Loading...
 
Share this Job
Information Technology

Senior Cyber Security Incident Responder

What we offer

Our company culture is focused on helping our employees enable innovation by building breakthroughs together. How? We focus every day on building the foundation for tomorrow and creating a workplace that embraces differences, values flexibility, and is aligned to our purpose-driven and future-focused work. We offer a highly collaborative, caring team environment with a strong focus on learning and development, recognition for your individual contributions, and a variety of benefit options for you to choose from. Apply now!

 

 

Summary

As an investigator in SAP's Global Security Operations team you will join a global team of security practitioners to mature SAP's security. You will be located in Shanghai (CN), an office belonging to the regional security hub Singapore, and reporting directly to the Head of Security Operations APJ. The main work will be to develop the SOC and DFIR functions as well as conducting and leading investigations and analysis.

This role will have the opportunity to work within SAP's Global Security functions and interacting in a complex and challenging environment to detect, react to and remediate cyber security incidents as well as to drive detection use case development forward.

 

The Role

    • Conducts investigations and forensics on internal and cloud assets for SAP and its line of businesses
    • Leads incidents of local and regional scale, sets investigation goals and prioritizes tasks
    • Drives continuous improvement and increases efficiency through standardization and automation
    • Conducts QA on incidents and provides clear areas of improvements for people and processes
    • Works independently and with management on highly visible and complex projects
    • Contributes to major, global scale incidents and crisis situations by conducting analysis and writing summaries or reports
    • Designs, implements and verifies new detection mechanisms and queries
    • Mentors analysts and helps develop skills
    • Is part of a 24/7 follow-the-sun organisation

 
Requirements

    • Degree in Computer Science or equivalent experience
    • Experience working in a 24/7 operational environment (Cyber Intelligence Fusion Center, SOC, NOC, Operations Center).Has Security certification (e.g. Security+, GCIA, GCIH, CISSP)
    • Proven experience in handling cyber security incidents including coordination of teams and driving root cause analysis as well as defining and leading mitigation and containment measures
    • Knowledge in the area of creation and maintenance of detection use cases and design of playbooks
    • Experience managing cases with enterprise SIEM or Incident Management systems (Information Security, Information Systems, Engineering or related work experience)
    • Technology: Good knowledge of one or more of the following: Windows/AD file system, registry functions and memory artifacts, Unix/Linux file systems and memory artifacts, Mac file systems and memory artifacts, Cybersecurity automation, SIEM tools (Splunk, Loggly, Sumo Logic, LogZilla, jKool, QRadar)
    • TCP/IP communications & knowledge of how common protocols and applications work at the network level, including DNS, HTTP(S), SSH, RDP and SMB
    • Experience in network security and network systems including LANs/WANs/VPNs/Firewalls and IDS’s
    • Experience with one or more scripting languages (PowerShell, Python, Bash, etc.)
    • Experience in forensics and reverse engineering (FTKimager, Autopsy/Sleuth Kit, X-Ways, Cellebrite Investigator/UFED, Ghidra, IDA, Volatility/Volcano, Wireshark, CAINE, Paladin, F-Response)
    • Experience with EDR tools and utilization for DFIR (Crowdstrike, MS Defender, Tanium, EndGame,)
    • Knowledge of APT actors; their tools, techniques, and procedures (TTPs), TTP methods and frameworks
    • Ability to demonstrate analytical expertise, close attention to detail, excellent critical thinking, logic, and solution orientation and to learn and adapt quickly
    • Ability to summarize and communicate findings and issues concise and clearly.

 

 

 

 

We are SAP

SAP innovations help more than 400,000 customers worldwide work together more efficiently and use business insight more effectively. Originally known for leadership in enterprise resource planning (ERP) software, SAP has evolved to become a market leader in end-to-end business application software and related services for database, analytics, intelligent technologies, and experience management. As a cloud company with 200 million users and more than 100,000 employees worldwide, we are purpose-driven and future-focused, with a highly collaborative team ethic and commitment to personal development. Whether connecting global industries, people, or platforms, we help ensure every challenge gets the solution it deserves. At SAP, we build breakthroughs, together.

 

Our inclusion promise

SAP’s culture of inclusion, focus on health and well-being, and flexible working models help ensure that everyone – regardless of background – feels included and can run at their best. At SAP, we believe we are made stronger by the unique capabilities and qualities that each person brings to our company, and we invest in our employees to inspire confidence and help everyone realize their full potential. We ultimately believe in unleashing all talent and creating a better and more equitable world.

 

SAP is proud to be an equal opportunity workplace and is an affirmative action employer. We are committed to the values of Equal Employment Opportunity and provide accessibility accommodations to applicants with physical and/or mental disabilities. If you are interested in applying for employment with SAP and are in need of accommodation or special assistance to navigate our website or to complete your application, please send an e-mail with your request to Recruiting Operations Team: Americas: Careers.NorthAmerica@sap.com or Careers.LatinAmerica@sap.com, APJ: Careers.APJ@sap.com, EMEA: Careers@sap.com.

 

EOE AA M/F/Vet/Disability:

Qualified applicants will receive consideration for employment without regard to their age, race, religion, national origin, ethnicity, age, gender (including pregnancy, childbirth, et al), sexual orientation, gender identity or expression, protected veteran status, or disability.

Successful candidates might be required to undergo a background verification with an external vendor.

 Requisition ID:310321 | Work Area: Information Technology | Expected Travel: 0 - 10% | Career Status: Professional | Employment Type: Regular Full Time  | Additional Locations: 

Senior Cyber Security Incident Responder

Facility:  310321
Posted Date:  Nov 17, 2021
Work Area:  Information Technology
Career Status:  Professional
Employment Type:  Regular Full Time
Expected Travel:  0 - 10%
Location: 

Shanghai, CN, 201203


Job Segment: ERP, Engineer, Cyber Security, SAP, Security, Technology, Engineering