Ensign is hiring L2 Security Analyst. You will monitor third party security feeds, forums, and mailing lists to gather information related to the client through automated means.
Responsibilities
- Produce intelligence outputs to provide an accurate depiction of the current threat landscape and associated risk through the use of customer, community, and open source reporting.
- Produce actionable intelligence information for delivery to colleagues and customers in the form of technical reports, briefings, and data feeds.
- Review vulnerability advisories and threat intelligence reports.
- Perform detailed investigative work into all traffic anomalies against established, historical baselines of individual agencies; review and profile the events of all monitored clients.
- Assess each event based on factual information and wider contextual information available; review, propose and generate reports to automate or reduce low‑value event escalations.
- Build rules and intelligence to detect threats and proliferate to all monitored networks.
- Implement and devise detection methods of such threats in our security operations through SIEM rules, DB scripts, etc.
- Perform periodic analysis of security events, network traffic, and logs to engineer new detection methods or create efficiencies when available.
- Support the development of tactics, techniques, and procedures in providing proactive threat hunting and analysis against available information sources (e.g. Netflow, DNS and firewall logs).
- Assist security analysts with investigative work; prepare training programmes for security analysts and conduct knowledge‑sharing sessions.
- Fulfil change requests, service requests and respond to internal/external enquiries with regards to detection use cases.
- Perform any other tasks as assigned.
Requirements
- Degree holder with at least 5 years of experience in a related field and capacity.
- Prior experience working in a Security Operations Centre (SOC) or Computer Emergency Response Team (CERT/CIRT).
- Deep interest in open source research and critical thinking / contextual analysis abilities.
- Proper understanding of network, applications, and server fundamentals; able to identify and analyse logs thoroughly by looking at indicators.
- Understanding of MITRE ATT&CK framework or cyber kill chain.
- Investigative and analytical problem‑solving skills.
- Understanding of current vulnerabilities, response, and mitigation strategies used in cyber security.
- Related professional cyber security certification, such as GCIA, CEH, preferred.
- Experience with intelligence analysis processes, including Open Source Intelligence (OSINT) and closed source intelligence gathering, source verification, data fusion, link analysis, and threat actor characterisation.
- Ability to research and characterise security threats, including identification and classification of threat indicators.
About Ensign InfoSecurity
Ensign InfoSecurity is the largest pure‑play cybersecurity service provider in Asia, headquartered in Singapore. We specialise in cybersecurity advisory and assurance, implementation and management of advanced controls, monitoring, threat hunting, and incident response. Our services are underpinned by in‑house research and development in cybersecurity.
What Makes Ensign Special? We are a technology company with warmth and soul. We are ambitious, propelled by our vision to be the cyber defender of choice, and fueled by the dedication and camaraderie of individuals who are eager to make a difference and leave their footprints in the industry. If you are a self‑motivated, curious go‑getter, we want you! Join us.