- Location
- MY
- Type
- Full-time
- Department
- Human Resources
- Experience
- 5+ years
- Closing date
- Today
- Source
- Vincere
Description
What's On Offer:
1 Year Contract
Based in KL, Malaysia
We are seeking an experienced Cyber Threat Intelligence & Threat Hunting Analyst with 5+ years of experience in threat intelligence, threat hunting, and cybersecurity operations to join our client in Kuala Lumpur, Malaysia. The role will focus on monitoring the external threat landscape, analysing threat actors and campaigns, and translating intelligence into actionable threat hunting and detection capabilities. You will work closely with SOC and security teams to identify detection gaps, develop MITRE ATT&CK-aligned use cases, and strengthen the organisation’s ability to detect and respond to emerging cyber threats.
Key Responsibilities
Threat Intelligence
- Monitor the external cyber threat landscape for emerging threats, vulnerabilities, threat actors and campaigns relevant to the organisation.
- Research and analyse threat actors, campaigns, tactics, techniques and procedures (TTPs).
- Collect, validate, enrich and assess Indicators of Compromise (IOCs) including IP addresses, domains, URLs, file hashes and other relevant indicators.
- Manage the lifecycle of threat intelligence and IOCs, including validation, prioritisation, monitoring and retirement.
- Produce tactical and executive-level threat intelligence advisories to communicate emerging threats, potential impact and recommended actions.
- Support security teams in prioritising detection and response activities based on threat intelligence and risk.
Threat Hunting
- Conduct proactive, intelligence-driven and hypothesis-driven threat hunts across the organisation's environment.
- Develop threat hunting hypotheses based on current intelligence, adversary behaviours and MITRE ATT&CK techniques.
- Analyse security telemetry and identify potential indicators of compromise, anomalous behaviour and previously undetected threats.
- Document threat hunting methodologies, findings, investigative evidence and outcomes.
- Recommend improvements to security monitoring and detection capabilities based on hunting results.
Detection & SOC Integration
- Develop and maintain MITRE ATT&CK-aligned detection use cases based on identified threats and adversary TTPs.
- Identify gaps in existing security monitoring and detection coverage.
- Work closely with SOC, detection engineering and incident response teams to operationalise new intelligence and detection capabilities.
- Translate threat intelligence and hunting findings into actionable detection requirements.
- Support the continuous improvement of security monitoring, detection and response processes.
Required Skills & Experience
- 5+ years of experience in Cyber Threat Intelligence, Threat Intelligence, Threat Hunting or a closely related cybersecurity function.
- Strong hands-on experience in threat hunting.
- Strong understanding of MITRE ATT&CK Framework, including adversary tactics, techniques and procedures.
- Experience analysing threat actors, campaigns and TTPs.
- Hands-on experience with IOC validation, enrichment and lifecycle management.
- Experience producing threat intelligence reports, advisories and executive-level security briefings.
- Experience developing or contributing to threat detection use cases.
- Experience identifying detection gaps and working with SOC teams to improve detection coverage.
- Strong understanding of security operations, incident response and defensive security concepts.
- Strong analytical, investigative and technical research skills.
- Relevant Cyber Threat Intelligence (CTI) certification is preferred.
Nice-to-Have
- Experience with SIEM platforms such as Microsoft Sentinel, Splunk, QRadar or Elastic.
- Experience with EDR/XDR platforms such as Microsoft Defender, CrowdStrike or SentinelOne.
- Experience with Threat Intelligence Platforms such as Recorded Future, Anomali, ThreatConnect or MISP.
- Experience with threat hunting/query languages such as KQL, SPL or equivalent.
- Knowledge of detection engineering and security analytics.
- Relevant certifications such as GIAC Cyber Threat Intelligence (GCTI) or equivalent.