
Security Operation Center (SOC)
Digital Tech Asia
- Kontrak
- On-site • Jakarta Selatan
- Rp6.000.000 – 12.000.000
Tidak Perlu Sign Up!
Deskripsi Pekerjaan
Position Purpose and Description
This position exists to detect and respond to security incidents, breaches, indicators of compromise, etc., in regard to data, networks, devices, cloud platforms, and business systems across the organization.
The primary role of the Security Operation Center (SOC) Analyst is to monitor the organization’s IT infrastructures for security threats and safeguard of the company's digital assets, by proactive threat hunting, detection engineering, etc.
The SOC Analyst will also assist during an incident response to ensure all in scope assets which have been, or currently are in the process of being attacked and/or compromised are properly protected.
Expected Outcomes & Actions – Weighting
THREAT PREVENTION (60%)
- Conduct a preliminary analysis of suspicious files and network traffic to identify malware and determine its capabilities and potential impact.
- Proactive threat hunting to determine if there are ongoing attacks, indicators of compromise, insider threats, etc. that might have evaded automated detection across the organization and flag any missing alerts and/or triggers to Security Analyst.
- Monitor network traffic to detect and respond to threats immediately as they occur.
- Engage in malware analysis, reverse engineering of binary/executable files, etc. using the required tools and techniques.
- Research the organization's network structures, computer systems, etc. and flag any gaps in visibility.
- Actively tracking possible supply-chain attacks and security alerts feeds.
THREAT OPERATIONS (20%)
- Provide effective detection engineering (configuration and testing of alerts, SIEM rules review, SOAR/Automated response, etc.)
- Support Red Team efforts when performing internal and external security pentesting to ensure we have visibility on these attacks.
- Support and participate in security simulations and Red Team exercises.
- Recognize and flag security flaws or errors.
- Keep updated on latest technologies, infrastructure changes, business system and platform changes, modifications to cloud platforms and organization’s implementations.
THREAT RESPONSE (20%)
- Participate in incident response meetings in collaboration with various teams (such as Legal, GTS, departmental leadership).
- Assist with computer and network forensics investigations when required.
- Provide effective and timely insider threat response and investigation.
- Assist with security incident response reports (for security incidents, threat hunting results, insider threat activities, etc.) including a timeline, root cause and findings.
Kualifikasi
Requirements and Qualifications
- Undergraduate degree in information systems, or computer science.
- Three to five years of experience working with technical security.
- Deep-seated experience with desktop and server operating systems.
- Extensive application support experience.
- Understanding of web development, HTTP, HTML, and application security
- Certified Incident Handler (E|CIH, eCIR, etc).
- Experience with SIEM solutions (preferably Exabeam and SQL server).
- Sound knowledge of computer hardware, operating systems, networking, intrusion detection systems, firewalls, vulnerability scanners, etc.
- Understanding of APIM/API
- Understanding of Cloud environments: external (i.e. snowflake/APPIAN), internal (i.e. Azure, AWS) and 3rd party cloud solutions.
- Strong written and oral communication skills in English. Additional language is an asset.
- Ability to present ideas in user-friendly language.
- Ability to effectively prioritize and execute tasks in a high-pressure environment.
- Knowledge of Ethical hacking skills.
- Strong Analytical skills.
- Capable of taking initiative
- Good interpersonal communication skills
Tips Menjaga Diri
Perusahaan dan Lowongan di Dealls tidak meminta data pribadi, informasi rekening, atau pungutan ketika melamar. Hindari juga lowongan Google Form / Grup Telegram tanpa keabsahan yang jelas.
We are an innovative, collaborative enterprise, helping customers to continuously improve their Operational Efficiency and Business Productivity through our IT solutions and Process enhancements. We are providing a range of software solutions to a worldwide client base making business successful through enhancing the performance and profitability of business processes. We Design, Develop, Implement and Integrate Business Applications.