Job Overview
The Security Analyst - Endpoint & Cloud Security is responsible for monitoring, triaging, and investigating security alerts across endpoints, servers, and cloud environments. The role covers end-to-end detection and response for EDR and cloud-native security tools, correlating telemetry with SIEM alerts, and coordinating remediation with asset owners to maintain a strong security posture across the organisation.
Principal Duties & Responsibilities
Endpoint Detection & Response
- Monitor and triage EDR (Endpoint Detection and Response) alerts across endpoints and servers.
- Investigate endpoint detections for malware, ransomware, and suspicious process behaviour.
- Perform host isolation and containment of compromised endpoints as per the response playbook.
- Manage EDR agent deployment, health, policy tuning, and exclusion management.
Cloud Security Monitoring & Investigation
- Respond to cloud security alerts from CSPM/CWPP and cloud-native tools (e.g. Defender for Cloud, GuardDuty).
- Monitor cloud workloads, IAM activity, and configuration drift across AWS, Azure, and GCP.
- Investigate cloud posture findings and misconfigurations and recommend remediation actions.
- Correlate EDR and cloud telemetry with SIEM alerts for end-to-end investigation.
Threat Intelligence & Vulnerability Management
- Maintain blocklists, threat intelligence indicators, and detection rules for endpoint and cloud.
- Track and report on vulnerabilities and threats affecting endpoints and cloud workloads.
- Coordinate with asset owners for remediation and patching of identified threats.
Reporting & Escalation
- Prepare daily endpoint and cloud security status reports.
- Escalate confirmed incidents to the Senior Analyst as per the escalation matrix.
Job Specification
Experience
- 6-8 years of relevant experience.
- Experience with EDR (Endpoint Detection and Response)
- Knowledge of malware, ransomware, and suspicious process behavior
- Ability to perform host isolation and containment
- Experience with EDR agent deployment and management
- Knowledge of cloud security alerts and response
- Experience with CSPM/CWPP and cloud-native tools
- Ability to monitor cloud workloads, IAM activity, and configuration drift
- Experience with SIEM alerts and correlation
- Knowledge of threat intelligence indicators and detection rules
Pay: RM6,000.00 - RM8,000.00 per month
Application Question(s):
- How many years of relevant experience do you have in endpoint and cloud security?
- Do you have hands-on experience with EDR tools (monitoring, triage, host isolation/containment)?
- Do you have experience with cloud security tools such as CSPM/CWPP, Defender for Cloud, or GuardDuty?
- Do you have experience monitoring cloud environments across AWS, Azure, or GCP?
- Do you have experience correlating alerts with SIEM tools?
- What is your expected monthly salary?
- What is your notice period?
Work Location: In person