company-logo-image

Security Analyst Level 2

ashley-avatar-image

AI-generated summary

beta

This job is for a Security Analyst Level 2 at Ensign. You might like this job because you get to track cyber threats, create reports, and help improve security systems. It’s perfect for someone who loves problem-solving and staying ahead in tech!

Undisclosed

Malaysia (Selangor), Kuala Lumpur

Job Description

Ensign is hiring !

Responsibilities

  • Monitor third party security feeds, forums, and mailing lists to gather information related to the client through automated means
  • Produce intelligence outputs to provide an accurate depiction of the current threat landscape and associated risk through the use of customer, community, and open source reporting
  • Produce actionable intelligence information for delivery to colleagues and customers in the form of technical reports, briefings, and data feeds
  • Review vulnerabilities advisories
  • Review and process threat intelligence reports
  • Perform detailed investigative works into all traffic anomalies against established, historical baselines of individual agencies. Reviewing and profiling the events of all monitored clients
  • Assess each event based on factual information and wider contextual information available
  • Review, propose and generate reports to automate or reduce low value event escalations
  • Build rules and intelligence to detect such threats and proliferate to all monitored networks
  • Implementing and devising detection method of such threats in our security operations through SIEM Rules, DB scripts etc
  • Perform periodic analysis of security events, network traffic, and logs to engineer new detection methods, or create efficiencies when available
  • Supports the development of tactics, techniques, and procedures in providing proactive threat hunting and analysis against the available information sources (e.g. Netflow, DNS and Firewall logs, etc.)
  • Assist the Security Analysts with the investigative works
  • Prepare training programme for Security Analyst and conduct knowledge sharing sessions for Security Analyst
  • Fulfil Change Requests, Service Requests and respond to internal / external enquiries with regards to detection Use Case
  • Any other tasks as assigned

Requirements

  • Degree holder with at least 5 years' of experience in related field and capacity
  • Prior experience working in a Security Operations Centre (SOC) or Computer Emergency Response Team (CERT/CIRT)
  • Possessed deep interest in open source research and critical thinking / contextual analysis abilities
  • Has proper understanding of network, apps,and server fundamentals, and be able to identify and analyze logs thoroughly by looking at the indicators
  • Has understanding of MITRE ATT&CK framework or cyber kill chain
  • Investigative and analytical problem solving skills
  • An understanding of the current vulnerabilities, response, and mitigation strategies used in cyber security
  • Related professional cyber security certification, such as GCIA, CEH, will be preferred
  • Experience with intelligence analysis processes, including Open Source Intelligence (OSINT) and closed source intelligence gathering, source verification, data fusion, link analysis, and threat actor
  • Ability to research and characterize security threats to include identification and classification of threat indicators


Job Requirements


Company Benefits

Health Benefits

Medical insurance for employees and dependents.

On-Site Meals and Snacks

Ensiders are served free bento sets every Monday and Friday.

On-Site Fitness Centre

Sweat it out in our own indoor gym, within a few walking steps from your office space.

Teach@Ensign / Brown Bag Sessions

Dive deeper into a variety of topics at Ensign’s regular knowledge-sharing sessions, taught by Ensign’s very own staff.

E-Learning Platform

Expand your knowledge in a wide range of subjects including cloud, cyber, and other technology-related courses.


Additional Info

Company Activity

Last active - few hours ago

Job Specialisation


Company Profile

Ensign Infosecurity (Malaysia)-logo-image

Ensign Infosecurity (Malaysia)

Ensign InfoSecurity, one of Asia’s largest pure play cyber security firms, formed as a result of a joint venture (JV) between Temasek and StarHub. Certis’s cyber security arm, Quann will be merged with StarHub’s Centre of Excellence and fully owned subsidiary, Accel Systems & Technologies Pte Ltd (ASTL). Quann, formerly known as e-Cop, is a Singapore-based cyber security services provider since 2000. The company...