Support PLDT Group’s Cyber Threat Intelligence efforts through the collection, analysis, and dissemination of actionable intelligence to protect against emerging cyber threats. Conduct proactive threat hunting to identify potential incidents and vulnerabilities across PLDT’s environment. Collaborate closely with Internal Cybersecurity Operations, Incident Response, and other key stakeholders to integrate threat intelligence into detection, response, and broader cyber defense strategies— strengthening PLDT’s overall cyber resilience.
Threat Intelligence Gathering and Analysis
- Conduct the collection, processing, and analysis of cyber threat intelligence from internal and external sources, including OSINT, dark web monitoring, industry reports, and threat intelligence platforms. Maintain an up-to-date understanding of the threat landscape, including threat actor tactics, techniques, and procedures (TTPs) relevant to PLDT.
Proactive Threat Hunting
- Conduct proactive threat hunting activities across PLDT’s networks and systems to identify potential threats, vulnerabilities, and indicators of compromise (IOCs). Use advanced detection tools, analytics, and threat intelligence to uncover threats that may bypass traditional security monitoring. Coordinate findings with Cyber Security Operations and Incident Response teams to ensure timely validation and response.
Collaboration and Communication
- Work closely with Cyber Security Operations, Incident Response, and other stakeholders to integrate threat intelligence into detection, response, and defense strategies. Share relevant, actionable intelligence to support informed decision‑making and risk mitigation. Participate in external information‑sharing groups and industry communities to stay informed about evolving threats and best practices.
- Create clear, concise, and actionable threat intelligence reports. Provide detailed analyses of threat trends, emerging risks, and mitigation recommendations for use by security teams and senior management. Ensure findings are well documented and support strategic and operational security decisions.
Tools and Technology Management
- Utilize and support the optimization of threat intelligence tools and platforms. Ensure tools are effectively configured and integrated with other security systems, such as SIEMs and incident Page 3 response platforms. Provide feedback on tool performance and assist in evaluating new technologies that could enhance threat detection and intelligence capabilities.
- Stay current with emerging cyber threats, threat intelligence methodologies, and threat hunting techniques. Participate in ongoing training, certifications, and skill development initiatives to support continuous improvement of the threat intelligence function and enhance personal expertise.
Reporting and Metrics
- Support the tracking and reporting of key metrics to assess the effectiveness of threat intelligence operations, including detection accuracy, timeliness, and relevance. Assist in compiling reports for senior management that highlight threat trends and intelligence-driven outcomes.
Compliance and Risk Management
- Ensure all threat intelligence activities align with applicable laws, industry standards, and PLDT's internal security policies. Contribute intelligence insights to risk assessments and support compliance-related documentation as needed