· EDR/XDR: Cortex XDR, CrowdStrike Falcon — investigation, threat hunting, and response actions
· SIEM/SOAR: Splunk, Microsoft Sentinel, or equivalent — log analysis, correlation rules, automated playbooks
· Forensics: Disk and memory forensics tools, network packet analysis — enough to guide investigations and validate findings
· Threat intelligence: MISP, commercial threat feeds — IOC management and operationalisation
· Cloud investigation: GCP, Azure, AWS — cloud-native logging (CloudTrail, Activity Log, Audit Log) and investigation procedures
· Network security: Palo Alto, Fortinet — log analysis, firewall containment actions during incidents
These are non-negotiable. If you do not meet all of these, this role is not the right fit.
· 5+ years in cyber security with at least 2 years leading incident response or SOC operations
· Demonstrated experience as Incident Commander during real security incidents — you’ve made containment decisions under pressure, not just participated in tabletops
· Strong knowledge of attack frameworks (MITRE ATT&CK, Cyber Kill Chain) and ability to map real incidents to TTPs for detection improvement
· Experience with EDR/XDR platforms (Cortex XDR, CrowdStrike, or equivalent) and SIEM — you can investigate alongside your analysts, not just manage from a dashboard
· Excellent communication skills — ability to translate technical incident details into business impact language for executives and non-technical stakeholders
· Fluent in Thai; working English proficiency for vendor coordination and threat intelligence consumption