1 день назад
Security Engineer (Blue Team)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Security Engineer (Blue Team) (EDR/UEM): Expanding endpoint security coverage, analysing security alerts, conducting threat intelligence analysis, and supporting daily SOC operations with an accent on defensive security, detection engineering, and incident response. Focus on tuning detection rules, investigating and containing threats, developing SOC playbooks, and automating routine security tasks with Python, PowerShell, or Bash.
Location: Kuala Lumpur, Malaysia
Company
operates a cybersecurity function focused on endpoint protection, security operations, threat detection, and vulnerability management.
What you will do
- Install, configure, and maintain EDR and UEM agents across company endpoints.
- Triage, analyse, and validate security alerts, distinguish true positives from false positives, and escalate confirmed threats.
- Analyse threat intelligence, ingest IOCs and TTPs, and convert relevant findings into detection rules.
- Support daily SOC operations by developing playbooks, processes, and escalation procedures.
- Tune detection rules and alert thresholds, and participate in containment, investigation, forensics, and post-incident reviews.
- Coordinate the bug bounty lifecycle, document validated vulnerabilities, maintain audit logs, and collaborate with IT and infrastructure teams on endpoint compliance.
Requirements
- At least one year of relevant experience in cybersecurity, IT operations, or a related field.
- Bachelor’s degree in Computer Science, Information Management, Information Security, or a related discipline.
- Understanding of common attack techniques and the MITRE ATT&CK framework.
- Basic knowledge of endpoint hardening, network security fundamentals, and log analysis.
- Strong analytical and problem-solving skills with attention to detail.
- Scripting skills in Python, PowerShell, or Bash for routine automation are advantageous.
Nice to have
- CompTIA Security+, CySA+, BTL1, or similar certification.
- Experience with EDR and UEM solutions such as CrowdStrike, SentinelOne, JumpCloud, or Jamf.
- Familiarity with threat intelligence platforms and IOC management.
Culture & Benefits
- Hands-on operational role within a cybersecurity team.
- Opportunity for an early-career professional to develop in defensive security.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
11 часов назад
Security Engineer (Fintech)
2 дня назад
CyberSecurity Engineer 1 (Threat Intelligence & Red Team)
84 700 - 157 300$
23 часа назад
Senior Security Analyst (Cybersecurity)
9 часов назад
Security Engineer (Cybersecurity)
7 часов назад
Infra Security Engineer
11 часов назад