Expoint – all jobs in one place
The point where experts and best companies meet

Cybersecurity Incident Senior Analyst jobs at Cisco in China, Shanghai

Discover your perfect match with Expoint. Search for job opportunities as a Cybersecurity Incident Senior Analyst in China, Shanghai and join the network of leading companies in the high tech industry, like Cisco. Sign up now and find your dream job with Expoint
Company (1)
Job type
Job categories
Job title (1)
China
Shanghai
10 jobs found
30.06.2025
C

Cisco Senior Threat Hunting Analyst China, Shanghai

Limitless High-tech career opportunities - Expoint
Network, Systems (Windows or Unix) or Cloud administration (AWS/GCP/Azure). Enterprise Identity Management. Web Application Development. Security Operations Center incident handling/management/coordination. SIEM technologies ideally Splunk. Detection Engineering Pipeline (and the development...
Description:

CSIRT prefers a college graduate with IT technical experience in one or more of the following fields:

  • Network, Systems (Windows or Unix) or Cloud administration (AWS/GCP/Azure)
  • Enterprise Identity Management
  • Web Application Development
  • Security Operations Center incident handling/management/coordination
  • SIEM technologies ideally Splunk
  • Detection Engineering Pipeline (and the development of detection rules)
  • Data Engineering Pipeline (and the onboarding of data for use for detections)
  • Strong understanding of incident response, malicious code/exploits, anti-virus, etc.
  • Understanding of computer forensics
  • Automation Scripting (Python)
  • Threat Intelligence
  • Attack Surface Risk Management

QUALIFICATIONS

The successful candidate should have the following qualifications:

  • Worked in a high pressure Global SOC environment handling incidents
  • Familiar with Windows exploits, malware and malicious code trends
  • Willing to work off-hours including rotational on-call shifts
  • Demonstrate interest and knowledge of security trends and latest attacker activity
  • Hands on experience with one or more areas of the following areas:
    • IT Infrastructure services (DNS, Web Servers, Email, etc…)
    • Networking
    • Identity (Active Directory, Okta, Duo, Ping, Azure AD)
    • Cloud Administration (AWS, Azure, Azure)
    • Systems Administration (Linux, Windows)
  • Familiar with Modern Cloud Applications and technology.
  • Experience with SIEM tools e.g. Splunk and ideally Splunk Enterprise Security.
  • Experienced ability to create SIEM Detection Rules based on latest Threats.
  • Demonstrate good customer service, communications, and troubleshooting skills.


Degree in IT / CS / MIS / Information Security or equivalent operational experience. Post graduate degrees a plus.

RESPONSIBILITIES

The core responsibilities of the CSIRT analyst are:

?Monitor and Respond to Security Alerts:

  • Continuously monitor security alerts and incidents using Splunk and other security tools.
  • Perform thorough analysis and investigation of security incidents to determine their scope and impact.
  • Coordinate with other IT and security teams to remediate incidents effectively.

?Develop and Implement Detection Strategies:

  • Create and fine-tune Splunk detections to identify potential security threats and anomalies.
  • Develop and maintain custom detection rules, alerts, and dashboards in Splunk.
  • Ensure detections are comprehensive, accurate, and provide actionable intelligence.

?Stay Ahead of Emerging Threats:

  • Keep up-to-date with the latest cyber threats, attack vectors, and security trends.
  • Develop and implement new detection techniques to address emerging threats.
  • Conduct regular threat hunting activities to proactively identify potential vulnerabilities.

?Technical Skills and Expertise:

  • Utilize your broad technology skill set to address security challenges across various platforms, including modern cloud environments (e.g., AWS, Azure, Google Cloud).
  • Apply your development skills to create automation scripts and tools to enhance SOC operations.
  • Collaborate with IT and DevOps teams to ensure security is integrated into the development lifecycle.

