Security Analyst (Intelligence & Operations)

GXS Bank

Petaling Jaya

On-site

MYR 90,000 - 150,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

GXS Bank is seeking a skilled SOC professional to join its Security Operations Center. You will act as Tier 2 escalation for validated threats and conduct deep-dive forensics on endpoints, memory, and traffic to identify root causes.

The role requires 3–5 years in SOC or equivalent, strong knowledge of SIEM/EDR/SOAR, and familiarity with cloud services. You will mentor junior analysts and contribute to incident response improvements.

Qualifications

  • Bachelor’s degree in a relevant field; 3–5 years SOC experience.
  • Experience developing SOC use cases in SIEM to correlate logs and enable effective investigations.

Responsibilities

  • Act as Tier 2 escalation point for validated threats.
  • Conduct deep-dive forensic analysis on endpoints, memory, and network traffic.

Skills

SOC use cases
Threat intelligence
Networking basics
Incident management
Cybersecurity certifications
Cloud familiarity
Splunk ES
SIEM/EDR/SOAR tools
Mentoring

Education

Bachelor’s Degree in a relevant field

Tools

SIEM
EDR
SOAR
TIP
ServiceNow
Splunk ES

Job description

Responsibilities
  • Act as the Tier 2 Escalation Point for all validated threats filtered by the L1 team.
  • Conduct deep-dive forensic analysis on endpoints, memory, and network traffic to identify root causes.
  • Lead containment and eradication efforts for multi-stage attacks (e.g., Ransomware, Business Email Compromise).
  • Maintain a comprehensive awareness of the current threat landscape, including malware, phishing attacks, and advanced persistent threats (APTS).
  • Create/review/modify documentation as needed, to include any process or procedure and thus ensure it’s up to date and standard
  • Daily/Weekly/Monthly SOC Reports.
  • Define, create and maintain SIEM correlation rules, customer build documents, security process and procedures.
  • Threat Hunting & Detection Engineering
  • Proactively hunt for stealthy threats that bypass automated security controls using the MITRE ATT&CK framework.
  • Develop and deploy custom SIEM correlation rules and EDR queries to detect advanced adversary techniques.
  • Convert "Tribal Knowledge" into automated Level 1 Playbooks to empower the junior team.
  • Mentorship & Quality Assurance
  • Perform "Case Reviews" of L1 investigations to ensure high data quality and provide technical coaching.
  • Coordinate with the Global Follow-the-Sun leads to ensure smooth handovers of high-priority incidents.
  • Actively participate in post-incident reviews to identify lessons learned and recommend improvements to processes and technologies.
  • Provide feedback and recommendations to enhance detection and response capabilities.
  • Participate in continuous improvement of security operations processes and toolsets.
  • Mentor and train junior analysts, sharing knowledge and best practices to strengthen team capabilities.
Requirements
  • Experience in developing SOC use cases in SIEM to correlate diverse logs, including the creation of new monitoring use case logic and enabling effective investigation of security alerts and incidents.
  • Knowledge of Cyber Threat Intelligence, including the analysis of intelligence alerts, threat hunting, and providing actionable recommendations.
  • Strong understanding of networking principles including TCP/IP, WANs, LANs, and commonly used Internet protocols such as SMTP, HTTP, FTP, POP, LDAP.
  • Understanding common threat vectors ie malware, email, and website analysis at a medium to high level.
  • Strong understanding of security incident management, malware management and vulnerability management processes.
  • Strong knowledge of IT and system administration skills in modern operating systems.
  • Exposure to SIEM, EDR, SOAR, TIP, & ServiceNow tools etc is required.
  • Ability to remain focused during repetitive monitoring while maintaining a high attention to detail.
  • Ability to translate complex technical findings into actionable insights for diverse stakeholders.
  • Some experience with cloud service providers like AWS and Azure would prove valuable.
  • Experience with Splunk ES would be a plus.
  • Bachelor’s Degree in relevant field of studies.
  • 3-5 years of experience in a SOC environment or equivalent technical role.
  • Valid certification for either CEH/ECIH/CHFI/Any SIEM Technical Certification/Any Firewall Technical Certification/or any other industry-related certificate.
  • Demonstrated commitment to continuous learning and intellectual curiosity within the cybersecurity domain.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Analyst (Intelligence - Operations)
Security Analyst (Intelligence - Operations)

GXS Bank • Selangor

On-site
MYR 90,000 - 130,000
Senior Security Analyst
Senior Security Analyst

Logicalis • Kuala Lumpur

On-site
MYR 180,000 - 300,000
SOC Lead
SOC Lead

Axonect • Kuala Lumpur

Hybrid
MYR 140,000 - 180,000
L2 SOC Analyst / Security Delivery Consultant
L2 SOC Analyst / Security Delivery Consultant

ABP Group • Kuala Lumpur

On-site
MYR 60,000 - 120,000
L2 SOC Analyst / Engineer
L2 SOC Analyst / Engineer

Insyghts Security Sdn Bhd • Iskandar Puteri

On-site
MYR 60,000 - 100,000
Senior Security Analyst
Senior Security Analyst

Logicalis Asia Pacific • Kuala Lumpur

On-site
MYR 80,000 - 100,000
Senior Security Analyst
Senior Security Analyst

All jobs • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Security Analyst L2
Security Analyst L2

Ensign InfoSecurity • Kuala Lumpur

On-site
MYR 80,000 - 120,000
Staff Analyst Threat Intelligence
Staff Analyst Threat Intelligence

Infineon Technologies AG • Penang

On-site
MYR 80,000 - 120,000
Manager Security Operation Centre
Manager Security Operation Centre

GoKardz Technologies • Kuala Lumpur

On-site
MYR 120,000 - 150,000