Security Incident Responder (IR):


Security incident responder (IR) is responsible to identify, triage, respond, contain, report, and recover from security incidents. It helps organizations by focusing on the resolution of security incidents in a timely and appropriate manner, providing clear visibility and traceability through the process.


This IR capability is heavily process focused and describes how a Cyber Security program should handle a security incident, including appropriate communication across the company.


Security Incident Management utilizes all the other capabilities identified in the Logical Operating Model in order to identify, triage, and respond to an security incident. It also provides an extension to the IR playbook process already in place within the SCBX group organizations with continuous improvement.

Key responsibilities with these requirements, but not limited to:

  • Establish a consistent approach to handle security incidents under committed OLA, SLA, MTTX matrix.

  • Effectively and efficiently contain and eradicate cyber threats with all subsidiaries.
  • Recover impacted assets from technical and business damage done by cyber threats.
  • Develop and distribute security incident reports to all key stakeholders.
  • Incorporate root cause and lessons learned into an improvement plan.
  • Strengthen processes and maturity of Group security operations.
  • Continuous improve security incident operations.
  • Security Incident Identification, Triage and Response with MS Sentinel SIEM and SOAR cover 24*7 detection & analysis, containment, eradication & post incident investigation on high, rather high, moderate, rather low and low severity.

  • Access to internal or external IR specialists to support in Digital forensics investigations and IR team, Threat hunting using Microsoft Sentinel to proactively identify threats in the environment.
  • Gather cyber threat insights on security incidents through governance reporting covering weekly operational reports, monthly tactical reports and quarterly management reports.
  • Review use-cases onboarding and continuous optimizations to comprehensively detect threats for all subsidiaries environments.
  • Works smooth with SOC operation outsources team under the SCBX Cyber Defense Operating Model.

  • Support in helping subsidiaries to containment and resolve security incidents within MTTC SLA.
  • Maintained and updated security incident response playbooks and runbooks with all subsidiary’s acknowledgement.
  • Develop, design and participate in cyber tabletop exercises.

Requirements with these requirements, but not limited to:


To be successful in this role, you should have experience in most of the following:

  • 5-7 years’ experienced in cyber security incident response or SOC environments. If you worked in Financial industry will be plus score.

  • Strong knowledge of cyber security principles and practices, including vulnerability assessment, incident response, and SOC architecture. If you have Cyber/IR certificates related will be plus score.

  • Strong knowledge and skills of security threats, attack countermeasures and threat detection/prevention/mitigation.
  • Working experience in SOC (Security Operations Center) with hands-on experience with Automated Analytic Rules and Automation Playbook on MS Sentinel.

  • Experience with a variety of cyber security tools such as SIEM, EDR, Firewall, IPS, etc and SOC technologies. Excellent analytical and problem-solving skills.
  • Hands-on experience in provisioning and interpreting log and network packet data, cloud environment.
  • Ability to work independently and as part of a team.
  • Ability to communicate complex technical concepts to both technical and non-technical audiences in both of Thai and English.

  • Experienced in multi-vendor management.


Join our team and contribute to ensuring the best availability and efficiency of our Cyber Defense strategy and Cyber Defense Operating Model.


Apply today to play a crucial role in safeguarding our organization's security.

āļ›āļĢāļ°āļŠāļšāļāļēāļĢāļ“āđŒāļ—āļĩāđˆāļˆāļģāđ€āļ›āđ‡āļ™
  • āđ„āļĄāđˆāļĢāļ°āļšāļļāļ›āļĢāļ°āļŠāļšāļāļēāļĢāļ“āđŒāļ‚āļąāđ‰āļ™āļ•āđˆāļģ
āđ€āļ‡āļīāļ™āđ€āļ”āļ·āļ­āļ™
  • āļŠāļēāļĄāļēāļĢāļ–āļ•āđˆāļ­āļĢāļ­āļ‡āđ„āļ”āđ‰
āļŠāļēāļĒāļ‡āļēāļ™
  • āļ„āļ§āļēāļĄāļ›āļĨāļ­āļ”āļ āļąāļĒ
āļ›āļĢāļ°āđ€āļ āļ—āļ‡āļēāļ™
  • āļ‡āļēāļ™āļ›āļĢāļ°āļˆāļģ

āđ€āļāļĩāđˆāļĒāļ§āļāļąāļšāļšāļĢāļīāļĐāļąāļ—

āļˆāļģāļ™āļ§āļ™āļžāļ™āļąāļāļ‡āļēāļ™:100-500 āļ„āļ™
āļ›āļĢāļ°āđ€āļ āļ—āļšāļĢāļīāļĐāļąāļ—:āļāļēāļĢāđ€āļ‡āļīāļ™āđāļĨāļ°āļāļēāļĢāļ˜āļ™āļēāļ„āļēāļĢ
āļ—āļĩāđˆāļ•āļąāđ‰āļ‡āļšāļĢāļīāļĐāļąāļ—:āļāļĢāļļāļ‡āđ€āļ—āļž
āđ€āļ§āđ‡āļšāđ„āļ‹āļ•āđŒ:www.scbx.com
āļāđˆāļ­āļ•āļąāđ‰āļ‡āđ€āļĄāļ·āđˆāļ­āļ›āļĩ:1906