In addition, the CSIRT Analyst will be accountable for the following:

  • Escalate to CSIRT investigators and external support teams to assist in analysis and event resolution.
  • Document cases, procedures, analysis, and investigations accurately and thoroughly (including best-practice documentation).
  • Inform higher-level priorities, improvements and problem resolutions to improve effectiveness of Cisco CSIRT & InfoSec.
  • Constructively challenge and improve existing tools, processes and procedures.
  • Assist CSIRT with continued enhancement of Cisco's security tools.
  • Develop and execute security controls, defences and countermeasures to intercept and prevent internal or external attacks or attempts to infiltrate company email, data, e-commerce and web-based systems.
  • Conduct vulnerability assessments of applications, operating systems and/or networks.
  • Respond to cybersecurity breaches, identify intrusions and isolate, block and remove unauthorized access.
  • Research and evaluate cybersecurity threats and perform root cause analysis.
  • Assist in the creation and implementation of security solutions.
  • Learn quickly on the job as CSIRT tackles security solutions for various environments & technologies, including cloud technologies, that may be new to you and others on the team
  • Provide information to management regarding impact on the business caused by theft, destruction, alteration or denial of access to information and systems.

Show more
21.06.2025
C

Cisco Cybersecurity Incident Senior Analyst China, Shanghai

Limitless High-tech career opportunities - Expoint
Escalate to CSIRT investigators and external support teams to assist in analysis and event resolution. Document cases, procedures, analysis, and investigations accurately and thoroughly (including best-practice documentation). Inform higher-level priorities,...
Description:

RESPONSIBILITIES

Assist with setup and tune multiple security monitoring products and data feeds.

Assist in development of documented process for incident and alert handling

• Escalate to CSIRT investigators and external support teams to assist in analysis and event resolution.

• Document cases, procedures, analysis, and investigations accurately and thoroughly (including best-practice documentation).

• Inform higher-level priorities, improvements and problem resolutions to improve effectiveness of CSCO, CSIRT, InfoSec, and CSPO.

• Constructively challenge and improve existing tools, processes and procedures.

• Assist CSIRT with testing, deployment and continued enhancement of Cisco's security tools.

• Provide information security awareness training to new hires.

• Watch and identify the emerging threats globally. Tune the configuration of monitoring products to catch the possible attack to Cisco.

EXPERIENCE/ SKILLS REQUIRED

The right candidate will have about 8 to 10 years relevant experience in one or more of the following fields:

Network administration, TCP/IP knowledge and application in securing systems, investigating security incidents.

Experience on Cloud platform (AWS)

Demonstrate clear experience with UNIX/Windows operating systems

IT security with a focus on computer incident response, malicious code/exploits, anti-virus, etc.

Knowledge of SIEM tools (preferably Splunk)

Scripting skills (BASH, Python, PERL)

Familiar with Windows exploits, malware and malicious code trends

Demonstrate interest and knowledge in learning of security trends and malware analysis.

Fluent in English. Good communication and presentation skills. (China)

Degree in BS or equivalent. MS is a plus

CCNA, RHCE, MCSE, CISSP (will be a plus)

Show more

These jobs might be a good fit

11.06.2025
C

Cisco Senior Hardware Engineer China, Shanghai

29.04.2025
C

Cisco Senior Signal Integrity Engineer China, Shanghai

28.04.2025
C

Cisco Cybersecurity Incident Manager China, Shanghai

Limitless High-tech career opportunities - Expoint
Incident Response Leadership. Lead all phases of incident response, including detection, analysis, containment, eradication, recovery and communication. Act as the primary decision-maker during cybersecurity incidents, coordinating efforts across technical and...
Description:

Key Responsibilities:

  1. Incident Response Leadership
    • Lead all phases of incident response, including detection, analysis, containment, eradication, recovery and communication.
    • Act as the primary decision-maker during cybersecurity incidents, coordinating efforts across technical and business teams.
    • Ensure adherence to the organization's incident response framework and regulatory requirements.
  1. Strategic Communication
    • Serve as the main point of contact for incident updates to executive leadership and stakeholders.
    • Provide detailed, actionable reports during and after incidents, including root cause analysis and mitigation strategies.
  1. Collaboration and Coordination
    • Collaborate with Corporate CSIRT, Incident Command, Cyber legal, IT, risk management, Data Protection and other departments to ensure a unified response.
    • Engage with third-party vendors, Managed Security Service Providers (MSSPs), and law enforcement when necessary.
  1. Preparation and Readiness
    • Develop, maintain, and test incident response plans, playbooks, and escalation procedures.
    • Conduct regular tabletop exercises and simulations to train and prepare teams.
  1. Post-Incident Activities
    • Oversee the generation of post-incident reports and ensure lessons learned are incorporated into future planning.
    • Recommend security enhancements to prevent recurrence of incidents.
  1. Compliance and Reporting
    • Ensure compliance with industry regulations and organizational policies during incident response.
    • Stay updated on emerging threats and trends in cybersecurity to improve response capabilities.

