Cyber Defense Specialist
Technology, Data & Digital · IT Infrastructure & Security · Cybersecurity · DevOps
In short
Ericsson is looking for an experienced Cyber Defense Specialist in Shah Alam, Malaysia, to monitor, detect, investigate, and respond to cybersecurity threats. This role requires hands-on experience in SOC functions, incident response, threat intelligence, and vulnerability management, ensuring compliance with security requirements and enhancing cyber defence capabilities.
Responsibilities
- Monitor security events using SIEM, EDR, NDR, SOAR, IDS/IPS, and other platforms.
- Perform Level 2/3 incident investigation and response, including malware analysis and threat hunting.
- Investigate various cyber threats like phishing, ransomware, insider threats, and APTs.
- Analyze logs from diverse sources including servers, firewalls, cloud platforms, endpoints, databases, and network devices.
- Develop and optimize SIEM correlation rules and detection use cases.
- Lead incident triage, containment, eradication, recovery, and post-incident reviews.
- Coordinate with infrastructure, application, cloud, and network teams during security incidents.
- Maintain incident documentation, root cause analysis (RCA), and lessons learned.
- Monitor emerging cyber threats and vulnerabilities, correlating IOCs and IOAs.
- Integrate threat intelligence feeds into SOC operations and perform proactive threat hunting.
- Recommend security control improvements based on threat trends.
- Perform forensic acquisition of endpoints, servers, virtual machines, and cloud workloads.
- Support cyber investigations with law enforcement or external agencies.
- Support customers in investigations related to their respective OS.
- Assist with internal and external security audits.
- Review and maintain security policies, procedures, and standards.
- Track compliance findings and remediation activities.
- Coordinate vulnerability assessments and penetration testing, prioritizing remediation based on business risk.
- Track vulnerabilities through closure and validate security hardening across various systems.
- Support secure configuration reviews.
- Enhance SOC automation using SOAR platforms and develop security playbooks.
- Improve detection engineering using Sigma, YARA, and SIEM rules.
- Support integration of security tools through APIs and automation scripts.
- Prepare executive and technical incident reports.
- Present security findings to management and stakeholders.
- Develop SOC dashboards and KPIs.
- Conduct awareness sessions for technical teams.
- Support cyber crisis management and tabletop exercises.
Requirements
- Bachelor's degree in Computer Science, Cyber Security, Information Technology, or related discipline.
- 5–10 years of cybersecurity experience.
- Minimum 3 years in a Security Operations Center (SOC).
- Experience handling major cyber incidents.
- Experience performing forensic investigations.
- Strong understanding of compliance and audit processes.
- SIEM (Splunk, Microsoft Sentinel, QRadar, ArcSight, Elastic).
- EDR/XDR (Microsoft Defender, CrowdStrike, SentinelOne, Carbon Black).
- SOAR platforms.
- Networking knowledge: TCP/IP, DNS, HTTP/HTTPS, SMTP, VPN, Routing and Switching.
- Network packet analysis (Wireshark).
- Familiarity with threat frameworks: MITRE ATT&CK, Cyber Kill Chain, Diamond Model.
- Knowledge of ISO/IEC 27001, NIST Cybersecurity Framework (CSF), CIS Controls.
- Familiarity with local regulatory requirements (e.g., MCMC NCII, PDPA).
Desired Qualifications
- Telco network background is preferred.
- ITIL certification.
- CEH, Security +, CompTIA Security+, CCNA Security, or similar will be an advantage.
- Basic knowledge of telecommunications networks will be an added advantage.
Benefits
- Outstanding opportunity to use skills and imagination to push the boundaries of what's possible.
- Build solutions to some of the world's toughest problems.
- Challenged but not alone, joining a team of diverse innovators.
- Welcome as your unique self and celebrated for skills, talent, and perspective.
- Empowered to learn, lead, and perform at your best.
- Opportunity to shape the future of technology.
- Learn more about the typical hiring process.
- Encouraged to apply from all backgrounds to realize full potential.
- Ericsson is proud to be an Equal Opportunity Employer.
Skills
SIEMEDRNDRSOARIDS/IPSSplunkMicrosoft SentinelQRadarArcSightElasticMicrosoft DefenderCrowdStrikeSentinelOneCarbon BlackTCP/IPDNSHTTP/HTTPSSMTPVPNWiresharkMITRE ATT&CKCyber Kill ChainDiamond ModelISO 27001NIST CSFCIS ControlsMCMC NCIIPDPASigmaYARA
#cybersecurity#SOC#incident response#threat intelligence#vulnerability management#forensics#compliance#governance#SIEM#EDR#SOAR
Our purpose \nTo create connections that make the unimaginable possible.\n\nOur vision\nA world where limitless connectivity improves lives, redefines business and pioneers a sustainable future.\n\nOur values\nPerseverance, professionalism, respect and integrity.\n\nThe future is a place for purpose & vision – ours are clear, and we invite partners, customers and consumers to join us in our journey. \n\nFor a brighter future. For all. Let's #ImaginePossible
Company
EricssonJob Posted
3 days ago
Employment Type
Full Time
Work mode
On Site
Experience Level
Mid-Senior
Locations
Shah Alam, Malaysia
Qualification
Bachelor
Applicants
Be an early applicant
Similar Jobs
Microsoft
United StatesSecurity Customer Experience Engineer
Full Time Be an early applicant Posted 9 hours ago
Microsoft
United StatesSenior Security Researcher
US$120–235k/yr Full Time Be an early applicant Posted 1 week ago
Ericsson
Mexico City, MexicoSustainability Program Manager LATAM
Full Time Be an early applicant Posted 1 week ago
Microsoft
United StatesSenior Solution Engineer Security
US$106–204k/yr Full Time Be an early applicant Posted 1 week ago
Microsoft
United StatesPrincipal Security Engineer
US$143–275k/yr Full Time Be an early applicant Posted 1 week ago
Microsoft
United StatesCloud Solution Architect (CSA), Security
Full Time Be an early applicant Posted 2 weeks ago
