< Back to search
SAP • Pasig City, PH

Cyber Defense Sr Specialist

Employment type:  Full time
8.4

/10

Transparency ranking
Apply now

Job Description

We help the world run better
At SAP, we keep it simple: you bring your best to us, and we'll bring out the best in you. We're builders touching over 20 industries and 80% of global commerce, and we need your unique talents to help shape what's next. The work is challenging – but it matters. You'll find a place where you can be yourself, prioritize your wellbeing, and truly belong. What's in it for you? Constant learning, skill growth, great benefits, and a team that wants you to grow and succeed.

Summary

We are seeking an experienced Senior Incident Response Analyst to join our security operations team. With nearly a decade or more of hands-on experience, you will lead complex security investigations, and drive high fidelity cases for incident response team. The ideal candidate combines deep technical expertise in digital forensics and endpoint security with strong cloud security capabilities, automation skills.

What you'll do

You will triage security alerts from Enterprise Detection and SIEM platforms to determine scope, severity, and priority, conducting initial assessments and root cause analysis while coordinating escalations to IR Investigators when needed. In this role, you will validate suspected cyber-attacks, scope incidents, support forensic investigations, and provide remediation guidance including attack remediation strategies. Involved in continuous improvements of IR procedures, playbooks, runbooks, and SOPs.

Additionally, you will collaborate with other security stakeholders to enhance detection and alerting mechanisms, coordinate communication during escalations, and provide supporting evidence for forensic investigations.

What you bring

You should have demonstrated experience in cyber-attack analysis managing cases with enterprise SIEM or Incident Management systems. Previous experience of supporting multi-function, cross-organizational teams is also highly desirable.

We are looking for analytical, critical thinkers, who have an eye for detail and are solution orientated. You should be quick to learn and adapt and operate in a dynamic environment.

You typically will have most of the following technical skills and experience:

  • 9-13 years of hands-on experience in cybersecurity incident response or similar investigator role, with proven experience leading security incidents in enterprise environments
  • Demonstrated experience working in “follow the sun” model SOC or incident response environments managing cases with enterprise SIEM and Incident Management systems
  • Strong experience with cloud security operations (AWS preferred) including GuardDuty, CloudTrail, and cloud incident response
  • Proficiency in Python scripting with a portfolio of automation projects (GitHub, GitLab, or similar)
  • Track record of mentoring junior team members and supporting multi-function, cross-organizational teams
  • Demonstrated improvement experience including playbook development and after lessons learned facilitation
  • Industry certifications such as GCIH, GCFA, GCFE, GREM (preferably)
  • Advanced security certifications such as CISSP or CCSP
  • Cloud security certification such as AWS Certified Security – Specialty

Solid knowledge of one or more:

  • Conduct advanced forensic investigations across multiple operating systems and enterprise environments, performing evidence collection and analysis following proper chain-of-custody procedures
  • Utilize industry-standard forensic tools for memory and disk analysis to identify indicators of compromise and attack methodologies
  • Develop and refine forensic playbooks, standard operating procedures, and response documentation
  • Monitor and respond to cloud security alerts, investigating suspicious activities including unauthorized access, privilege escalation, and data exfiltration
  • Configure and manage cloud infrastructure for forensic analysis, threat hunting, and security testing purposes
  • Integrate security tools and build automated response workflows to enhance detection and response capabilities
  • Utilize scripting and automation for platform-specific tasks and process efficiency
  • Map incidents to industry-standard threat frameworks and apply knowledge of advanced threat actor methodologies to identify sophisticated attacks

#LI-RC6

Bring out your best
SAP innovations help more than four hundred thousand customers worldwide work together more efficiently and use business insight more effectively. Originally known for leadership in enterprise resource planning (ERP) software, SAP has evolved to become a market leader in end-to-end business application software and related services for database, analytics, intelligent technologies, and experience management. As a cloud company with two hundred million users and more than one hundred thousand employees worldwide, we are purpose-driven and future-focused, with a highly collaborative team ethic and commitment to personal development. Whether connecting global industries, people, or platforms, we help ensure every challenge gets the solution it deserves. At SAP, you can bring out your best.

