Digital Forensic & Incident Response (L3)

GoKardz Technologies

Kuala Lumpur

On-site

MYR 80,000 - 120,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

GoKardz Technologies is seeking an Executive for Digital Forensics & Incident Response in Kuala Lumpur. The successful candidate will be responsible for developing and maintaining honeypots, supporting incident response tasks, and conducting threat hunting.

The position requires a Bachelor's degree in Computer Science with a major in Cybersecurity and relevant certifications like SANS GIAC. Preferred candidates will have hands-on experience in DFIR, ability to mentor teammates, and a strong skill set in scripting for automation.

Qualifications

  • Bachelor's degree necessary in a related field.
  • Certifications like CEH or GIAC are advantages.
  • Experience in DFIR is a plus.

Responsibilities

  • Develop and maintain honeypots and threat analysis lab.
  • Support Security Operations Center with daily alerts.
  • Conduct threat hunting and analysis of anomalies.
  • Evaluate and implement EDR solutions for detection.
  • Mentor junior analysts in incident response.

Skills

Cybersecurity expertise
Incident Response Management
Scripting/Programming (Python, Yara)
Threat Hunting
Threat Analysis

Education

Bachelor’s Degree in Computer Science or IT majoring in Cybersecurity
Certifications in Cybersecurity

Tools

EDR Solutions
SIEM Tools

Job description

Executive, Digital Forensics & Incident Response
Responsibilities
  • Develop and maintain honeypots and supporting infrastructure and be SME on honeypots and honeypot infrastructure
  • Develop and maintain threat analysis lab virtual machines, cyber ranges and supporting infrastructure and be SME on lab machines and supporting infrastructure
  • Develop and maintain open source or in-house tools, scripts, automation and systems as needed to support threat intelligence and incident response tasks
  • Conduct ad hoc and periodic compromise assessments of Maybank networks and systems and report on findings
  • Support the Security Operations Center in validating daily security alerts by investigating the malicious artefacts and binaries when additional coverage is needed
  • Conduct threat hunting on Maybank systems and networks to identify undetected activities and breaches, while also creating proactive and reactive rules to alert IT Security on potential threats.
  • Analyse code (binaries, scripts, web scripts) and malspam emails to determine malicious intent
  • Analyse artefacts and logs to determine malicious intent and/or scope of incident
  • Report and document results of analysis and recommend follow up actions, remediation and security control gaps to IT Security, application owners and other stakeholders
  • Create rules to detect adversary TTP on Maybank systems and network
  • Evaluate, implement, and fine-tune Endpoint Detection and Response (EDR) and other detective solutions to improve threat detection and response times
  • Conduct a clean-up of Indicators of Compromise (IOCs) by identifying and removing duplicates to optimize threat detection and response processes
  • Work closely with other teams including IT Security Engineers regarding improving detection/blocking reducing false positives, the threat intelligence team to ensure real-time threat data is integrated into detection systems and incident response procedures.
  • Utilizing scripting/programming skill such as Phyton, Yara etc to automate repetitive incident response tasks such as data extraction or improving overall efficiency
  • Configuring risk based alerts and defining response playbooks
  • Executing threat hunting assignments and providing update reports with recommendations for security improvement
  • Representing the IR team in cyber drill exercises.
  • Being present whenever required for incident response, when required.
  • Mentor IR and SOC analysts on improving digital forensics & incident response (DFIR) analysis.
  • Working with the SOC and SIEM engineers closely to recommend solutions for threat activity logging gaps, reduction of false alarms.
  • Reviewing and improving CSIRT Incident management processes continuously.
  • Playing the role of acting Incident Response manager/lead, in his/her absence.
Requirements
  • Bachelor’s Degree in Computer Science or Information Technology majoring in Cybersecurity, Networking or any related field
  • Certifications an advantage - SANS GIAC Certified Incident Handler / SANS GIAC Reverse Engineering Malware / Certified Ethical Hacker (CEH)
  • CompTIA CySA+.
  • Job experience in DFIR an advantage
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Incident Response Lead
Incident Response Lead

Axonect • Kuala Lumpur

On-site
MYR 180,000 - 360,000
Senior Security Analyst
Senior Security Analyst

Logicalis • Kuala Lumpur

On-site
MYR 180,000 - 300,000
advanced cyber security incident responder
advanced cyber security incident responder

RecruitFirst Pte Ltd • Malaysia

On-site
Cyber Security Engineer
Cyber Security Engineer

RHB Banking Group • Selangor

On-site
MYR 80,000 - 120,000
Senior Information Security Incident Response Lead
Senior Information Security Incident Response Lead

NTT DATA Asia Pacific • Petaling Jaya

On-site
MYR 80,000 - 120,000
Associate (Forensics Lead), Incident Response
Associate (Forensics Lead), Incident Response

S-RM • Kuala Lumpur

Hybrid
MYR 80,000 - 120,000
20 days paid holiday
Flexible working hours
Pension scheme
+2
IT Security Analyst
IT Security Analyst

RHB Banking Group • Selangor

On-site
MYR 60,000 - 110,000
Lead DFIR Scientist: Threat Hunting & Incident Response
Lead DFIR Scientist: Threat Hunting & Incident Response

GoKardz Technologies • Kuala Lumpur

On-site
MYR 80,000 - 120,000
Associate (Forensics Lead), Incident Response Cyber security Kuala Lumpur
Associate (Forensics Lead), Incident Response Cyber security Kuala Lumpur

S-RM Intelligence and Risk Consulting • Kuala Lumpur

Hybrid
MYR 75,000 - 95,000
20 days paid holiday
Flexible working hours
Pension scheme
+3
Security Analyst (Intelligence & Operations)
Security Analyst (Intelligence & Operations)

GXS Bank • Petaling Jaya

On-site
MYR 90,000 - 150,000