Minimum Qualifications:

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related field.
  • At least 8+ years of experience in cybersecurity
  • Demonstrated experience managing large-scale cybersecurity incidents.
  • Strong understanding of regulatory requirements and industry standards (e.g., CSL, DSL, PIPL, GDPR, HIPAA, PCI-DSS).
  • Excellent written and verbal communication abilities in Chinese and English.

Preferred qualifications:

  • 3+ years in an incident response or leadership role.
  • Certifications such as CISSP, CISM, GIAC Certified Incident Handler (GCIH), or Certified Information Systems Auditor (CISA) preferred.
  • Exceptional leadership and decision-making under pressure.
  • Strong analytical and problem-solving skills.
  • Collaborative mindset with an ability to manage cross-functional teams.
  • Ability to coordinate 24 x 7 cross geographic incidents.

Work Environment:

  • Hybrid work environment with on-site presence required as needed.
  • On-call availability to respond to critical incidents.

But “Digital Transformation” is an empty buzz phrase without a culture that allows for innovation, creativity, and yes, even failure (if you learn from it.)

Show more

These jobs might be a good fit

20.04.2025
C

Cisco Threat Hunting Analyst China, Shanghai

Limitless High-tech career opportunities - Expoint
Network, Systems (Windows or Unix) or Cloud administration (AWS/GCP/Azure). Enterprise Identity Management. Web Application Development. Security Operations Center incident handling/management/coordination. SIEM technologies ideally Splunk. Detection Engineering Pipeline (and the development...
Description:

Threat Hunting Analyst:

CSIRT prefers a college graduate with IT technical experience in one or more of the following fields:

  • Network, Systems (Windows or Unix) or Cloud administration (AWS/GCP/Azure)
  • Enterprise Identity Management
  • Web Application Development
  • Security Operations Center incident handling/management/coordination
  • SIEM technologies ideally Splunk
  • Detection Engineering Pipeline (and the development of detection rules)
  • Data Engineering Pipeline (and the onboarding of data for use for detections)
  • Strong understanding of incident response, malicious code/exploits, anti-virus, etc.
  • Understanding of computer forensics
  • Automation Scripting (Python)
  • Threat Intelligence
  • Attack Surface Risk Management

QUALIFICATIONS

The successful candidate should have the following qualifications:

  • Worked in a high pressure Global SOC environment handling incidents
  • Familiar with Windows exploits, malware and malicious code trends
  • Willing to work off-hours including rotational on-call shifts
  • Demonstrate interest and knowledge of security trends and latest attacker activity
  • Hands on experience with one or more areas of the following areas:
    • IT Infrastructure services (DNS, Web Servers, Email, etc…)
    • Networking
    • Identity (Active Directory, Okta, Duo, Ping, Azure AD)
    • Cloud Administration (AWS, Azure, Azure)
    • Systems Administration (Linux, Windows)
  • Familiar with Modern Cloud Applications and technology.
  • Experience with SIEM tools e.g. Splunk and ideally Splunk Enterprise Security.
  • Experienced ability to create SIEM Detection Rules based on latest Threats.
  • Demonstrate good customer service, communications, and troubleshooting skills.


Degree in IT / CS / MIS / Information Security or equivalent operational experience. Post graduate degrees a plus.

RESPONSIBILITIES

The core responsibilities of the CSIRT analyst are:

Monitor and Respond to Security Alerts:

  • Continuously monitor security alerts and incidents using Splunk and other security tools.
  • Perform thorough analysis and investigation of security incidents to determine their scope and impact.
  • Coordinate with other IT and security teams to remediate incidents effectively.


Develop and Implement Detection Strategies:

  • Create and fine-tune Splunk detections to identify potential security threats and anomalies.
  • Develop and maintain custom detection rules, alerts, and dashboards in Splunk.
  • Ensure detections are comprehensive, accurate, and provide actionable intelligence.


