Security Analyst L2

Ensign InfoSecurity

Selangor

Hybrid

MYR 70,000 - 110,000

Full time

4 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Ensign InfoSecurity in Malaysia is seeking an experienced security professional to monitor, investigate and report on threat activity for multiple clients. You will analyze network logs, security events and open-source information to identify risks and generate actionable intelligence.

A strong background in SOC/CERT/CIRT, MITRE ATT&CK familiarity, and ability to communicate findings in technical reports and briefings is essential.

Qualifications

  • Degree holder with at least 5 years' of experience in related field and capacity.
  • Experience in a Security Operations Centre (SOC) or CERT/CIRT.
  • Strong interest in open source research and contextual analysis abilities.
  • Understanding of networks, apps, and servers; ability to analyze logs.
  • Familiarity with MITRE ATT&CK or cyber kill chain.
  • Investigative and analytical problem solving skills.
  • Knowledge of vulnerabilities, response, and mitigation in cyber security.
  • Certifications such as GCIA, CEH are preferred.
  • Experience with OSINT and closed source intelligence processes.
  • Ability to research and characterize security threats and indicators.

Responsibilities

  • Monitor third party security feeds, forums, and mailing lists to gather information related to the client through automated means.
  • Produce intelligence outputs to provide an accurate depiction of the current threat landscape and associated risk through the use of customer, community, and open source reporting.
  • Produce actionable intelligence information for delivery to colleagues and customers in the form of technical reports, briefings, and data feeds.
  • Review vulnerabilities advisories.
  • Review and process threat intelligence reports.
  • Perform detailed investigative works into all traffic anomalies against established baselines of individual agencies.
  • Assess each event based on factual information and wider contextual information available.
  • Review, propose and generate reports to automate or reduce low value event escalations.
  • Build rules and intelligence to detect threats and proliferate to all monitored networks.
  • Implement detection methods in SIEM Rules, DB scripts etc.
  • Periodic analysis of security events, network traffic, and logs to engineer new detection methods.
  • Support development of tactics, techniques, and procedures for proactive threat hunting and analysis.
  • Assist Security Analysts with investigative works.
  • Prepare training programmes for Security Analysts and conduct knowledge sharing sessions.
  • Fulfil Change Requests and Service Requests and respond to inquiries regarding detection Use Case.

Skills

Analytical thinking
Open source research
Critical thinking
Log analysis
Threat hunting
Investigative skills

Education

Degree holder
GCIA/CEH certifications preferable

Tools

MITRE ATT&CK framework

Job description

  • Monitor third party security feeds, forums, and mailing lists to gather information related to the client through automated means
  • Produce intelligence outputs to provide an accurate depiction of the current threat landscape and associated risk through the use of customer, community, and open source reporting
  • Produce actionable intelligence information for delivery to colleagues and customers in the form of technical reports, briefings, and data feeds
  • Review vulnerabilities advisories
  • Review and process threat intelligence reports
  • Perform detailed investigative works into all traffic anomalies against established, historical baselines of individual agencies. Reviewing and profiling the events of all monitored clients
  • Assess each event based on factual information and wider contextual information available
  • Review, propose and generate reports to automate or reduce low value event escalations
  • Build rules and intelligence to detect such threats and proliferate to all monitored networks
  • Implementing and devising detection method of such threats in our security operations through SIEM Rules, DB scripts etc
  • Perform periodic analysis of security events, network traffic, and logs to engineer new detection methods, or create efficiencies when available
  • Supports the development of tactics, techniques, and procedures in providing proactive threat hunting and analysis against the available information sources (e.g. Netflow, DNS and Firewall logs, etc.)
  • Assist the Security Analysts with the investigative works
  • Prepare training programme for Security Analyst and conduct knowledge sharing sessions for Security Analyst
  • Fulfil Change Requests, Service Requests and respond to internal / external enquiries with regards to detection Use Case
  • Any other tasks as assigned
Requirements
  • Degree holder with at least 5 years' of experience in related field and capacity
  • Prior experience working in a Security Operations Centre (SOC) or Computer Emergency Response Team (CERT/CIRT)
  • Possessed deep interest in open source research and critical thinking / contextual analysis abilities
  • Has proper understanding of network, apps,and server fundamentals, and be able to identify and analyze logs thoroughly by looking at the indicators
  • Has understanding of MITRE ATT&CK framework or cyber kill chain
  • Investigative and analytical problem solving skills
  • An understanding of the current vulnerabilities, response, and mitigation strategies used in cyber security
  • Related professional cyber security certification, such as GCIA, CEH, will be preferred
  • Experience with intelligence analysis processes, including Open Source Intelligence (OSINT) and closed source intelligence gathering, source verification, data fusion, link analysis, and threat actor
  • Ability to research and characterize security threats to include identification and classification of threat indicators
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Specialist - Security Operation Analyst (L2)
Senior Specialist - Security Operation Analyst (L2)

Commerz Global Service Solutions • Petaling Jaya

On-site
MYR 80,000 - 120,000
Senior Security Analyst
Senior Security Analyst

Logicalis Asia Pacific • Kuala Lumpur

On-site
MYR 80,000 - 100,000
L2 SOC Analyst
L2 SOC Analyst

Pride Global • Selangor

On-site
MYR 60,000 - 110,000
Cybersecurity Analyst L2/L3
Cybersecurity Analyst L2/L3

Tech Staffing • Kuala Lumpur

On-site
MYR 90,000 - 150,000
SOC Analyst
SOC Analyst

Getronics • Kuala Lumpur

On-site
MYR 60,000 - 120,000
L2 SOC Analyst – SIEM
L2 SOC Analyst – SIEM

S SQUAD SDN. BHD. • Labuan

On-site
MYR 60,000 - 90,000
Senior SOC Analyst
Senior SOC Analyst

Pride Global • Selangor

On-site
MYR 120,000 - 180,000
Information Technology Security Analyst
Information Technology Security Analyst

Lotus's Malaysia • Kuala Lumpur

On-site
MYR 90,000 - 150,000
L2 SOC Analyst (Security Operations Center)
L2 SOC Analyst (Security Operations Center)

AGENSI PEKERJAAN TRUST RECRUIT SDN. BHD. • Selangor

On-site
MYR 120,000 - 180,000
SOC Analyst L2
SOC Analyst L2

PERSOL Workforce Solutions Malaysia Sdn Bhd • Kuala Lumpur

On-site
MYR 60,000 - 100,000