You will own the end-to-end incident response lifecycle at CP Axtra — from detection and triage through containment, eradication, and recovery, all the way to post-incident review and capability improvement. You are the Incident Commander during major security events, the person in the war room making real-time decisions about containment actions, stakeholder communications, and escalation paths.

Beyond crisis response, you'll build and mature the incident response programme itself. This means developing playbooks tailored to CP Axtra's specific threat scenarios (ransomware hitting POS systems, credential stuffing on the e-commerce login, insider threats in finance systems), running realistic tabletop exercises, and driving post-incident reviews that produce actual operational improvements — not just reports that gather dust.

You'll manage the SOC team's operational effectiveness, own the KPIs that matter (MTTD, MTTR, false positive rates), and work closely with the Security Architect and GRC teams to ensure lessons learned feed back into both technical controls and governance processes.

Key Responsibilities

  • Serve as Incident Commander for all Severity-1 and Severity-2 security incidents — lead war rooms, make containment decisions, coordinate cross-functional response, and manage executive communications
  • Build and maintain the incident response playbook library — at least 15 scenario-specific playbooks covering ransomware, data exfiltration, credential compromise, DDoS, insider threat, cloud breach, and supply chain compromise
  • Drive post-incident reviews (PIRs) for every significant incident, producing root cause analyses with specific, tracked remediation actions — not generic recommendations
  • Own and improve SOC operational KPIs: MTTD < 30 minutes, MTTR < 4 hours for critical incidents, false positive rate < 20% on high-priority alerts
  • Design and execute quarterly tabletop exercises and annual red team/purple team engagements, measuring response effectiveness and identifying capability gaps
  • Manage relationships with MSSP/MDR providers — review SLAs, escalation performance, and detection quality monthly; hold them accountable to contractual commitments
  • Develop and maintain the incident communication framework — pre-drafted templates for executive briefings, customer notifications, regulatory reports (PDPA breach notification), and media holding statements
  • Coordinate with legal, compliance, and communications teams during incidents that have regulatory, legal, or public-relations implications
  • Maintain the threat intelligence integration pipeline — ensure IOCs and TTPs from threat feeds are operationalised into detection rules within 24 hours
  • Build incident response capabilities in the SOC team through structured skill development, scenario-based training, and mentoring


Requirements

  • EDR/XDR: Cortex XDR, CrowdStrike Falcon — investigation, threat hunting, and response actions
  • SIEM/SOAR: Splunk, Microsoft Sentinel, or equivalent — log analysis, correlation rules, automated playbooks
  • Forensics: Disk and memory forensics tools, network packet analysis — enough to guide investigations and validate findings
  • Threat intelligence: MISP, commercial threat feeds — IOC management and operationalisation
  • Cloud investigation: GCP, Azure, AWS — cloud-native logging (CloudTrail, Activity Log, Audit Log) and investigation procedures
  • Network security: Palo Alto, Fortinet — log analysis, firewall containment actions during incidents

MUST-HAVE REQUIREMENTS

These are non-negotiable. If you do not meet all of these, this role is not the right fit.

  • 5+ years in cyber security with at least 2 years leading incident response or SOC operations
  • Demonstrated experience as Incident Commander during real security incidents — you've made containment decisions under pressure, not just participated in tabletops
  • Strong knowledge of attack frameworks (MITRE ATT&CK, Cyber Kill Chain) and ability to map real incidents to TTPs for detection improvement
  • Experience with EDR/XDR platforms (Cortex XDR, CrowdStrike, or equivalent) and SIEM — you can investigate alongside your analysts, not just manage from a dashboard
  • Excellent communication skills — ability to translate technical incident details into business impact language for executives and non-technical stakeholders
  • Fluent in Thai; working English proficiency for vendor coordination and threat intelligence consumption

NICE-TO-HAVE

These will set you apart from other candidates:

  • GCIH, GCFA, GCIA, or equivalent incident response / forensics certifications
  • Experience managing MSSP/MDR relationships and holding third-party SOCs accountable to SLAs
  • Familiarity with Thai regulatory incident reporting requirements (PDPA breach notification timelines, sector-specific reporting)
  • Experience with incident response in retail or e-commerce environments — POS malware, card skimming, credential stuffing at scale
  • Purple team experience — working with offensive security teams to validate detection and response capabilities
āļ›āļĢāļ°āļŠāļšāļāļēāļĢāļ“āđŒāļ—āļĩāđˆāļˆāļģāđ€āļ›āđ‡āļ™
  • 5 āļ›āļĩ
āđ€āļ‡āļīāļ™āđ€āļ”āļ·āļ­āļ™
  • āļŠāļēāļĄāļēāļĢāļ–āļ•āđˆāļ­āļĢāļ­āļ‡āđ„āļ”āđ‰
āļŠāļēāļĒāļ‡āļēāļ™
  • āļāļēāļĢāļˆāļąāļ”āļāļēāļĢ
āļ›āļĢāļ°āđ€āļ āļ—āļ‡āļēāļ™
  • āļ‡āļēāļ™āļ›āļĢāļ°āļˆāļģ

