Security Analyst (Intelligence & Operations)

GXBank

Petaling Jaya

On-site

MYR 120,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

GXBank is seeking a skilled cybersecurity professional to serve as Tier 2 escalation for validated threats, performing deep-dive analyses of endpoints, memory, and network traffic to identify root causes. You will lead containment and eradication for multi-stage attacks and contribute to daily/weekly/monthly SOC reports.

Ideal candidates have 3–5 years in SOC roles, strong knowledge of MITRE ATT&CK, and hands-on experience with SIEM/EDR/SOAR, cloud platforms, and documentation updates to keep

Qualifications

  • Experience in developing SOC use cases to correlate logs and enable investigations.

Responsibilities

  • Act as the Tier 2 Escalation Point for validated threats filtered by L1 team.

Skills

SOC
Threat Hunting
Incident Response
SIEM
EDR
SOAR
ServiceNow
Splunk ES
Networking
Cloud Platforms

Education

Bachelor’s Degree in Cybersecurity or related field

Tools

Splunk ES
SIEM
EDR Tools
ServiceNow
Cloud Platforms (AWS/Azure)

Job description

Responsibilities:

  1. Advanced Incident Response & Escalation
  • Act as the Tier 2 Escalation Point for all validated threats filtered by the L1 team.

  • Conduct deep-dive forensic analysis on endpoints, memory, and network traffic to identify root causes.

  • Lead containment and eradication efforts for multi-stage attacks (e.g., Ransomware, Business Email Compromise).

  • Maintain a comprehensive awareness of the current threat landscape, including malware, phishing attacks, and advanced persistent threats (APTs).

  • Create/review/modify documentation as needed, to include any process or procedure and thus ensure it’s up to date and standard

  • Daily/Weekly/Monthly SOC Reports.

  • Define, create and maintain SIEM correlation rules, customer build documents, security process and procedures.

  1. Threat Hunting & Detection Engineering
  • Proactively hunt for stealthy threats that bypass automated security controls using the MITRE ATT&CK framework.

  • Develop and deploy custom SIEM correlation rules and EDR queries to detect advanced adversary techniques.

  • Convert “Tribal Knowledge” into automated Level 1 Playbooks to empower the junior team.

  1. Mentorship & Quality Assurance
  • Perform “Case Reviews” of L1 investigations to ensure high data quality and provide technical coaching.

  • Coordinate with the Global Follow-the-Sun leads to ensure smooth handovers of high-priority incidents.

  • Actively participate in post-incident reviews to identify lessons learned and recommend improvements to processes and technologies.

  • Provide feedback and recommendations to enhance detection and response capabilities.

  • Participate in continuous improvement of security operations processes and toolsets.

  • Mentor and train junior analysts, sharing knowledge and best practices to strengthen team capabilities.

Requirements :

  • Experience in developing SOC use cases in SIEM to correlate diverse logs, including the creation of new monitoring use case logic and enabling effective investigation of security alerts and incidents.

  • Knowledge of Cyber Threat Intelligence, including the analysis of intelligence alerts, threat hunting, and providing actionable recommendations.

  • Strong understanding of networking principles including TCP/IP, WANs, LANs, and commonly used Internet protocols such as SMTP, HTTP, FTP, POP, LDAP.

  • Understanding common threat vectors ie malware, email, and website analysis at a medium to high level.

  • Strong understanding of security incident management, malware management and vulnerability management processes.

  • Strong knowledge of IT and system administration skills in modern operating systems.

  • Exposure to SIEM, EDR, SOAR, TIP, & ServiceNow tools etc is required.

  • Ability to remain focused during repetitive monitoring while maintaining a high attention to detail.

  • Ability to translate complex technical findings into actionable insights for diverse stakeholders.

  • Some experience with cloud service providers like AWS and Azure would prove valuable.

  • Experience with Splunk ES would be a plus.

  • Bachelor’s Degree in relevant field of studies.

  • 3-5 years of experience in a SOC environment or equivalent technical role.

  • Valid certification for either CEH/ECIH/CHFI/Any SIEM Technical Certification/Any Firewall Technical Certification/or any other industry-related certificate.

  • Demonstrated commitment to continuous learning and intellectual curiosity within the cybersecurity domain.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Analyst (Intelligence & Operations)
Security Analyst (Intelligence & Operations)

GXS Bank • Petaling Jaya

On-site
MYR 90,000 - 150,000
Senior SOC Analyst
Senior SOC Analyst

Pride Global • Selangor

On-site
MYR 120,000 - 180,000
Senior Security Analyst (SOC Level 3)
Senior Security Analyst (SOC Level 3)

Ensign Services • Kuala Lumpur

On-site
MYR 70,000 - 130,000
Security Analyst L3
Security Analyst L3

Ensign Services • Rawang

On-site
MYR 120,000 - 180,000
SOC Specialist
SOC Specialist

Pride Global • Cyberjaya

On-site
MYR 120,000 - 180,000
Senior Security Analyst
Senior Security Analyst

Logicalis • Kuala Lumpur

On-site
MYR 180,000 - 300,000
Senior Cyber Threat Engineer & SOC Mentor
Senior Cyber Threat Engineer & SOC Mentor

RHB Banking Group • Selangor

On-site
MYR 80,000 - 120,000
SOC Lead
SOC Lead

Axonect • Kuala Lumpur

On-site
MYR 180,000 - 240,000
L2 SOC Analyst – SIEM
L2 SOC Analyst – SIEM

S SQUAD SDN. BHD. • Labuan

On-site
MYR 60,000 - 90,000
L2 SOC Analyst
L2 SOC Analyst

Pride Global • Selangor

On-site
MYR 60,000 - 110,000