Threat Hunter & Incident Response Engineer

PT Cemerlang Tunggal Intikarsa (CTI Group Jakarta)

Jakarta Utara

On-site

IDR 400,000,000 - 700,000,000

Full time

10 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

PT Cemerlang Tunggal Intikarsa (CTI Group Jakarta) is hiring a Threat Hunter & Incident Response Engineer to develop and maintain detection capabilities using Sigma, YARA, and related rules. You will lead DFIR investigations, containment, and root cause analysis across client environments.

You will monitor daily cyber threats and conduct PoC testing for new detections, while performing threat hunting and knowledge transfer to the SOC team in Jakarta.

Responsibilities

  • Develop and maintain detection capabilities using Sigma, YARA, and other rules.
  • Perform DFIR activities to support incident investigation, containment, and root cause analysis.
  • Monitor and analyze daily cybersecurity threats, vulnerabilities, advisories, and new attack techniques.
  • Conduct periodic SOC visibility and log completeness assessments to identify monitoring gaps.
  • Perform IOC analysis and enrichment from logs, intel sources, and related data.
  • Develop and enhance detection use cases and correlation rules for threat identification.
  • Maintain documentation for detection capabilities, logic, use cases, and tuning.
  • Conduct PoC testing, validation, and quality assessment of new detections before production.
  • Threat hunting activities to proactively identify suspicious activities and indicators of compromise.
  • Provide knowledge transfer and guidance to SOC Analysts to boost capabilities.
  • Collaborate with SOC and Security Engineering to improve detection coverage and visibility.

Job description

Threat Hunter & Incident Response Engineer
  • Develop and maintain detection capabilities using technologies and frameworks such as Sigma, YARA, and other detection rules.
  • Perform Digital Forensics and Incident Response (DFIR) activities to support security incident investigation, containment, and root cause analysis.
  • Monitor and analyze daily cybersecurity threats, vulnerabilities, security advisories, and emerging attack techniques relevant to the organization and its customers.
  • Conduct periodic SOC visibility and log completeness assessments to identify gaps in security monitoring and detection coverage.
  • Perform IOC analysis and enrichment based on integrated security logs, threat intelligence sources, and other relevant data.
  • Develop and enhance detection use cases and correlation rules to identify potential security threats based on IOCs, TTPs, and observed attack patterns.
  • Maintain comprehensive documentation for detection capabilities, including detection logic, use cases, rule development, validation, and tuning.
  • Conduct Proof of Concept (PoC), testing, validation, and quality assessment of new detection capabilities before production implementation.
  • Perform threat hunting activities to proactively identify suspicious activities, advanced threats, and potential indicators of compromise within monitored environments.
  • Provide knowledge transfer and technical guidance to SOC Analysts across L1–L3 to improve investigation, detection, and incident response capabilities.
  • Collaborate with SOC, Security Engineering, and other technical teams to continuously improve detection coverage, monitoring visibility, and overall SOC capabilities.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Threat Hunter & Incident Response Engineer
Threat Hunter & Incident Response Engineer

Jedi Solutions • Jakarta Utara

On-site
IDR 200,000,000 - 500,000,000
Threat Hunter & IR Engineer - Detection, DFIR & PoC Lead
Threat Hunter & IR Engineer - Detection, DFIR & PoC Lead

PT Cemerlang Tunggal Intikarsa (CTI Group Jakarta) • Jakarta Utara

On-site
IDR 400,000,000 - 700,000,000
Senior Threat Hunter & Incident Response Engineer
Senior Threat Hunter & Incident Response Engineer

Jedi Solutions • Jakarta Utara

On-site
IDR 200,000,000 - 500,000,000
Security Operations Center Analyst
Security Operations Center Analyst

Privy • Jakarta Pusat

On-site
IDR 133,920,000 - 200,880,000
Senior Information Security Incident Response Lead
Senior Information Security Incident Response Lead

NTT Limited • Daerah Khusus Ibukota Jakarta

On-site
IDR 1,068,185,000 - 1,602,279,000
Security Analyst L2
Security Analyst L2

Ensign InfoSecurity • Jakarta Selatan

On-site
IDR 180,000,000 - 240,000,000
SOC L2 Analyst - Cybersecurity Technology Consulting
SOC L2 Analyst - Cybersecurity Technology Consulting

EY • Daerah Khusus Ibukota Jakarta

On-site
IDR 150,000,000 - 200,000,000
Cyber Threat Intelligence Analyst
Cyber Threat Intelligence Analyst

Packet Systems Indonesia • Jakarta Pusat

On-site
IDR 100,440,000 - 167,400,000
Senior Incident Response Lead: Threat Hunts & Forensics
Senior Incident Response Lead: Threat Hunts & Forensics

NTT Limited • Daerah Khusus Ibukota Jakarta

On-site
IDR 1,068,185,000 - 1,602,279,000
TC - SOC Cybersecurity Consultant Manager
TC - SOC Cybersecurity Consultant Manager

EY • Daerah Khusus Ibukota Jakarta

On-site