āđ€āļāļĩāđˆāļĒāļ§āļāļąāļšāļšāļĢāļīāļĐāļąāļ—

āļˆāļģāļ™āļ§āļ™āļžāļ™āļąāļāļ‡āļēāļ™:5000-10000 āļ„āļ™
āļ›āļĢāļ°āđ€āļ āļ—āļšāļĢāļīāļĐāļąāļ—:āļāļēāļĢāļ„āđ‰āļēāļŠāđˆāļ‡
āļ—āļĩāđˆāļ•āļąāđ‰āļ‡āļšāļĢāļīāļĐāļąāļ—:āļāļĢāļļāļ‡āđ€āļ—āļž
āđ€āļ§āđ‡āļšāđ„āļ‹āļ•āđŒ:www.cpaxtra.com
āļāđˆāļ­āļ•āļąāđ‰āļ‡āđ€āļĄāļ·āđˆāļ­āļ›āļĩ:1988
āļ„āļ°āđāļ™āļ™:4/5

CP Axtra āđ„āļĄāđˆāđ„āļ”āđ‰āđ€āļ›āđ‡āļ™āđ€āļžāļĩāļĒāļ‡āļšāļĢāļīāļĐāļąāļ— āđāļ•āđˆāđ€āļĢāļēāđ€āļ›āđ‡āļ™āļāļēāļĢāļ›āļāļīāļ§āļąāļ•āļīāļ§āļ‡āļāļēāļĢāļ„āđ‰āļēāļŠāđˆāļ‡āđāļĨāļ°āļ„āđ‰āļēāļ›āļĨāļĩāļ āđ€āļāļīāļ”āļ—āļĩāđˆāļāļĢāļļāļ‡āđ€āļ—āļžāļŊ āđāļĨāļ°āļ•āļ­āļ™āļ™āļĩāđ‰āđ€āļ›āđ‡āļ™āļŠāđˆāļ§āļ™āļŦāļ™āļķāđˆāļ‡āļ‚āļ­āļ‡āļ„āļĢāļ­āļšāļ„āļĢāļąāļ§ CP ALL āļ­āļĒāđˆāļēāļ‡āļ āļēāļ„āļ āļđāļĄāļīāđƒāļˆ āļāļēāļĢāđ€āļ”āļīāļ™āļ—āļēāļ‡āļ‚āļ­āļ‡āđ€āļĢāļēāļˆāļēāļ Siam Makro āļŠāļđāđˆ CP Axtra āđ„āļ”āđ‰āļ–āļđāļāļāļģāļŦāļ™āļ”āļ”āđ‰āļ§āļĒāļ™āļ§āļąāļ•āļāļĢāļĢāļĄāđāļĨāļ°āļ„āļ§āļēāļĄāļĄāļļāđˆāļ‡āļĄāļąāđˆāļ™āļŠāļđāđˆāļ„āļ§āļēāļĄāđ€āļ›āđ‡āļ™āđ€āļĨāļīāļĻ

āļ™āļĩāđˆāļ„āļ·āļ­āļŠāļīāđˆāļ‡āļ—āļĩāđˆāļ—āļģāđƒāļŦāđ‰āđ€āļĢāļēāđāļ•āļāļ•āđˆāļēāļ‡:

āļ­āđˆāļēāļ™āļ•āđˆāļ­

āļĢāđˆāļ§āļĄāļ‡āļēāļ™āļāļąāļšāđ€āļĢāļē: At CP Axtra, we believe in creating an AXTRA life for our employees. We offer competitive salaries and benefits, along with a hybrid workplace that promotes work-life balance. You'll have the opportunity to collaborate with talented individuals in a dynamic environment, working on challenging projec ... āļ­āđˆāļēāļ™āļ•āđˆāļ­

āđ€āļ‚āļ•āļ—āļĩāđˆāļ•āļąāđ‰āļ‡āļ—āļĩāđˆāļ—āļģāļ‡āļēāļ™: āļŠāļ§āļ™āļŦāļĨāļ§āļ‡
āļŠāļģāļ™āļąāļāļ‡āļēāļ™āđƒāļŦāļāđˆ: CP Axtra
Display map

