telecommunications organization
Technology
AssistantManager,CybersecurityIncidentResponse
Neural analysis suggests this role is
optimal for Manager candidates.
“Assistant Manager, Cybersecurity Incident Response at telecommunications organization. Skills: Incident Response, SIEM administration, Detection Engineering. Manage cybersecurity incidents. Achieve MTTD benchmarks”
What You'll Achieve.
Achieve MTTD benchmarks; Achieve MTTR benchmarks; Strengthen security posture
Industry & Context.
Incident investigation; Log analysis; Event correlation; Root cause analysis
What They're Looking For.
Must Have
5-8 years experience, SIEM administration, Elastic Stack environments, Incident triage, Log analysis, Detection rule engineering, MITRE ATT&CK-aligned use cases, Cross-department collaboration, Incident coordination, Presentation experience, Communication experience
Nice to Have
CISSP, GCIH, GCIA, CEH, Elastic Certified Engineer
What You'll Do.
Manage cybersecurity incidents
Achieve MTTD benchmarks
Achieve MTTR benchmarks
Administer Elastic SIEM platform
Create detection rules
Develop detection use cases
Coordinate with stakeholders
Manage Elastic Stack components
Lead integration efforts
Collaborate with IT teams
Collaborate with Network teams
Collaborate with Cloud teams
Present incident findings
Present root cause analyses
Present remediation plans
Conduct post-incident reviews
Implement lessons learned
How You'll Work.
Team & Collaboration
Internal stakeholders; External stakeholders; Data Engineering teams; Architecture teams; Security teams; Infrastructure teams; Tooling teams; IT teams; Network teams; Cloud teams
Communication Scope
Incident reporting; Incident discussions
Full Job Description
We are currently partnering with a leading technology-driven telecommunications organization that is scaling rapidly to support new digital initiatives and platforms. As part of this expansion, multiple roles are open across key functions to help build, maintain, and enhance next-generation solutions. This opportunity offers exposure to large-scale systems, innovative technologies, and a collaborative environment where skills and ideas make a real impact. Accountabilities: - End-to-end management of cybersecurity incidents, ensuring timely detection, triage, investigation, and resolution - Achieving and maintaining target MTTD (Mean Time to Detect) and MTTR (Mean Time to Respond) benchmarks. - Effective administration and optimization of the Elastic SIEM platform, including rule creation, tuning, and integrations. - Development of accurate and relevant detection use cases aligned with evolving threat patterns and organizational needs. - Ensuring timely escalation and coordination with internal and external stakeholders during major incidents. - Providing transparent and comprehensive incident reporting to leadership and relevant teams. - Drive operational excellence through monitoring, alerting, timely investigation and continuous fine tuning the alerts - Partner with Data Engineering, Architecture, Security, Infrastructure & Tooling teams to ensure aligned technical cyber security discussions Responsibilities: - Monitor, triage, and investigate alerts from multiple log sources (network, endpoint, cloud, and application). - Create, refine, and manage SIEM detection rules to capture the latest attack patterns. - Conduct log analysis and event correlation to identify potential intrusions or malicious behavior. - Drive use case ideation and validation to improve threat detection coverage and accuracy. - Manage and maintain Elastic Stack components (Elasticsearch, Logstash, Kibana, Beats) for operational efficiency. - Lead integration efforts with tools such as EDR, fir
Applying for this Assistant Manager, Cybersecurity Incident Response role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
How to Apply on Ashby
- Ashby is a fast modern ATS — most applications take under 3 minutes.
- The resume parser is strong; verify parsed experience dates and job titles.
- Custom screening questions are often scored algorithmically — answer completely.
- Location field affects geo-based screening; use your actual metro area.
ANONYMOUS · UNFILTERED
What do employees actually say about telecommunications organization?
Real rants from real employees. Read before you apply.