Stay Ahead of Emerging Threats:

  • Keep up-to-date with the latest cyber threats, attack vectors, and security trends.
  • Develop and implement new detection techniques to address emerging threats.
  • Conduct regular threat hunting activities to proactively identify potential vulnerabilities.

Technical Skills and Expertise:

  • Utilize your broad technology skill set to address security challenges across various platforms, including modern cloud environments (e.g., AWS, Azure, Google Cloud).
  • Apply your development skills to create automation scripts and tools to enhance SOC operations.
  • Collaborate with IT and DevOps teams to ensure security is integrated into the development lifecycle.

In addition, the CSIRT Analyst will be accountable for the following:

  • Escalate to CSIRT investigators and external support teams to assist in analysis and event resolution.
  • Document cases, procedures, analysis, and investigations accurately and thoroughly (including best-practice documentation).
  • Inform higher-level priorities, improvements and problem resolutions to improve effectiveness of Cisco CSIRT & InfoSec.
  • Constructively challenge and improve existing tools, processes and procedures.
  • Assist CSIRT with continued enhancement of Cisco's security tools.
  • Develop and execute security controls, defences and countermeasures to intercept and prevent internal or external attacks or attempts to infiltrate company email, data, e-commerce and web-based systems.
  • Conduct vulnerability assessments of applications, operating systems and/or networks.
  • Respond to cybersecurity breaches, identify intrusions and isolate, block and remove unauthorized access.
  • Research and evaluate cybersecurity threats and perform root cause analysis.
  • Assist in the creation and implementation of security solutions.
  • Learn quickly on the job as CSIRT tackles security solutions for various environments & technologies, including cloud technologies, that may be new to you and others on the team
  • Provide information to management regarding impact on the business caused by theft, destruction, alteration or denial of access to information and systems.
Show more

These jobs might be a good fit

20.04.2025
C

Cisco Senior Thermal engineer China, Shanghai

Limitless High-tech career opportunities - Expoint
ob responsibilities includeworking out thermal solution for new product, using Flotherm to do thermal simulation, developing thermal test plan and completing thermal test.ssential dutiesWork with HW/Mechanical engineer to do the...
Description:

Job description

ob responsibilities includeworking out thermal solution for new product, using Flotherm to do thermal simulation, developing thermal test plan and completing thermal test.


ssential duties

Work with HW/Mechanical engineer to do the concept design for new product.

Use thermal & Fluid simulation tools such as Flotherm to do thermal simulation.

Cooperate with HW/ECAD/Mechanical engineer to optimize the board placement.

Search and choose cost-effective fan and thermal interface material.

Work with Mechanical/MPE to review the detailed manufacture process of heatsink.

Create thermal test and acoustic test plan, complete these tests according to schedule.

Solve thermal issue during NPI phase and sustaining phase.

Study advanced thermal solutions such as 3D vapor chamber heatsink, liquid cooling, etc, and apply them into new product which need it.

Technical skills

Rich experience on Flotherm software.

Familiar with product development process in network equipment industry.

Rich knowledge on the optical module thermal solution, high power density ASICsolution, fan speed control, acoustic test, wind tunnel test and thermal test.

Familiar with vapor chamber heatsink,heat pipe, thermo-siphon’s manufacture process.

knowledge about advanced thermal solution such asliquid cooling solution.

Familiar with PCB placement design and review process.

Familiar with Microsoft office software.

Ability to communicate in English

+ years experience innetwork equipment industry or other IT industry.

Show more

These jobs might be a good fit

Limitless High-tech career opportunities - Expoint
Network, Systems (Windows or Unix) or Cloud administration (AWS/GCP/Azure). Enterprise Identity Management. Web Application Development. Security Operations Center incident handling/management/coordination. SIEM technologies ideally Splunk. Detection Engineering Pipeline (and the development...
Description:

CSIRT prefers a college graduate with IT technical experience in one or more of the following fields:

