Security Analyst (Intelligence - Operations)

GXS Bank

Selangor

On-site

MYR 90,000 - 130,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

GXS Bank is seeking a Security Analyst (Intelligence - Operations) in Malaysia to act as Tier 2 escalation for validated threats, perform deep-dive forensics, and lead containment for multi-stage attacks. You will maintain SOC reports, craft SIEM rules, and drive threat hunting using MITRE ATT&CK.

A strong background in SIEM/EDR and cloud security is required. You will mentor junior analysts, review cases for data quality, and collaborate with global teams to improve detection capabilities and

Qualifications

  • Experience developing SOC use cases in SIEM and correlation logic.
  • Knowledge of Cyber Threat Intelligence and actionable recommendations.
  • Strong networking principles understanding (TCP/IP, WANs/LANs, protocols).
  • Understanding of common threat vectors (malware, email, websites).
  • Experience in security incident management, malware and vulnerability processes.
  • IT and system administration skills in modern operating systems.
  • Exposure to SIEM, EDR, SOAR, TIP, and ServiceNow tools.
  • Some cloud experience with AWS and Azure is valuable.
  • Awareness of MITRE ATT&CK framework for threat hunting.
  • Ability to translate complex findings into actionable insights.

Responsibilities

  • Act as Tier 2 escalation for all validated threats; lead containment and eradication.
  • Conduct deep-dive forensic analysis on endpoints, memory and network traffic.
  • Maintain SOC reports daily/weekly/monthly and review playbooks.
  • Define and maintain SIEM correlation rules and security procedures.
  • Threat hunting and detection engineering to identify stealthy threats.
  • Develop and deploy custom SIEM/EDR queries for adversary techniques.
  • Convert tribal knowledge into automated Level 1 playbooks for juniors.
  • Mentor junior analysts and conduct case reviews for data quality.
  • Coordinate handovers with global Follow-the-Sun leads for incidents.
  • Participate in post-incident reviews to derive lessons learned.
  • Provide feedback to enhance detection and response capabilities.
  • Contribute to continuous improvement of security operations tooling.

Skills

SOC use cases in SIEM
Cyber Threat Intelligence
Networking principles
Threat vectors awareness
Security incident management
IT & system administration
SIEM, EDR, SOAR, TIP, ServiceNow
Cloud service providers (AWS/Azure)
Splunk ES
Analytical thinking
Threat hunting

Education

Bachelor’s Degree in relevant field

Tools

SIEM
EDR
SOAR
MITRE ATT&CK
Splunk ES

Job description

Jora Malaysia will close on 9th September 2026. Thank you for being with us, we are cheering you on as you continue your career journey.


Security Analyst (Intelligence - Operations)


  • Act as the Tier 2 Escalation Point for all validated threats filtered by the L1 team.

  • Conduct deep-dive forensic analysis on endpoints, memory, and network traffic to identify root causes.

  • Lead containment and eradication efforts for multi-stage attacks (e.g., Ransomware, Business Email Compromise).

  • Maintain a comprehensive awareness of the current threat landscape, including malware, phishing attacks, and advanced persistent threats (APTs).

  • Create/review/modify documentation as needed, to include any process or procedure and thus ensure it’s up to date and standard

  • Daily/Weekly/Monthly SOC Reports.

  • Define, create and maintain SIEM correlation rules, customer build documents, security process and procedures.

  • Threat Hunting & Detection Engineering

  • Proactively hunt for stealthy threats that bypass automated security controls using the MITRE ATT&CK framework.

  • Develop and deploy custom SIEM correlation rules and EDR queries to detect advanced adversary techniques.

  • Convert "Tribal Knowledge" into automated Level 1 Playbooks to empower the junior team.

  • Mentorship & Quality Assurance

  • Perform "Case Reviews" of L1 investigations to ensure high data quality and provide technical coaching.

  • Coordinate with the Global Follow-the-Sun leads to ensure smooth handovers of high-priority incidents.

  • Actively participate in post-incident reviews to identify lessons learned and recommend improvements to processes and technologies.

  • Provide feedback and recommendations to enhance detection and response capabilities.

  • Participate in continuous improvement of security operations processes and toolsets.

  • Mentor and train junior analysts, sharing knowledge and best practices to strengthen team capabilities.


Responsibility

Responsibilities


  • Advanced Incident Response & Escalation

  • Act as the Tier 2 Escalation Point for all validated threats filtered by the L1 team.

  • Conduct deep-dive forensic analysis on endpoints, memory, and network traffic to identify root causes.