SCBX āđ€āļ›āđ‡āļ™āļĒāļēāļ™āđāļĄāđˆāļ‚āļ­āļ‡āļāļĨāļļāđˆāļĄāļ˜āļļāļĢāļāļīāļˆāđ€āļ—āļ„āđ‚āļ™āđ‚āļĨāļĒāļĩāļ—āļēāļ‡āļāļēāļĢāđ€āļ‡āļīāļ™ āđ‚āļ”āļĒāļĄāļĩ āļ˜āļ™āļēāļ„āļēāļĢāđ„āļ—āļĒāļžāļēāļ“āļīāļŠāļĒāđŒ āļšāļĢāļīāļĐāļąāļ— āđ€āļ­āļŠāļ‹āļĩāļšāļĩ āđ€āļ—āđ‡āļ™āđ€āļ­āļāļ‹āđŒ āļˆāļģāļāļąāļ” āļšāļĢāļīāļĐāļąāļ— āļ„āļēāļĢāđŒāļ” āđ€āļ­āļāļ‹āđŒ āļˆāļģāļāļąāļ” āļšāļĢāļīāļĐāļąāļ—āļŦāļĨāļąāļāļ—āļĢāļąāļžāļĒāđŒ āļ­āļīāļ™āđ‚āļ™āđ€āļ§āļŠāļ—āđŒ āđ€āļ­āļāļ‹āđŒ āļˆāļģāļāļąāļ”āļšāļĢāļīāļĐāļąāļ— āđ€āļžāļ­āļĢāđŒāđ€āļžāļīāļĨ āđ€āļ§āļ™āđ€āļˆāļ­āļĢāđŒāļŠ āļˆāļģāļāļąāļ” āđāļĨāļ°āļšāļĢāļīāļĐāļąāļ—āļ­āļ·āđˆāļ™āđ† āļĄāļĩāļĒāļļāļ—āļ˜āļĻāļēāļŠāļ•āļĢāđŒāļĄāļļāđˆāļ‡āļŠāļđāđˆāļāļēāļĢāđ€āļ›āđ‡āļ™āļāļĨāļļāđˆāļĄāļšāļĢāļīāļĐāļąāļ—āđ€āļ—āļ„āđ‚āļ™āđ‚āļĨāļĒāļĩāļ—āļēāļ‡āļāļēāļĢāđ€āļ‡āļīāļ™āļĢāļ°āļ”āļąāļšāļ āļđāļĄāļī ...

āļ­āđˆāļēāļ™āļ•āđˆāļ­

āļĢāđˆāļ§āļĄāļ‡āļēāļ™āļāļąāļšāđ€āļĢāļē:

āļ—āļĩāđˆ SCB X āļ„āļļāļ“āļˆāļ°āđ„āļ”āđ‰āđ€āļ›āđ‡āļ™āļŠāđˆāļ§āļ™āļŦāļ™āļķāđˆāļ‡āļ‚āļ­āļ‡āļ­āļ‡āļ„āđŒāļāļĢāļ—āļĩāđˆāļāđ‰āļēāļ§āļĨāđ‰āļģāļŠāļđāđˆāļ­āļ™āļēāļ„āļ• āļžāļĢāđ‰āļ­āļĄāļžāļĨāļīāļāđ‚āļ‰āļĄāļ§āļ‡āļāļēāļĢāļāļēāļĢāđ€āļ‡āļīāļ™āđāļšāļšāļ”āļąāđ‰āļ‡āđ€āļ”āļīāļĄāļœāđˆāļēāļ™āļ™āļ§āļąāļ•āļāļĢāļĢāļĄāđāļĨāļ°āđ€āļ—āļ„āđ‚āļ™āđ‚āļĨāļĒāļĩ āđ€āļĢāļēāļĄāļĩāļŠāļ āļēāļžāđāļ§āļ”āļĨāđ‰āļ­āļĄāļāļēāļĢāļ—āļģāļ‡āļēāļ™āļ—āļĩāđˆāļ—āđ‰āļēāļ—āļēāļĒāđāļĨāļ°āđ€āļ›āļīāļ”āļāļ§āđ‰āļēāļ‡āļŠāļģāļŦāļĢāļąāļšāđ„āļ­āđ€āļ”āļĩāļĒāđƒāļŦāļĄāđˆ āđ† āđāļĨāļ°āđƒāļŦāđ‰āđ‚āļ­āļāļēāļŠāļ„āļļāļ“āđ„āļ”āđ‰āļ—āļģāļ‡āļēāļ™āļĢāđˆāļ§āļĄāļāļąāļšāļ—āļĩāļĄāļ—āļĩāđˆāļĄāļĩāļ„āļ§āļēāļĄāđ€āļŠāļĩāđˆāļĒāļ§āļŠāļēāļāļŦāļĨāļēāļāļŦāļĨāļēāļĒ

āđ€āļĢāļēāļŠāđˆāļ‡āđ€āļŠāļĢāļīāļĄāļ§āļąāļ’āļ™āļ˜āļĢāļĢāļĄāļ­āļ‡āļ„āđŒāļāļĢāļ—āļĩāđˆāđƒāļŦāđ‰āļ„ ...

