jobs in Maybank

Maybank Hiring! Full Time SOC Cyber Threat Intelligence Analyst I IT Security in Federal Territory - Ricebowl

SOC Cyber Threat Intelligence Analyst I IT Security

KL City, Federal Territory

Share
Save

Working Location

  • Kuala Lumpur Federal Territory Malaysia

Job Description

Responsibilities

Job Purposes


  • The SOC Cyber Threat Intelligence Analyst identifies, analyses and communicates cyber threats that may affect the organisation, its customers, suppliers and digital services.
  • The role supports 24/7 CTI operations by validating indicators, profiling threat actors, monitoring emerging threats and vulnerabilities, and producing actionable intelligence for SOC monitoring, incident response, threat hunting, vulnerability management and management decision-making.
  • By converting internal and external threat information into timely monitoring, hunting, response and remediation actions, the role strengthens cyber resilience and protects critical services, data and operations.


Job Responsibilities


  • Monitor approved internal and external intelligence sources.
  • Validate, enrich, prioritise and distribute IOCs, IOAs and relevant threat information.
  • 24/7 Track intelligence items through action, closure or expiry.
  • Track cybercriminal, ransomware, hacktivist and nation-state activity relevant to financial services.
  • Develop profiles covering motives, campaigns, TTPs, IOCs and infrastructure.
  • Assess likely intent, capability and relevance to the organisation.
  • Translate threat information into testable hunt hypotheses.
  • Work with SOC and detection engineering to recommend analytics and use cases.
  • Identify detection and telemetry gaps.
  • Support CSIRT, incident response and forensics during investigations.
  • Correlate actors, campaigns, tools, infrastructure and observed activity.
  • Assess objectives, likely next actions and affected scope.
  • Monitor newly disclosed and actively exploited vulnerabilities.
  • Assess exploitation evidence, threat actor use, affected technologies and business relevance.
  • Support risk-based remediation prioritization.
  • Validate phishing sites, stolen credentials, stolen cards and fake mobile applications.
  • Identify affected stakeholders and route intelligence through approved processes.
  • Track response, takedown or closure status.
  • Prepare daily summaries, weekly reports, monthly threat reports, threat control status reports advisories and executive briefings.
  • Tailor content to operational, technical and management audiences.
  • Track acknowledgement and operational use of intelligence.
  • Execute the CTI lifecycle: collection, processing, analysis, distribution, tracking, reporting and housekeeping.
  • Maintain repositories, source records, confidence ratings and handling requirements.
  • Support process automation, training, role-play and weekly status reviews.


Job Requirements

  • Degree in IT or a related discipline such as Computer Science, Cybersecurity, Information Assurance, Digital Forensics, Network Engineering or Data Analytics.
  • 3 to 7 years of cybersecurity experience.
  • Experience in CTI, SOC operations, incident response, threat hunting, vulnerability intelligence or digital forensics.
  • Banking, financial services or multi-entity operational experience is preferred.
  • GIAC Cyber Threat Intelligence (GCTI), GCIH, GCFA, CISSP, CTIA, CompTIA Security+, or a relevant CREST threat-intelligence certification.
  • Equivalent practical experience may be considered in place of certification.
  • Cyber threat intelligence analysis and structured analytic techniques.
  • IOC, IOA, infrastructure, malware and campaign analysis.
  • Threat actor profiling and MITRE ATT&CK mapping.
  • Threat-hunting hypothesis development and intelligence-led detection.
  • Vulnerability intelligence and active-exploitation assessment.
  • OSINT collection, source evaluation, confidence assessment and handling discipline.
  • Working knowledge of SIEM, EDR, SOAR, threat-intelligence platforms and case-management tools.
  • Proficiency in clear intelligence writing, stakeholder briefings and executive summaries.
  • Ability to manage time-sensitive tasks in a 24/7 or on-call environment, where applicable.
  • Good teamwork, stakeholder management, ownership and continuous-learning mindset.
  • Shell scripting or automation of simple tasks using Perl, Python, or Ruby.
  • Developing, extending, or modifying exploits, shellcode or exploit tools is a bonus.
  • Reverse engineering malware, data obfuscators, or ciphers.

Important Information

Never provide your bank or credit card details when applying for jobs. Do not transfer any money or complete unrelated online surveys. If you see something suspicious, Report this Job ad.

Learn More