  • Lead containment and eradication efforts for multi-stage attacks (e.g., Ransomware, Business Email Compromise).

  • Maintain a comprehensive awareness of the current threat landscape, including malware, phishing attacks, and advanced persistent threats (APTs).

  • Create/review/modify documentation as needed, to include any process or procedure and thus ensure it’s up to date and standard

  • Daily/Weekly/Monthly SOC Reports.

  • Define, create and maintain SIEM correlation rules, customer build documents, security process and procedures.

  • Threat Hunting & Detection Engineering

  • Proactively hunt for stealthy threats that bypass automated security controls using the MITRE ATT&CK framework.

  • Develop and deploy custom SIEM correlation rules and EDR queries to detect advanced adversary techniques.

  • Convert "Tribal Knowledge" into automated Level 1 Playbooks to empower the junior team.

  • Mentorship & Quality Assurance

  • Perform "Case Reviews" of L1 investigations to ensure high data quality and provide technical coaching.

  • Coordinate with the Global Follow-the-Sun leads to ensure smooth handovers of high-priority incidents.

  • Actively participate in post-incident reviews to identify lessons learned and recommend improvements to processes and technologies.

  • Provide feedback and recommendations to enhance detection and response capabilities.

  • Participate in continuous improvement of security operations processes and toolsets.

  • Mentor and train junior analysts, sharing knowledge and best practices to strengthen team capabilities.


Requirements


  • Experience in developing SOC use cases in SIEM to correlate diverse logs, including the creation of new monitoring use case logic and enabling effective investigation of security alerts and incidents.

  • Knowledge of Cyber Threat Intelligence, including the analysis of intelligence alerts, threat hunting, and providing actionable recommendations.

  • Strong understanding of networking principles including TCP/IP, WANs, LANs, and commonly used Internet protocols such as SMTP, HTTP, FTP, POP, LDAP.

  • Understanding common threat vectors ie malware, email, and website analysis at a medium to high level.

  • Strong understanding of security incident management, malware management and vulnerability management processes.

  • Strong knowledge of IT and system administration skills in modern operating systems.

  • Exposure to SIEM, EDR, SOAR, TIP, & ServiceNow tools etc is required.

  • Ability to remain focused during repetitive monitoring while maintaining a high attention to detail.

  • Ability to translate complex technical findings into actionable insights for diverse stakeholders.

  • Some experience with cloud service providers like AWS and Azure would prove valuable.

  • Experience with Splunk ES would be a plus.

  • Bachelor’s Degree in relevant field of studies.

  • 3-5 years of experience in a SOC environment or equivalent technical role.

  • Valid certification for either CEH/ECIH/CHFI/Any SIEM Technical Certification/Any Firewall Technical Certification/or any other industry-related certificate.

  • Demonstrated commitment to continuous learning and intellectual curiosity within the cybersecurity domain.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Analyst (Intelligence & Operations)
Security Analyst (Intelligence & Operations)

GXS Bank • Petaling Jaya

On-site
MYR 90,000 - 150,000
L2 - Security Analyst
L2 - Security Analyst

Ensign Infosecurity • Kuala Lumpur

On-site
MYR 60,000 - 100,000
Senior Security Analyst
Senior Security Analyst

Logicalis • Kuala Lumpur

On-site
MYR 180,000 - 300,000
SOC Lead
SOC Lead

Axonect • Kuala Lumpur

Hybrid
MYR 140,000 - 180,000
L2 SOC Analyst / Security Delivery Consultant
L2 SOC Analyst / Security Delivery Consultant

ABP Group • Kuala Lumpur

On-site
MYR 60,000 - 120,000
SENIOR SOC ANALYST L2
SENIOR SOC ANALYST L2

TechLab Security • Shah Alam

On-site
MYR 120,000 - 180,000
L1 - SOC Analyst
L1 - SOC Analyst

Dwell Technologies Sdn. Bhd. • Kuala Lumpur

On-site
MYR 54,000 - 90,000
Security Operations Center Lead
Security Operations Center Lead

Altera • Bayan Lepas

On-site
MYR 180,000 - 280,000
L2 SOC Analyst / Engineer
L2 SOC Analyst / Engineer

Insyghts Security Sdn Bhd • Iskandar Puteri

On-site
MYR 60,000 - 100,000
Manager Security Operation Centre
Manager Security Operation Centre

GoKardz Technologies • Kuala Lumpur

On-site
MYR 120,000 - 150,000