āļ­āđˆāļēāļ™āļ•āđˆāļ­

āļŠāļģāļ™āļąāļāļ‡āļēāļ™āđƒāļŦāļāđˆ: 9 āļ–āļ™āļ™āļĢāļąāļŠāļ”āļēāļ āļīāđ€āļĐāļ āđ€āļ‚āļ•āļˆāļ•āļļāļˆāļąāļāļĢ āļāļĢāļļāļ‡āđ€āļ—āļžāļŊ 10900
Display map
āļ—āļĩāđˆ WorkVenture āđ€āļĢāļēāđƒāļŦāđ‰āļĄāļđāļĨāđ€āļŠāļīāļ‡āđ€āļāļĩāđˆāļĒāļ§āļāļąāļšāļšāļĢāļīāļĐāļąāļ— SCB X PCL āđ‚āļ”āļĒāļĄāļĩāļ‚āđ‰āļ­āļĄāļđāļĨāļ—āļĩāđˆāđ€āļāļĩāđˆāļĒāļ§āļ‚āđ‰āļ­āļ‡ āļ•āļąāđ‰āļ‡āđāļ•āđˆāļ āļēāļžāļšāļĢāļĢāļĒāļēāļāļēāļĻāļāļēāļĢāļ—āļģāļ‡āļēāļ™ āļĢāļđāļ›āļ–āđˆāļēāļĒāļ‚āļ­āļ‡āļ—āļĩāļĄāļ‡āļēāļ™ āđ„āļ›āļˆāļ™āļ–āļķāļ‡āļĢāļĩāļ§āļīāļ§āđ€āļŠāļīāļ‡āļĨāļķāļāļ‚āļ­āļ‡āļāļēāļĢāļ—āļģāļ‡āļēāļ™āļ—āļĩāđˆāļ™āļąāđˆāļ™ āļ‹āļķāđˆāļ‡āļ‚āđ‰āļ­āļĄāļđāļĨāļ—āļļāļāļ­āļĒāđˆāļēāļ‡āļšāļ™āļŦāļ™āđ‰āļēāļ‚āļ­āļ‡āļšāļĢāļīāļĐāļąāļ— SCB X PCL āļĄāļĩāļžāļ™āļąāļāļ‡āļēāļ™āļ—āļĩāđˆāļāļģāļĨāļąāļ‡āļ—āļģāļ‡āļēāļ™āļ—āļĩāđˆāļšāļĢāļīāļĐāļąāļ— SCB X PCL āļŦāļĢāļ·āļ­āđ€āļ„āļĒāļ—āļģāļ‡āļēāļ™āļ—āļĩāđˆāļ™āļąāđˆāļ™āļˆāļĢāļīāļ‡āđ† āđ€āļ›āđ‡āļ™āļ„āļ™āđƒāļŦāđ‰āļ‚āđ‰āļ­āļĄāļđāļĨāļˆāļĢāļīāļ‡āļŠāļĄāļąāļ„āļĢāļ‡āļēāļ™ āļ­āļīāļ™āđ€āļ”āđ‡āļāļ‹āđŒ āļ„āļĢāļĩāđ€āļ­āļ—āļĩāļŸ āļ§āļīāļĨāđ€āļĨāļˆ āļˆāļģāļāļąāļ” āļĄāļŦāļēāļŠāļ™āļŠāļĄāļąāļ„āļĢāļ‡āļēāļ™ āļŠāļģāļ™āļąāļāļ‡āļēāļ™āļŠāđˆāļ‡āđ€āļŠāļĢāļīāļĄāļ­āļļāļ•āļŠāļēāļŦāļāļĢāļĢāļĄāļ‹āļ­āļŸāļ•āđŒāđāļ§āļĢāđŒāđāļŦāđˆāļ‡āļŠāļēāļ•āļī āļ­āļ‡āļ„āđŒāļāļēāļĢāļĄāļŦāļēāļŠāļ™āļŠāļĄāļąāļ„āļĢāļ‡āļēāļ™ āđ‚āļŪāļĄāđ‚āļ›āļĢāļŠāļĄāļąāļ„āļĢāļ‡āļēāļ™ āđāļ­āļ„āļĄāļĩāđˆ āļāļēāļĢāđŒāđ€āļĄāļ™āļ—āđŒ