We win with inclusion
SAP’s culture of inclusion, focus on health and well-being, and flexible working models help ensure that everyone – regardless of background – feels included and can run at their best. At SAP, we believe we are made stronger by the unique capabilities and qualities that each person brings to our company, and we invest in our employees to inspire confidence and help everyone realize their full potential. We ultimately believe in unleashing all talent and creating a better world.

SAP is committed to the values of Equal Employment Opportunity and provides accessibility accommodations to applicants with physical and/or mental disabilities. If you are interested in applying for employment with SAP and are in need of accommodation or special assistance to navigate our website or to complete your application, please send an e-mail with your request to Recruiting Operations Team: Careers@sap.com.

For SAP employees: Only permanent roles are eligible for the SAP Employee Referral Program, according to the eligibility rules set in the SAP Referral Policy. Specific conditions may apply for roles in Vocational Training.

Qualified applicants will receive consideration for employment without regard to their age, race, religion, national origin, ethnicity, gender (including pregnancy, childbirth, et al), sexual orientation, gender identity or expression, protected veteran status, or disability, in compliance with applicable federal, state, and local legal requirements.

Successful candidates might be required to undergo a background verification with an external vendor.

AI Usage in the Recruitment Process

For information on the responsible use of AI in our recruitment process, please refer to our Guidelines for Ethical Usage of AI in the Recruiting Process.

Please note that any violation of these guidelines may result in disqualification from the hiring process.

Requisition ID: 449644 | Work Area: Information Technology | Expected Travel: 0 - 10% | Career Status: Professional | Employment Type: Regular Full Time | Additional Locations: #LI-Hybrid


Company benefits

25 (UK) 30 (Germany) 21 (India) days annual leave + bank holidays
Accrued annual leave – 1 day/year up to 30 days (UK)
Open to job sharing
Sabbaticals
Adoption leave – Up to 52 weeks (UK)
Open to part time work for some roles
Returnship
Equity packages
Shared parental leave
Enhanced maternity leave
Fertility benefits
Pregnancy support
On-site childcare
Share options
Electric Car Salary Sacrifice
Gym membership
Dental coverage
Health insurance
Private GP service
Mental health platform access
Life assurance
Life insurance
Enhanced pension match/contribution
Enhanced paternity leave
Travel insurance
Cycle to work scheme
On-site gym
Bike parking
Enhanced sick pay
Emergency leave
Enhanced sick days
Company car
Open to part-time employees
Work from anywhere scheme
Childcare credits
Fertility treatment leave
Pregnancy loss leave
Carer’s leave
Nursery salary sacrifice scheme
Family health insurance
Women’s health leave
Annual bonus
401K
Referral bonus
Joining bonus
Employee discounts
Loyalty programme
Non-contributory pension
Personal development days
Personal development budgets
L&D budget
Language lessons
Learning license
Study support
Studying sabbaticals
Lunch and learns
In house training
Hackathons
Professional subscriptions
Further education support

Working at SAP

Company employees:

107,000

Gender diversity (m:f):

65:35

Hiring in countries

Argentina

Australia

Austria

Bahrain

Belgium

Brazil

Bulgaria

Canada

Chile

China

Colombia

Croatia

Czechia

Denmark

Egypt

Finland

France

Germany

Greece

Hong Kong

Hungary

India

Indonesia

Ireland

Israel

Italy

Japan

Kazakhstan

Malaysia

Mexico

Morocco

Netherlands

New Zealand

Norway

Pakistan

Peru

Philippines

Poland

Portugal

Qatar

Romania

Saudi Arabia

Serbia

Singapore

Slovakia

Slovenia

South Africa

South Korea

Spain

Sweden

Switzerland

Taiwan

Thailand

Türkiye

Ukraine

United Arab Emirates

United Kingdom

United States

Vietnam

Office Locations

Other jobs you might like