Incident Response Security Analyst
- Full-time
- Contract: Fixed Term
- Work flexibility: Office-based
Company Description
Ubisoft is a global leader in gaming with teams across the world creating original and memorable gaming experiences, from Assassin’s Creed, Rainbow Six, to Just Dance and more. We believe diverse perspectives help both players and teams thrive. If you’re passionate about innovation and pushing entertainment boundaries, join our journey and help us create the unknown!
Created in 1996, Ubisoft Shanghai studio, is a vibrant and exciting place where our talents get opportunities to either co-develop great AAA blockbuster games, create cutting-edge online games or produce fun mobile games.
To learn more, please visit: www.ubisoftgroup.com
Job Description
The incumbent works in coordination with all production and services teams, and other security relays to ensure the coherent execution of the Ubisoft security strategy.
Moreover, they provide informational and technical security expertise in order to support, ensure and enhance the current security posture of all assets within Ubisoft.
The candidate will perform incident response activities while challenging current processes and suggesting improvements or alternatives. This role operates at the intersection of security operations and real-world business impact—where speed, precision, and judgment matter more than theory.
Responsibilities
- Acting as a central point of contact within the global incident response team, the Security Analyst will:
- Analyze and respond to alerts generated by our SIEM (Security Information and Events management) and other security tool suite (EDR, Identity service, etc.) on a day to day basis
- Perform forensic and investigation activities on hosts, network, infrastructure and applications targeted by threat actors
- Identify attacker tactics, techniques, and procedures and proactively hunt for threats based on intelligence and hypothesis.
- Lead incident response activities end to end for incident of low and medium criticality before, during and after incidents;
- Support and coordinate incident response activities for high and critical incidents before, during and after incidents;
- Drive decision-making processes under pressure to determine incident handling approaches (contain vs monitor, isolate vs preserve, shutdown or maintain availability).
- Produce clear investigation reports for technical and non-technical audiences
- Those circumstances may require to outside of traditional working hours.
- Validate and enrich detection by collaborating with detection engineering team and propose alert tuning strategies and implementations.
- Validate and tune our security tool suite by providing feedback to the detection engineering team and suggest improvement plan.
- Participate in the creation and implementation of incident response plans;
- Occasionally participate in internal investigations (local and corporate headquarters) in accordance to established policies;
- Collaborate on threat intelligence activities by performing relevant and efficient analyses and reporting back findings;
- Propose solutions to mitigate identified risks and bring them to an acceptable level for management.
- Carry out all other related tasks.
Qualifications
Education & Experience
- Bachelors’ Degree in Computer Sciences or any related discipline.
- 2+ years in operating system administration and/or network administration.
- 2+ years in audit and/or incident response and/or monitoring.
- 2+ years in other security related function.
- 1+ years in managing SIEM, IDS/IPS, EDR/XDR solutions in a fast paced environment.
- Hands-on experience in incident response and coordination.
- SANS GIAC certification is a strong asset.
Knowledge & Skills
- Ability to work under pressure and adapt quickly to change;
- Good problem-solving skills.
- Ability to manipulate sensitive information;
- Ability to analyse and summarize complex data;
- Effectively collaborate with a variety of stakeholders from top management to business and technical stakeholders;
- Proactive, methodic, and result-oriented;
- Solid business understanding;
- Ability to write clear and concise documentation;
- Adapt quickly to change;
- English & Mandarin is required (Written and verbal communication);
- French language is an asset;
- Interpersonal and negotiation skills.
Additional Information
While the team operates under a “follow the sun” coverage model and not on a 24/7 rotation or night shift basis, on rare occasions you may be called to assist with resolving major incidents outside of standard working hours.
Due to the nature of incident response, you will be working in a fast-paced environment and must be efficient at prioritizing multiple critical incidents.
Skills and competencies show up in different forms and can be based on different experiences, that's why we strongly encourage you to apply even though you may not have all the requirements listed above.
At Ubisoft, you can come as you are. We embrace diversity in all its forms. We’re committed to fostering a work environment that is inclusive and respectful of all
By clicking the link above or any third-party link within this posting, you are leaving this site and going to a third-party website where the third-party website's terms and privacy policy apply