  • Network, Systems (Windows or Unix) or Cloud administration (AWS/GCP/Azure)
  • Enterprise Identity Management
  • Web Application Development
  • Security Operations Center incident handling/management/coordination
  • SIEM technologies ideally Splunk
  • Detection Engineering Pipeline (and the development of detection rules)
  • Data Engineering Pipeline (and the onboarding of data for use for detections)
  • Strong understanding of incident response, malicious code/exploits, anti-virus, etc.
  • Understanding of computer forensics
  • Automation Scripting (Python)
  • Threat Intelligence
  • Attack Surface Risk Management

QUALIFICATIONS

The successful candidate should have the following qualifications:

  • Worked in a high pressure Global SOC environment handling incidents
  • Familiar with Windows exploits, malware and malicious code trends
  • Willing to work off-hours including rotational on-call shifts
  • Demonstrate interest and knowledge of security trends and latest attacker activity
  • Hands on experience with one or more areas of the following areas:
    • IT Infrastructure services (DNS, Web Servers, Email, etc…)
    • Networking
    • Identity (Active Directory, Okta, Duo, Ping, Azure AD)
    • Cloud Administration (AWS, Azure, Azure)
    • Systems Administration (Linux, Windows)
  • Familiar with Modern Cloud Applications and technology.
  • Experience with SIEM tools e.g. Splunk and ideally Splunk Enterprise Security.
  • Experienced ability to create SIEM Detection Rules based on latest Threats.
  • Demonstrate good customer service, communications, and troubleshooting skills.


Degree in IT / CS / MIS / Information Security or equivalent operational experience. Post graduate degrees a plus.

RESPONSIBILITIES

The core responsibilities of the CSIRT analyst are:

?Monitor and Respond to Security Alerts:

  • Continuously monitor security alerts and incidents using Splunk and other security tools.
  • Perform thorough analysis and investigation of security incidents to determine their scope and impact.
  • Coordinate with other IT and security teams to remediate incidents effectively.

?Develop and Implement Detection Strategies:

  • Create and fine-tune Splunk detections to identify potential security threats and anomalies.
  • Develop and maintain custom detection rules, alerts, and dashboards in Splunk.
  • Ensure detections are comprehensive, accurate, and provide actionable intelligence.

?Stay Ahead of Emerging Threats:

  • Keep up-to-date with the latest cyber threats, attack vectors, and security trends.
  • Develop and implement new detection techniques to address emerging threats.
  • Conduct regular threat hunting activities to proactively identify potential vulnerabilities.

?Technical Skills and Expertise:

  • Utilize your broad technology skill set to address security challenges across various platforms, including modern cloud environments (e.g., AWS, Azure, Google Cloud).
  • Apply your development skills to create automation scripts and tools to enhance SOC operations.
  • Collaborate with IT and DevOps teams to ensure security is integrated into the development lifecycle.

In addition, the CSIRT Analyst will be accountable for the following:

  • Escalate to CSIRT investigators and external support teams to assist in analysis and event resolution.
  • Document cases, procedures, analysis, and investigations accurately and thoroughly (including best-practice documentation).
  • Inform higher-level priorities, improvements and problem resolutions to improve effectiveness of Cisco CSIRT & InfoSec.
  • Constructively challenge and improve existing tools, processes and procedures.
  • Assist CSIRT with continued enhancement of Cisco's security tools.
  • Develop and execute security controls, defences and countermeasures to intercept and prevent internal or external attacks or attempts to infiltrate company email, data, e-commerce and web-based systems.
  • Conduct vulnerability assessments of applications, operating systems and/or networks.
  • Respond to cybersecurity breaches, identify intrusions and isolate, block and remove unauthorized access.
  • Research and evaluate cybersecurity threats and perform root cause analysis.
  • Assist in the creation and implementation of security solutions.
  • Learn quickly on the job as CSIRT tackles security solutions for various environments & technologies, including cloud technologies, that may be new to you and others on the team
  • Provide information to management regarding impact on the business caused by theft, destruction, alteration or denial of access to information and systems.

Show more
Find your dream job in the high tech industry with Expoint. With our platform you can easily search for Cybersecurity Incident Senior Analyst opportunities at Cisco in China, Shanghai. Whether you're seeking a new challenge or looking to work with a specific organization in a specific role, Expoint makes it easy to find your perfect job match. Connect with top companies in your desired area and advance your career in the high tech field. Sign up today and take the next step in your career journey with Expoint.