Setup and operating Managed Endpoint and Detection Response (MDR) program and proposing enhancement to achieve better efficiency/ effectiveness.
Operating Network Traffic Analytics (NTA) program, identification of abnormalities in client's environment.
Performs threat hunting within the clients technology environments to uncover indicators of threat activities.
Performs digital forensic preservation, legal documentation and electronic discovery for incidents and investigations.
Supports the development of tactics, techniques, and procedures in providing proactive threat hunting and analysis against the available information sources (e.g. Netflow, DNS and Firewall logs, etc.).
Supports the identification and documentation of Indicators of Compromise (IoCs).
Leverages internal and external resources to research threats, vulnerabilities and intelligence on various threat actors and exploitation tools and platforms.
Use an analytics platform to identify threats in the available information repositories.
Perform threat research to identify potential threat vectors and work with multi-disciplines to improve prevention and detection methods.
Identify gaps in an organisation's measurement metrics, telemetry and logging capabilities and propose enhancement strategies to achieve the intended outcomes.
Work with client's appointed Incident Response Management team for cyber security incidents such as data security breach, Advanced Persistent Threat (APT).
Requirements:
Bachelor's Degree in Computer Engineering, Computer Science, Cyber Security, Information Security or other equivalents
Must have either of these certifications (Microsoft Cybersecurity Architect/Microsoft Certified: Cybersecurity Architect Expert/Microsoft Security Operations Analyst)
Possess at least 3 years of working experience in managing Microsoft Azure Cloud Security & Microsoft Sentinel
Experience in consulting, including both internal and client facing experiences
Experience with research, technical and business documentation and analysis
Ability to demonstrate flexibility, initiative and innovation in dealing with ambiguous, fast-paced situations