Cybersecurity Incident Commander - CIRT
Thrive
About Us:
Thrive is a rapidly growing technology solutions provider focusing upon Cloud, Cyber Security, Networking, Disaster Recovery and Managed Services. Our corporate culture, engineering talent, customer-centric approach, and focus upon “next generation” services help us stand out amongst our peers. Thrive is on the look-out for individuals who don’t view their weekdays spent at “a job”, but rather look to develop valuable skills that ignite their passion and lead to a CAREER. If you’re attracted to a “work hard, play hard” environment, seeking the guidance, training and experience necessary to build a lucrative career, then welcome to THRIVE!!
Position Overview:
Thrive is expanding its cybersecurity capabilities and is seeking a highly capable Incident Commander to lead critical security incident operations across our organization. This role is essential for directing and coordinating all activities and resources involved in a security incident , ensuring alignment across internal Thrive teams and with client stakeholders.
The Incident Commander acts as the single point of accountability for the lifecycle of high-severity incidents—driving containment, eradication, recovery, and client communication with authority and clarity. This leader must possess both technical fluency and strong executive presence to guide multi-team efforts under pressure.
Primary Responsibilities:
- Serve as the lead Incident Commander for complex or high-priority cybersecurity incidents, assuming control from initial scoping through post-incident review.
- Act as the central coordination point across all parties engaged in security incidents
- Ensure that all internal actions are synchronized, prioritized, and in alignment with client needs and Thrive’s incident response methodology.
- Set the operational tempo, assign task owners, and communicate timelines, dependencies, and roadblocks in real-time.
- Drive incident lifecycle management with a focus on containment, minimizing business disruption, and maintaining security assurance.
- Maintain clear, structured communication with client stakeholders and Thrive leadership, including updates on threat actor behavior, system impact, business risk, and required decisions.
- Lead conference bridges during incident response, ensuring everyone is aligned and progressing toward resolution.
- Approve restoration plans, re-entry conditions, and sequencing to minimize risk of re-compromise.
- Serve as the public face of Thrive during a cybersecurity crisis, guiding clients with authority and confidence through incident containment and recovery.
- Provide real-time risk assessments and business impact updates to client executive teams, IT leads, and legal stakeholders.
- Assist clients in coordination with cyber insurance or legal counsel when applicable.
- Advocate for long-term maturity improvements post-incident, helping position Thrive as a trusted partner.
- Continually enhance Thrive’s playbooks, escalation frameworks, and IR documentation based on lessons learned from real-world incidents.
- Lead internal after-action reviews and root cause analysis meetings with technical teams and business units.
- Partner with Security Engineering to validate detection coverage and response automation opportunities.
- Conduct tabletop with internal Thrive teams to test and improve readiness for various threat scenarios.
- Promote a strong, communicative culture of shared accountability and post-incident learning across all Thrive teams.
Requirements
Qualifications:
- Proven incident response experience with demonstrated leadership of cross-functional security teams.
- Proven success commanding high-impact cybersecurity incidents in a fast-paced, customer-facing environment.
- Strong understanding of attack lifecycle stages, investigative workflows, and containment best practices.
- Deep knowledge of modern attacker tactics and incident frameworks (MITRE ATT&CK, Cyber Kill Chain, NIST 800-61).
- Excellent communication skills, with experience briefing clients, executives, and cross-disciplinary teams.
- Familiarity with security tools (SIEM, EDR, forensic platforms), system/network architecture, incident response methodologies, and backup and disaster recovery plans.
- Ability to multitask and make decisions quickly under pressure.
Preferred Experience:
- Experience with MSSP coordination, including multi-tenant incident response and customer escalation management.
- Familiarity with tools like SentinelOne, Microsoft 365 Defender, Fortinet, CrowdStrike, and similar platforms.
- Experience integrating legal, compliance, or insurance considerations into incident decision-making.
Preferred Certifications
- GCIH – GIAC Certified Incident Handler
- GCFA – GIAC Certified Forensic Analyst
- GCFE – GIAC Certified Forensic Examiner
- CHFI – Computer Hacking Forensic Investigator
- CISSP , CISM , or other management-level security certifications are a plus
- ...continuously monitor and improve our customers' security posture while preventing, detecting, analyzing, and responding to cybersecurity incidents utilizing technology and well-defined processes and procedures. The ideal candidate will have a passion for information security...
- ...environments. This is an ideal opportunity for someone early in their cybersecurity career who is interested in the engineering side of security... ...-layer protocols Knowledge of cybersecurity threats and incident response concepts Ability to communicate technical...
- ...detail-oriented and proactive individual who is passionate about cybersecurity and dedicated to enhancing client relationships. Primary... ...automated security use cases and playbooks to accelerate incident response and remediation. ~ Assist in overseeing the implementation...
- ...understanding. Stay informed about the latest security threats and remediation techniques to maintain Thrive's leading edge in cybersecurity services. Ensure all remediation efforts align with industry standards and best practices to uphold high security standards....
- ...resolution process. Perform first response and initial triage of customer issues, troubleshooting single-user and system-impacting incidents and accurately documenting all actions in Thrive’s tools. Perform rapid analysis of workstation-level incidents, identifying...
- ...Position Overview System Administrators provide remote support across diverse, multi-tenant environments, handling escalated incidents and complex service requests. The role involves advanced troubleshooting, implementing changes, coordinating with other teams, and...