āļŠāļ§āļąāļŠāļ”āļīāļāļēāļĢ

  • āđ€āļ„āļĢāļ·āđˆāļ­āļ‡āđāļšāļšāļžāļ™āļąāļāļ‡āļēāļ™
  • āļāļķāļāļ­āļšāļĢāļĄ
  • āļŠāđˆāļ§āļ™āļĨāļ”āļžāļ™āļąāļāļ‡āļēāļ™
  • āđ‚āļ„āļĢāļ‡āļāļēāļĢāļŠāđˆāļ‡āđ€āļŠāļĢāļīāļĄāļ„āļļāļ“āļ āļēāļžāļŠāļĩāļ§āļīāļ•
āļ—āļĩāđˆ WorkVenture āđ€āļĢāļēāđƒāļŦāđ‰āļĄāļđāļĨāđ€āļŠāļīāļ‡āđ€āļāļĩāđˆāļĒāļ§āļāļąāļšāļšāļĢāļīāļĐāļąāļ— āļšāļĢāļīāļĐāļąāļ— āļ‹āļĩāļžāļĩ āđāļ­āđ‡āļāļ‹āđŒāļ•āļĢāđ‰āļē āļˆāļģāļāļąāļ” (āļĄāļŦāļēāļŠāļ™) - (āđāļĄāđ‡āļ„āđ‚āļ„āļĢ) āđ‚āļ”āļĒāļĄāļĩāļ‚āđ‰āļ­āļĄāļđāļĨāļ—āļĩāđˆāđ€āļāļĩāđˆāļĒāļ§āļ‚āđ‰āļ­āļ‡ āļ•āļąāđ‰āļ‡āđāļ•āđˆāļ āļēāļžāļšāļĢāļĢāļĒāļēāļāļēāļĻāļāļēāļĢāļ—āļģāļ‡āļēāļ™ āļĢāļđāļ›āļ–āđˆāļēāļĒāļ‚āļ­āļ‡āļ—āļĩāļĄāļ‡āļēāļ™ āđ„āļ›āļˆāļ™āļ–āļķāļ‡āļĢāļĩāļ§āļīāļ§āđ€āļŠāļīāļ‡āļĨāļķāļāļ‚āļ­āļ‡āļāļēāļĢāļ—āļģāļ‡āļēāļ™āļ—āļĩāđˆāļ™āļąāđˆāļ™ āļ‹āļķāđˆāļ‡āļ‚āđ‰āļ­āļĄāļđāļĨāļ—āļļāļāļ­āļĒāđˆāļēāļ‡āļšāļ™āļŦāļ™āđ‰āļēāļ‚āļ­āļ‡āļšāļĢāļīāļĐāļąāļ— āļšāļĢāļīāļĐāļąāļ— āļ‹āļĩāļžāļĩ āđāļ­āđ‡āļāļ‹āđŒāļ•āļĢāđ‰āļē āļˆāļģāļāļąāļ” (āļĄāļŦāļēāļŠāļ™) - (āđāļĄāđ‡āļ„āđ‚āļ„āļĢ) āļĄāļĩāļžāļ™āļąāļāļ‡āļēāļ™āļ—āļĩāđˆāļāļģāļĨāļąāļ‡āļ—āļģāļ‡āļēāļ™āļ—āļĩāđˆāļšāļĢāļīāļĐāļąāļ— āļšāļĢāļīāļĐāļąāļ— āļ‹āļĩāļžāļĩ āđāļ­āđ‡āļāļ‹āđŒāļ•āļĢāđ‰āļē āļˆāļģāļāļąāļ” (āļĄāļŦāļēāļŠāļ™) - (āđāļĄāđ‡āļ„āđ‚āļ„āļĢ) āļŦāļĢāļ·āļ­āđ€āļ„āļĒāļ—āļģāļ‡āļēāļ™āļ—āļĩāđˆāļ™āļąāđˆāļ™āļˆāļĢāļīāļ‡āđ† āđ€āļ›āđ‡āļ™āļ„āļ™āđƒāļŦāđ‰āļ‚āđ‰āļ­āļĄāļđāļĨāļˆāļĢāļīāļ‡āļŠāļĄāļąāļ„āļĢāļ‡āļēāļ™ āļ§āļđāļ‹āđˆāļē āļ”āļĩāđ„āļ‹āļ™āđŒāļŠāļĄāļąāļ„āļĢāļ‡āļēāļ™ āļ”āļĢāļēāđ‚āļāđ‰āļŠāļĄāļąāļ„āļĢāļ‡āļēāļ™ āļ§āļĩāļ‹āļĩ āđāļŸāļšāļĢāļīāļ„āļŠāļĄāļąāļ„āļĢāļ‡āļēāļ™ āđāļšāļĢāļ™āļ”āđŒāđ€āļ”āđ‡āļ” āļ”āļī āđ€āļ­āđ€āļˆāļ™āļ‹āļĩāđˆ