About the job Incident Response/Cybersecurity Engineer
Swak BPO Corp. is one of the fastest-growing BPO companies in the Clark Freeport Zone. We are committed to delivering outstanding service to our clients through professionalism, energy, and enthusiasm. Our workplace fosters a culture of teamwork, stability, and dedication. As we continue to grow, we are looking for an Incident Response/Cybersecurity Engineer to join our dynamic team.
The Incident Response Engineer is responsible for monitoring, investigating, containing, and responding to cybersecurity threats and enterprise-wide technology incidents across Staff Boom's global environment. This role works closely with Infrastructure, Cloud Operations, Identity & Access Management, Support Services, and other technical teams to identify security risks, minimize operational impact, preserve forensic evidence when appropriate, and continuously improve the organization's security posture.
The ideal candidate is analytical, detail-oriented, and thrives in a fast-paced environment where quick decision-making, strong technical troubleshooting, and effective communication are essential.
Job Responsibilities:
- Monitor security monitoring platforms, endpoint protection tools, and incident management systems for potential cybersecurity threats and operational incidents.
- Investigate security alerts to determine legitimacy, scope, impact, and required response actions.
- Respond to cybersecurity incidents including malware infections, phishing attacks, unauthorized access attempts, suspicious authentication events, and other security-related activities.
- Coordinate incident response efforts with Infrastructure, Cloud Operations, Identity & Access Management, Support Services, and business stakeholders.
- Perform incident containment, eradication, recovery, and validation activities while minimizing business disruption.
- Collect, preserve, and document forensic evidence when required to support investigations.
- Conduct root cause analysis and develop recommendations to reduce future risk.
- Maintain detailed incident documentation, timelines, and response activities within the organization's ticketing and documentation platforms.
- Develop and maintain incident response playbooks, standard operating procedures, and knowledge base documentation.
- Participate in security awareness initiatives, tabletop exercises, disaster recovery testing, and continuous improvement activities.
- Track incident trends and provide reporting, metrics, and recommendations to leadership.
- Support regulatory, audit, and compliance activities by providing documentation and evidence related to security incidents and response processes.
- Create and maintain Knowledge Base articles and Frequently Asked Questions (FAQs) to assist Support Services Engineers and other operational teams.
Job Requirements:
- Willingness and ability to work a 24x7x365 rotational shift schedule, including Day, Mid, Night, weekends, and holidays, as required by the Incident Response Team schedule
- CompTIA Security+ (or equivalent industry certification) (Required)
- 2+ years of experience in Information Technology, Security Operations, Incident Response, or Help Desk environments.
- Experience managing incident queues using platforms such as Ivanti, ServiceNow, Jira Service Management, or similar IT Service Management (ITSM) solutions.
- Strong understanding of Windows operating systems, Active Directory, Microsoft 365, and endpoint troubleshooting.
- Familiarity with endpoint protection, antivirus, endpoint detection and response (EDR), and security monitoring solutions.
- Working knowledge of networking fundamentals, including TCP/IP, DNS, DHCP, VPNs, and common network troubleshooting techniques.
- Basic understanding of cybersecurity frameworks, incident response methodologies, and security best practices.
Incident Management
- Ability to investigate, prioritize, document, and coordinate responses to multiple security incidents simultaneously.
- Strong analytical and troubleshooting skills with the ability to identify root causes and recommend corrective actions.
- Experience documenting incident timelines, evidence, and remediation activities.
Compliance & Documentation
- Knowledge of security documentation, audit evidence collection, and compliance reporting.
- Ability to produce clear, accurate, and detailed technical documentation supporting internal policies and regulatory requirements.
Communication
- Excellent written and verbal communication skills with the ability to explain technical concepts to both technical and non-technical audiences.
- Strong customer service mindset and ability to communicate calmly during high-impact incidents.
Desired Skills & Certifications (Nice-to-Haves)
Experience
- Previous experience in a Security Operations Center (SOC) or Incident Response environment.
- Experience with Microsoft Defender, Microsoft Entra ID, Microsoft 365 Security, or similar Microsoft security technologies.
- Experience using SIEM, EDR, vulnerability management, or threat detection platforms.
- Experience supporting cloud environments such as Microsoft Azure or AWS.
- Familiarity with phishing investigations, identity security, and endpoint security.
Certifications
- CompTIA CySA+
- GIAC Certified Incident Handler (GCIH)
- Microsoft Certified: Security Operations Analyst Associate (SC-200)
- Microsoft Certified: Azure Security Engineer Associate (AZ-500)
- Certified Information Security Manager (CISM)
- Certified Information Systems Security Professional (CISSP)
- ITIL Foundation
Why work with Swak BPO Corp.?
- Opportunity to work with international teams and companies
- Opportunity in promotions and salary increases
- A company that provides HMO; upon reaching your second year with the company, you will get one (1) free dependent at no additional cost
- Free meals prepared and provided by the company to promote a healthy lifestyle
- Free shuttle services provided around Angeles City and nearby areas
- A recreational facility that provides comfort and entertainment for employees to unwind
*This is going to be on-site work. Our offices are located in Clark Freeport Zone, Angeles City, Pampanga.