THEOS Cyber logoT

DFIR Specialist / Senior SOC Analyst (Hong Kong)

THEOS Cyber

Remote · Hong KongFull Time
Apply with OnJob Free profile · takes about a minute

DFIR Specialist / Senior SOC Analyst (Hong Kong) at THEOS Cyber is a full time role based in Remote · Hong Kong (remote). It was published on 3 September 2026 and was open at last check.

DFIR Specialist / Senior SOC Analyst (Hong Kong) at THEOS Cyber — key details
RoleDFIR Specialist / Senior SOC Analyst (Hong Kong)
CompanyTHEOS Cyber
LocationRemote · Hong Kong (remote)
Employment typeFull Time
Published3 September 2026
StatusOpen at last check

DFIR Specialist / Senior SOC Analyst

Manila | Kuala Lumpur | Hong Kong | Singapore | APAC Remote

Our Mission

Our mission is to empower businesses to thrive in the digital security age by defining and executing practical strategies that build true cyber resilience. At Theos, security is not an afterthought. It is our foundation. We believe in disciplined execution over silver bullets, and real outcomes over noise.

Who We Are

Theos is a cybersecurity company delivering premium services across Asia and beyond. We support SMEs and enterprises with capabilities traditionally reserved for global Tier-1 firms, spanning Penetration Testing, Red Teaming, Managed Detection and Response, and Digital Forensics and Incident Response. We combine deep technical capability with commercial discipline and operational maturity.

Our culture is grounded in five core values: Security as Our Foundation; Global Collaboration and Respect; Embrace Change and Innovate; Integrity and Accountability; and Strive for Excellence.

As we grow, we are building a culture that moves from heroics to process, from reaction to discipline, and from surviving to thriving. We value ownership, clarity, execution, and people who continuously raise the standard for themselves, their teams, and our clients.

Job Summary

As a DFIR Specialist / Senior SOC Analyst at Theos, you will lead client-facing engagements across the full incident response lifecycle. You will work closely with diverse customers and senior stakeholders to deliver critical outcomes and guide organisations through complex investigations.

Your role will be central to managing engagements, containing security incidents with precision, and providing clear, actionable remediation plans that strengthen client resilience and enhance overall security posture.

Key Responsibilities

  • Lead end-to-end incident response engagements, guiding clients through investigation, containment, and long-term remediation across business email compromise (BEC), ransomware, data breaches, insider threats, and compromise assessment cases.
  • Conduct forensic analysis across cloud, Windows, Linux, and macOS environments, including network traffic and log data from web application firewalls, firewalls, endpoints, cloud platforms, and applications.
  • Use tools such as CrowdStrike, FTK, next-generation SIEM platforms, and Magnet AXIOM to identify indicators of compromise (IOCs), threat-actor tactics, techniques, and procedures (TTPs), root cause, and scope of impact.
  • Collaborate with clients and internal stakeholders to communicate findings, provide timely updates, and deliver comprehensive reports.
  • Mentor junior staff and share expertise in incident response and digital forensics best practices.
  • Maintain awareness of the evolving threat landscape, including emerging AI- and large language model-related threats.
  • Improve playbooks, methodologies, and tooling, including artefact collectors and parsers, and feed lessons from live engagements back into processes and automation.
  • Travel as required, approximately 5%, to support client and business needs through on-site engagements.

Qualifications

- Required Qualifications

  • Bachelor's degree in Information Security, Computer Science, Digital Forensics, Cybersecurity, or a related discipline, or equivalent professional experience.
  • Experience administering, monitoring, or investigating cloud platforms such as Microsoft Azure, AWS, Google Workspace, or Alibaba Cloud.
  • Minimum of four years of direct experience in cybersecurity operations.
  • Strong proficiency in rapid incident response, creative problem-solving, and report writing.
  • An investigative mindset, with an interest in solving complex problems, learning new techniques, and continuously improving.

- Preferred Qualifications

  • Prior experience in a client-facing incident response consulting role.
  • Direct experience in incident response and/or digital forensics, with practical experience using forensic and incident response tools.
  • Prior experience developing and delivering tabletop exercises.
  • Strong executive presence, with the ability to present complex technical findings to C-level stakeholders.
  • Proven ability to build collaborative relationships with internal teams, external partners, and clients.

About Your Application

We aim to provide a clear and efficient hiring process. To support your application, please include your expected annual compensation in your local currency and your availability or notice period. Work authorisation requirements may vary by location and will be discussed as part of the process.

Originally posted on Himalayas

Share:WhatsAppLinkedIn

Create your free OnJob profile to apply — we'll take you to THEOS Cyber's application after sign-up. · Posted 3 Sept 2026.

DFIR Specialist / Senior SOC Analyst (Hong Kong) at THEOS Cyber — questions answered

What does the DFIR Specialist / Senior SOC Analyst (Hong Kong) role at THEOS Cyber pay?

THEOS Cyber does not publish a salary on this DFIR Specialist / Senior SOC Analyst (Hong Kong) listing, so OnJob shows no figure for it rather than an estimate. For what this role pays across the market, the OnJob salary guides aggregate the live listings that do disclose pay.

Is the DFIR Specialist / Senior SOC Analyst (Hong Kong) role at THEOS Cyber remote?

Yes — THEOS Cyber advertises this DFIR Specialist / Senior SOC Analyst (Hong Kong) role as remote, tied to Remote · Hong Kong, and it is listed as full time work. Remote terms come from the employer's own posting, so confirm the expected working hours, timezone and any on-site days with THEOS Cyber before you apply.

Is the DFIR Specialist / Senior SOC Analyst (Hong Kong) role at THEOS Cyber still open?

The DFIR Specialist / Senior SOC Analyst (Hong Kong) posting at THEOS Cyber was open at OnJob's last check of the employer's careers page, having been published on 3 September 2026. OnJob re-checks source listings on each build and marks a role closed once it disappears, but listings can close without notice, so the employer's own page is the final word.

How do you apply for the DFIR Specialist / Senior SOC Analyst (Hong Kong) role at THEOS Cyber?

Apply to the DFIR Specialist / Senior SOC Analyst (Hong Kong) at THEOS Cyber role through OnJob with a free profile: OnJob scores your fit against the listing, shows the skills lowering that score, and submits an ATS-ready profile to THEOS Cyber's own application page. Creating a profile is free and needs no card.

Explore more on OnJob

Hiring for a role like this?

Post a job on OnJob and reach AI-matched candidates.

Post a Job