Are you ready to shape a better tomorrow? AIA Digital+ is a Technology, Digital and Analytics innovation hub dedicated to powering AIA to be more efficient, connected and innovative as it fulfils its Purpose to help millions of people across Asia-Pacific live Healthier, Longer, Better Lives.
Role Summary
The candidate will serve as a Senior Manager in the Cyber Threat Intelligence Team within the GIS Cybersecurity group. The role focuses on proactively investigating security events, identifying artifacts of cyber‑attacks, detecting advanced threats, and supporting incident investigations.
Key Responsibilities
- Investigate security events to identify artifacts of a cyber‑attack and detect advanced threats that evade traditional security solutions.
- Conduct threat actor‑based investigations and create new detection methodologies.
- Support incident investigations and monitoring functions, including forensic analysis of network packet captures, DNS logs, proxy logs, malware artifacts, host‑based logs, application logs, and other relevant data sources.
- Develop, document, and maintain the Cyber Threat Hunting Framework.
- Perform threat hunting through analysis of anomalous log data to detect and mitigate cyber threats.
- Develop threat hunting hypotheses, translate hunting activities into an iterative process, and automate threat hunting activities where possible.
- Review alerts generated by security monitoring tools and recommend enhancements to improve monitoring efficiency.
- Analyze security incidents and recommend enhancements to security monitoring and alert catalogs.
- Investigate and validate suspicious events using open‑source and proprietary intelligence sources.
- Document and communicate findings effectively to technical and executive audiences.
- Continuously improve processes, use cases, and capabilities within security monitoring tools.
- Stay current with information security news, threat landscapes, emerging adversary techniques, and cyber threat intelligence trends.
- Support day‑to‑day Cyber Threat Intelligence (CTI) operations and ensure efficient service delivery.
- Participate in strategic initiatives, security‑related projects, and additional support activities as required.
Experience and Knowledge
- Minimum of 5 years of experience in a technical cybersecurity role, specifically in Cyber Threat Intelligence, Cyber Threat Hunting, Purple Teaming, or Red Teaming.
- Experience researching and integrating Cyber Threat Intelligence findings into threat hunting workflows.
- Strong knowledge and practical experience with the MITRE ATT&CK Framework, Cyber Kill Chain Model, and Diamond Model.
- Proficiency in using Threat Intelligence Platforms (TIPs) and Open‑Source Intelligence (OSINT) tools.
- Understanding of malware analysis, threat actor behaviors, network protocols and applications.
- Experience with incident response processes, including detection of advanced threats and adversaries, log analysis, and malware triage.
- Strong understanding of network protocols, system vulnerabilities, and detection signature development using YARA and SNORT.
Certifications
- GCTI (GIAC Cyber Threat Intelligence)
- CCIP
- CIA
- Other relevant cybersecurity certifications
Key Deliverables
- Threat Advisories and Intelligence Reports for executive-level briefings.
- Executive‑level security briefings for senior management in a timely manner.