IT Incident Response Engineer - Digital Forensics & Incident Response Manager

Olympus

Security

Cybersec

About this role

This senior global security operations role leads complex cyber incident response and digital forensics investigations across all regions. The position serves as the primary incident response point of contact for Japan while coordinating response activities for corporate offices, manufacturing plants, and research and development facilities. It also leads Japan-based response activities and acts as the delegated incident response lead when the US-based Incident Response Leader is unavailable.

The role directs 15–20 offsite contractors during Japan business hours and manages coordination with managed service providers, third-party incident response firms, and other external stakeholders. Responsibilities include overseeing service delivery, including SLAs and KPIs, and leading investigations involving endpoints, servers, networks, cloud environments, and mobile devices. The position conducts digital forensic examinations, malware analysis, incident analysis, containment and recovery activities, and post-incident reporting. It also develops and maintains IT, OT, and ICS incident response playbooks, tabletop exercises, operating procedures, and forensic response processes. Additional work includes security monitoring and analysis in a GSOC or SIEM environment, threat intelligence analysis, and continuous improvement of workflows and response capabilities.

Applicants are expected to have at least 10 years of progressive cybersecurity experience, including at least 5 years in hands-on incident response or digital forensics. Required experience includes leading complex enterprise-scale incidents such as ransomware, data breaches, insider threats, and advanced persistent threats. Hands-on experience should cover endpoint forensics on Windows, Linux, and macOS; memory and network forensics; log analysis; malware triage; and cloud forensics using Azure, AWS, or GCP. Experience supporting OT/ICS environments or the IT security of manufacturing or R&D facilities, working with a SOC or global SOC, and managing external contractors, managed service providers, or third-party incident response firms is stated. Security automation and scripting experience using Python, PowerShell, Ruby, or similar languages is also required. Familiarity with blockchain and cryptocurrency transaction tracing for ransomware and fraud investigations is listed.

The incident response and forensics toolchain named in the posting includes CrowdStrike, Splunk, Microsoft Sentinel, Velociraptor, Magnet AXIOM, X-Ways, Volatility, ELK, and Osquery. Certifications listed include GCIH, GCFA or GCFE, GCED, CISSP, EnCE, and CISM.

The listed work locations are the Japan headquarters in Hachioji, Tokyo, and the satellite office at 2-3-1 Nishi-Shinjuku, Shinjuku-ku, Tokyo. Working hours are 8:45–17:30 with a 45-minute break and eight standard working hours. A flextime system without core hours, a telework system, 129 annual holidays, 20 days of annual paid leave, and statutory social insurance are stated. Salary follows company regulations.

This is an AI-generated summary of the employer's original posting — details can be incomplete, out of date or simply wrong. Always confirm everything on the official posting before applying.