Richemont Senior Cybersecurity Incident Response Analyst
- Employment
- Full-Time
- Seniority
- Senior
- Department
- IT & Technology Systems
- Industry
- High Jewelry
- Posted
- Sep 22, 2026
About Richemont
Richemont is one of the world’s foremost luxury groups, stewarding a distinguished portfolio of maisons across jewellery, watchmaking, fashion and accessories, including Cartier, Van Cleef & Arpels, Jaeger-LeCoultre and Montblanc. As an employer, it combines the heritage of artisanal excellence with a forward-looking culture shaped by innovation, client-centricity and responsible business. Its global teams operate in an environment that values craftsmanship, entrepreneurship and collaboration, offering opportunities to grow within iconic maisons and group functions alike. Richemont attracts professionals who aspire to contribute to enduring luxury, preserving rare savoir-faire while helping define the future of high craftsmanship.
Richemont seeks a Senior Cybersecurity Incident Response Analyst in Hong Kong to lead complex incident investigations and technical team leadership.
Role & Responsibilities
- Act as the technical escalation point (Level 3) for complex and high-impact cybersecurity incidents affecting the Group
- Lead advanced incident investigations to determine attack scope, root cause, attacker techniques, affected assets, and business impact
- Perform advanced forensic analysis including evidence collection, timeline reconstruction, endpoint analysis, and suspicious file analysis across multiple environments
- Lead technical incident response activities including investigation, containment, eradication, remediation, and recovery recommendations
- Conduct proactive and hypothesis-driven threat hunting based on emerging threats, threat intelligence, and attacker behaviours
- Develop, enhance, and technically validate security detections across SIEM, EDR/XDR, identity, cloud, network, and other security platforms
- Translate incident and threat hunting findings into improved detections, monitoring coverage, and response capabilities
- Perform technical quality reviews of junior analyst investigations to ensure findings are complete, evidence-based, technically accurate, and aligned with standards
- Identify recurring investigation gaps and contribute to improved playbooks, SOPs, documentation standards, and investigation methodologies
- Support threat intelligence, purple-team, and threat-informed defence activities to enhance detection and response effectiveness
- Develop scripts, queries, SOAR workflows, and automation tools to improve investigation efficiency
- Provide technical guidance, mentoring, and hands-on support to Level 1 and Level 2 analysts
- Contribute to Cybersecurity projects and initiatives with implications for incident response and security operations
Qualifications
- 5–8+ years of hands-on experience in Security Operations, Incident Response, Threat Hunting, Digital Forensics, or related disciplines
- Advanced knowledge of networking, operating systems, identity management, cloud environments, and enterprise infrastructure
- Strong practical experience investigating attacker techniques including credential access, privilege escalation, persistence, defence evasion, lateral movement, command and control, and data exfiltration
- Proficiency in analysing endpoint, network, identity, cloud, email, and application telemetry across multiple data sources
- Practical expertise in digital forensic investigation techniques including evidence collection, timeline analysis, endpoint artefacts analysis, and root cause analysis
- Hands-on experience with security technologies including SIEM, SOAR, EDR/XDR, IDS/IPS, NDR, mail security, identity security, and cloud security platforms
- Strong technical quality-assurance skills with ability to review investigations critically, identify gaps, and ensure conclusions are evidence-based
- Proficiency in analytics and investigation languages such as SPL, KQL, or SQL
- Experience developing, improving, or validating security detections, investigation queries, and threat hunting methodologies
- Strong understanding of attacker tactics, techniques, and procedures with practical experience using frameworks such as MITRE ATT&CK
- Ability to independently investigate ambiguous, unfamiliar, or technically complex incidents where established playbooks may not provide complete answers
- Demonstrated ability to mentor and provide technical guidance to less experienced analysts
- Strong analytical, problem-solving, and communication skills with ability to engage both technical and non-technical stakeholders
Skills
Experience
5-8+ years of hands-on cybersecurity experience in Security Operations, Incident Response, Threat Hunting, or Digital Forensics. Strong background in investigating complex attacker techniques, analysing multi-source telemetry, and leading technical incident response activities in enterprise environments. Demonstrated experience providing technical leadership and mentoring to junior security professionals. Experience working in large, multinational, or distributed enterprise organisations is highly advantageous.
Education
Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related technical discipline is preferred. Equivalent practical experience and certifications may be considered.
Workplace
The successful candidate will be located in Hong Kong, Hong Kong, China.
Culture
Richemont fosters a refined, international workplace where its Maisons preserve exceptional craftsmanship while benefiting from the strength and perspective of a global luxury group. As an employer, it values long-term stewardship, collaboration, innovation, and the development of talent within an environment shaped by heritage, creativity, and high standards.
About Cerulean
Cerulean is the definitive career portal for the global luxury industry. We match exceptional professionals with exclusive opportunities at the world's most prestigious brands. From haute couture and fine watchmaking to prestige beauty, hospitality, and boutique retail, Cerulean centralises luxury employment to help you find the career for which you were destined.
Frequently Asked Questions
The luxury industry is characterised by a diverse and nuanced nomenclature. Esteemed houses frequently employ proprietary terminology, and even within a single organisation like Richemont, titles may vary across global markets to reflect local conventions. To ensure absolute clarity, Cerulean assigns a standardised, industry-coherent canonical title to every listing. However, it is worth noting that this role is functionally synonymous with «Technical Lead, Incident Response», «Senior Threat Investigator», «Cybersecurity Investigator», «Advanced Incident Response Specialist», and other variations. Our sophisticated search architecture anticipates these variations, ensuring that inquiries using related terms will seamlessly yield the exact roles you desire.