Job Title: Cyber Security Incident Engineer
Bandar Seri Begawan , Brunei-M, Brunei Darussalam
Notice
- Closing Date: Tuesday, 06 October 2026
- Please submit a PDF copy of your CV, IC, Academic and Professional Certificate(s)
- Only shortlisted candidates will be notified
Job Description
The purpose of the function of a Cyber Security Incident Engineer is to provide initial detection, analysis and response to security incidents within an organisation. The role serves several key purposes such as early incident detection, incident triage and analysis, timely incident detection, timely incident response and documenting incident details for next action.
Responsibilities and Tasks
- Monitors security alerts and events from various sources, such as SIEM, NDR, and other security tools
- Analyses incoming alerts and triage them based on predefined criteria to determine their priority and escalates as necessary
- Performs initial investigations to gather additional information and context about the alerts
- Detects and identifies potential security incidents based on analysis of security events, logs, and alerts
- Conducts preliminary analysis of incidents to determine their nature, severity, and potential impact on the organisation's systems and data
- Uses incident response playbooks and standard operating procedures to guide the initial response activities
- Provides support to L2 incident analyst in the execution of incident response activities
- Assists in coordinating and executing incident containment measures, such as isolating affected systems or blocking malicious activities
- Collaborates with other teams, such as system administrators and network engineers, to implement response actions
- Documents all aspects of security incidents, including initial findings, actions taken, and relevant details in incident ticketing system
- Conducts security control assessments, including firewall rules, access control audits, and configuration reviews
- Prepares incident reports and updates for Senior Manager of Cyber Security, providing clear and concise summaries of incident details, actions, and recommendations
- Ensures accurate and timely documentation to support post-incident analysis and reporting requirements
Competencies
- Knowledge of Cybersecurity Fundamentals
- Security Tools & Technologies
- Incident Response & Analysis
- Log Analysis & Threat Detection
- Cyber Threat Intelligence (CTI)
- Analytical Skills
- Written and spoken English
Area and Years of Experience
- Incident response, including incident identification, investigation, containment, eradication, and recovery processes with 5 years of experience
- Coordinating and leading incident response efforts is beneficial with 5 years of experience
- Exposure to threat intelligence analysis, including monitoring and analysing threat feeds, identifying emerging threats, and understanding their potential impact on the organisation's security posture with 5 years of experience
- Preparing incident reports, documenting incident details, actions taken, and lessons learned and familiarity with incident management frameworks and reporting standards is beneficial with 5 years of experience
Education
Higher National Diploma in Information Technology, Computer Science or relevant areas and equivalent working experience.