Requirements:
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Computer/Network Engineering, or a related discipline, with a CGPA of 3.00 and above, MUET Band 4 or equivalent, and relevant cybersecurity certifications being an advantage.
- 1 to 3 years of hands-on experience in security operations, SOC, or infrastructure/security engineering, including experience with EDR/XDR, DLP, DSPM, SIEM platforms, vulnerability management tools, and incident handling.
- Strong knowledge of detection and response operations, alert triage, threat hunting, vulnerability management, and remediation tracking across cybersecurity environments.
- Understanding of networking, firewall, endpoint, email, and cloud security concepts, with scripting or automation skills and the ability to produce clear technical reports and documentation.
- Strong analytical and problem-solving skills, with the ability to remain calm, structured, and effective when managing security incidents and operational challenges.
- Ability to work closely with MSPs and vendors, provide on-call support when required, maintain high integrity and confidentiality, and pursue advanced cybersecurity certifications for continuous professional development.
Job Responsibilities:
1. Security Platform Management
- Manage, operate, and tune the Managed Extended Detection & Response (MxDR) platform, monitor detections, coordinate with the service provider, and drive response actions and threat hunting.
- Manage and operate the Data Loss Prevention (DLP) platform, including policy configuration, alert triage, and monitoring of data egress and exfiltration activities.
- Manage and operate the Data Security Posture Management (DSPM) platform, including data discovery, classification, posture monitoring, and remediation of exposed sensitive data.
- Maintain platform health, licensing, integrations, and configuration baselines across all security platforms.
2. Vulnerability Management
- Conduct quarterly internal vulnerability assessment (VA) scans, analyze results, prioritize risks, and prepare scan reports.
- Track remediation of identified vulnerabilities with system owners through to closure.
- Support annual third-party Vulnerability Assessment and Penetration Testing (VAPT) activities and validate remediation efforts.
3. Incident Response & Security Operations
- Support operational first-response activities, including triage, containment, eradication, and recovery, while escalating decisions to the Cybersecurity Manager as required.
- Support the CSIRT technical lead under the CSIRP by assisting with evidence preservation and technical investigations.
- Operate and monitor network, endpoint, and email security controls in collaboration with the Managed Service Provider (MSP).
- Monitor threat intelligence and implement security hardening measures.
4. Secure Change & Development Support
- Implement approved security-related changes and hardening activities.
- Perform security testing and secure configuration reviews for system releases and development initiatives before go-live.
5. Data Privacy (PDPA) Support
- Use DSPM solutions to discover and classify personal data supporting the Record of Processing Activities (ROPA).
- Configure and manage DLP controls to enforce PDPA-compliant data handling practices.
- Support technical breach investigations and containment activities for the Data Protection Officer (DPO).
6. Special Duties
- Assume operational cybersecurity responsibilities currently carried out on an interim basis by the Cybersecurity Manager.
- Provide on-call support for security incidents outside normal working hours when required.