governance processes.
Key Responsibilities
- EDR/XDR: Cortex XDR, CrowdStrike Falcon — investigation, threat hunting, and response actions
- SIEM/SOAR: Splunk, Microsoft Sentinel, or equivalent — log analysis, correlation rules, automated playbooks
- Forensics: Disk and memory forensics tools, network packet analysis — enough to guide investigations and validate findings
- Threat intelligence: MISP, commercial threat feeds — IOC management and operationalisation
- Cloud investigation: GCP, Azure, AWS — cloud-native logging (CloudTrail, Activity Log, Audit Log) and investigation procedures
- Network security: Palo Alto, Fortinet — log analysis, firewall containment actions during incidents
- 5+ years in cyber security with at least 2 years leading incident response or SOC operations
- Demonstrated experience as Incident Commander during real security incidents — you've made containment decisions under pressure, not just participated in tabletops
- Strong knowledge of attack frameworks (MITRE ATT&CK, Cyber Kill Chain) and ability to map real incidents to TTPs for detection improvement
- Experience with EDR/XDR platforms (Cortex XDR, CrowdStrike, or equivalent) and SIEM — you can investigate alongside your analysts, not just manage from a dashboard
- Excellent communication skills — ability to translate technical incident details into business impact language for executives and non-technical stakeholders
- Fluent in Thai; working English proficiency for vendor coordination and threat intelligence consumption
- GCIH, GCFA, GCIA, or equivalent incident response / forensics certifications
- Experience managing MSSP/MDR relationships and holding third-party SOCs accountable to SLAs
- Familiarity with Thai regulatory incident reporting requirements (PDPA breach notification timelines, sector-specific reporting)
- Experience with incident response in retail or e-commerce environments — POS malware, card skimming, credential stuffing at scale
- Purple team experience — working with offensive security teams to validate detection and response capabilities
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search