Threat Hunter & Incident Response Engineer

Jedi Solutions

Jakarta Utara

On-site

IDR 200,000,000 - 500,000,000

Full time

10 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Jedi Solutions is hiring a Threat Hunter & Incident Response Engineer to enhance detection capabilities and lead proactive security investigations in Jakarta, Indonesia. You will develop detection rules using Sigma and YARA, perform DFIR activities, monitor threats, and provide guidance to SOC analysts.

Collaboration with SOC and Security Engineering teams is essential to strengthen monitoring coverage and incident response capabilities.

Qualifications

  • Experience in security operations and incident response.
  • Proficient with DFIR methodologies and threat hunting.
  • Knowledge of detection rules and use-case development.

Responsibilities

  • Develop and maintain detection capabilities using Sigma, YARA and other rules.
  • Perform DFIR activities to support incident investigation, containment and root cause analysis.
  • Monitor and analyze daily cybersecurity threats, vulnerabilities, advisories and attack techniques.
  • Conduct periodic SOC visibility and log coverage assessments to identify gaps.
  • Perform IOC analysis and enrichment from logs and threat intel.
  • Develop and refine detection use cases and correlation rules based on IOCs and TTPs.
  • Maintain documentation for detection capabilities including logic, rules and validation.
  • Conduct PoC, testing, validation and quality assessment of new detections before production.
  • Carry out threat hunting to identify suspicious activity and indicators of compromise.
  • Provide knowledge transfer and guidance to SOC Analysts to improve capabilities.
  • Collaborate with SOC and Security Engineering to improve detection coverage and monitoring.

Skills

Network
Incident response
Operating systems
DFIR
Threat hunting
Detection eng

Tools

Sigma
YARA

Job description

Threat Hunter & Incident Response Engineer
  • Develop and maintain detection capabilities using technologies and frameworks such as Sigma, YARA, and other detection rules.
  • Perform Digital Forensics and Incident Response (DFIR) activities to support security incident investigation, containment, and root cause analysis.
  • Monitor and analyze daily cybersecurity threats, vulnerabilities, security advisories, and emerging attack techniques relevant to the organization and its customers.
  • Conduct periodic SOC visibility and log completeness assessments to identify gaps in security monitoring and detection coverage.
  • Perform IOC analysis and enrichment based on integrated security logs, threat intelligence sources, and other relevant data.
  • Develop and enhance detection use cases and correlation rules to identify potential security threats based on IOCs, TTPs, and observed attack patterns.
  • Maintain comprehensive documentation for detection capabilities, including detection logic, use cases, rule development, validation, and tuning.
  • Conduct Proof of Concept (PoC), testing, validation, and quality assessment of new detection capabilities before production implementation.
  • Perform threat hunting activities to proactively identify suspicious activities, advanced threats, and potential indicators of compromise within monitored environments.
  • Provide knowledge transfer and technical guidance to SOC Analysts across L1-L3 to improve investigation, detection, and incident response capabilities.
  • Collaborate with SOC, Security Engineering, and other technical teams to continuously improve detection coverage, monitoring visibility, and overall SOC capabilities.

Job Requirement

  • Skill: Network, Security incident management, Operating Systems, Incident Response
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Threat Hunter & Incident Response Engineer
Threat Hunter & Incident Response Engineer

PT Cemerlang Tunggal Intikarsa (CTI Group Jakarta) • Jakarta Utara

On-site
IDR 400,000,000 - 700,000,000
Threat Hunter & IR Engineer - Detection, DFIR & PoC Lead
Threat Hunter & IR Engineer - Detection, DFIR & PoC Lead

PT Cemerlang Tunggal Intikarsa (CTI Group Jakarta) • Jakarta Utara

On-site
IDR 400,000,000 - 700,000,000
Security Analyst L2
Security Analyst L2

Ensign InfoSecurity • Jakarta Selatan

On-site
IDR 180,000,000 - 240,000,000
Senior Threat Hunter & Incident Response Engineer
Senior Threat Hunter & Incident Response Engineer

Jedi Solutions • Jakarta Utara

On-site
IDR 200,000,000 - 500,000,000
Security Operations Center Analyst
Security Operations Center Analyst

Privy • Jakarta Pusat

On-site
IDR 133,920,000 - 200,880,000
Senior Information Security Incident Response Lead
Senior Information Security Incident Response Lead

NTT Limited • Daerah Khusus Ibukota Jakarta

On-site
IDR 1,068,185,000 - 1,602,279,000
SOC L2 Analyst - Cybersecurity Technology Consulting
SOC L2 Analyst - Cybersecurity Technology Consulting

EY • Daerah Khusus Ibukota Jakarta

On-site
IDR 150,000,000 - 200,000,000
Cyber Threat Intelligence Analyst
Cyber Threat Intelligence Analyst

Packet Systems Indonesia • Jakarta Pusat

On-site
IDR 100,440,000 - 167,400,000
SOC L2 Analyst - Cybersecurity Technology Consulting
SOC L2 Analyst - Cybersecurity Technology Consulting

Ernst & Young Advisory Services Sdn Bhd • Daerah Khusus Ibukota Jakarta

On-site
IDR 180,000,000 - 240,000,000
Senior Incident Response Lead: Threat Hunts & Forensics
Senior Incident Response Lead: Threat Hunts & Forensics

NTT Limited • Daerah Khusus Ibukota Jakarta

On-site
IDR 1,068,185,000 - 1,602,279,000