- ...Ensure network compliance with security policies and best practices Provide technical support and escalation for network-related incidents Requirements ~6+ years of hands-on network engineering experience ~ Strong expertise in Cisco Catalyst and Meraki switching...
- ...Required Deliverables: Ensure all logged incidents are resolved within SLAs. Ensure all internal personnel involved in a service call work efficiently to meet SLAs. Ensure all customer communication within a service call is prompt, professional, and reliable...
- ...developing network standards and processes Deploy and activate network solutions and internet circuits Troubleshoot networking level incidents and provide relevant information to senior engineers when escalation is necessary Demonstrate knowledge of network design and...
- ...Job Functions: ~ Incident Management role is to assist the Technical Service team to oversee all cases that requires Service Partner intervention and to ensure Service Partner resources are always available. Primary Workflow: Oversee incidents requiring Service...
640000 - 910000 Php per year
...optic) Execute hardware deployments and decommissions Monitor environmental systems (power, cooling, security) Respond to incidents and perform troubleshooting Maintain accurate documentation and asset tracking Collaborate with engineering and operations teams...- ...performing security risk assessments, testing or auditing of cybersecurity or information security standards or governance frameworks (e... ...assessment of recovery plans for critical applications and systems, Incident management as well as review against frameworks such as ISO...
- ...procedures and enhance system performance; Follow stringent security and compliance measures to prevent data breaches and cybersecurity incidents; Conduct routine/preventive maintenance, pre-operation inspections, functional testing, and system checks during...
- ...confidentiality. Required Skills & Qualifications Language Proficiency: Fluency in Mandarin (both spoken and written) and a strong command of the target language (often English and/or Filipino). Cultural Understanding: Deep knowledge of Mandarin and its cultural...
- ...management &/or merchandising Excellent leadership, analytical and PR skills Flexible; results-oriented and excellent in customer service With good command of oral and written communication Applicants who worked at Adidas, Nike, Fila, etc. is an advantage...
- ...● Enforce hygiene protocols and sanitation requirements to ensure a safe working environment for all kitchen staff. ● Act as third-in-command in the absence of the Head Chef and Sous Chef, taking responsibility for kitchen operations and decision-making as needed....
- ...Qualifications Fresh graduates are encouraged to apply. Well-versed in editing and content creation platforms. Excellent command of the English language (needed for creating marketing collaterals). Experience in writing creative copy is preferred. Experience...
- ...and telephone systems Ability to learn about products and services and describe/explain them to prospect customers Excellent command of the English language Has strong interpersonal skills Cool-tempered and able to handle rejection Outstanding negotiation...
- ...Building Codes & Standards is favourable. Strong organization and time management skills. Open, supportive, and accessible. Good command of written and spoken English. Qualifications in Hydraulic Engineering preferred. Reliable IT setup and a well-equipped home...
- ...Strong analytical skills and experience in using data to drive decision-making. • Familiarity with IT governance frameworks, cybersecurity practices, and emerging digital technologies. Key Competencies specific to the role: (what traits or capabilities must they...
- ...experience in the accounting industry. Familiarity with accounting software ( Xero, QuickBooks, MYOB ) is highly regarded. Strong command of written and verbal English . Problem-solving skills with a strong customer-first approach . Experience in customer...
- ...platforms, APIs, and workflow tools ~ Experience working with distributed teams or in cross-cultural environments ~ Strong grasp of cybersecurity, system integration, and cloud infrastructure ~ Excellent communication skills and a proactive, solutions-oriented mindset ~...
- ...others; · Working knowledge of Enterprise Resource Programs (ERP); hands on experience of SAP is an advantage; · Good command of the MS Office Suite (MS Excel, MS Word, MS PowerPoint) · Familiarity with operations and set-up of manufacturing entities, either...
- ...ensuring adherence to project timelines. Monitor helpdesk performance and ensure user satisfaction with ICT services. Implement cybersecurity measures and ensure compliance with data protection policies. Maintain system uptime, network reliability, and availability...
- ...Working knowledge of office equipment and computer hardware and peripheral devices Strong understanding of databases Good command of English both oral and written and customer service skills Great attention to detail Non-negotiable skills: Proven 3+ years...
- ...related reports; - Working knowledge of Enterprise Resource Programs (ERP); hands on experience of SAP is an advantage; - Good command of the MS Office suite (MS Excel, MS Word, MS Powerpoint); - Minimum familiarity with operations and set up of manufacturing...
- ...Follows the Rules and Regulations of the Company and the Standard Operating Procedures of Warehouse Division and reports any untoward incidents happened inside the warehouse - Responsible to elevate properly items using elevated pallet or five plastic pallets if elevated...
- ...Conduct regular safety checks and inspections. Maintain cleanliness and organization of the pool area. Complete reports on incidents and behaviors. Provide assistance and guidance to patrons. Educational Qualifications: High/Senior High School diploma required...
- ...regular patrols within and around the premises\ Monitor surveillance cameras and alarm system Write detailed daily reports and incident reports when necessary. Respond promptly to alarms and security incidents. Coordinate with law enforcement , emergency...
- ...decisions as appropriate. Contributes to process improvement efforts. Focusing on Safety ~ Identify and reports hazards and incidents - recognises unsafe working conditions, environments and behaviours that can jeopardise staff safety. Alert relevant support staff...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cybersecurity Incident Commander - CIRT. Be the first to apply!
