Accountability & Responsibility:
Coordinate activities for assisting digital product development teams during the designing, developing and testing stage for security control evaluation effectiveness.
Validate and produce threat modelling, threat detection script, threat hunting scripts, threat data enrichment and threat advisory reports and articles produced by analyst.
Collaborate with SOC in monitoring, gathering, tracking and analyzing internal and external threat environment and threat actors' objectives, tactics, techniques and procedures.
Operate the threat modelling platform, threat intelligence enrichment platform (deception technology, DAM, Mobile & Telco Sensing, TIP) and APT threat hunting platform (End Point Forensics, Database Activity Monitoring, Network Forensics).
Operationalize new and innovative techniques of discovering APT and work with partners inside and outside TNB to ensure good data sources and better detection results.
Develop, coordinate and perform system specific security control evaluation test procedure and activities for threat management effectiveness (fraud test, secure code test, customized pen-test) on operational or production system.
Assist in devising threat strategic framework formulation and implementation business case for project and business owners.
Experience Requirements:
Minimum 5 years of working experience in threat intelligence and hunting related to cyber security defense and offense field.
Proven delivered projects in digital forensics and penetration testing.
Strong programming skills in Python, LUA, GO, Bash or C/C++.
Deep understanding in Digital Forensics and Information Security Controls (SIEM, IDS/IPS, EDR, AV, DLP, PKI, IAM etc.)
Deep understanding in NIST, ISO27001, IEC62443, PMO framework.
Competent in digital forensics (OS, Network, Memory, IoT, ICS) and penetration testing.
Deep understanding of threat that targets Utility Power, Telco, Retail and ICT sectors and experienced in operationalizing Cyber-Kill-Chain, Mitre ATT&CK, NIST CSF and CIA Models.
Ability to work independently, as well as work collaboratively with teams, some of those may be geographically distributed.
Demonstrated ability to form coalition among people or disparate groups, be able to produce thorough and precise documentation and have sound decision making skills.
0 Comments