Cyber Defense Specialist
Ericsson
- Location
- Shah Alam,Selangor Darul Ehsan,Malaysia
- Work model
- On-Site
- Level
- Mid
- Posted
- 1h ago
Skills
About this role
Grow with us As the tech firm that created the mobile world, and with more than 54,000 patents to our name, we’ve made it our business to make a mark. When joining our team at Ericsson you are empowered to learn, lead and perform at your best, shaping the future of technology. This is a place where you're welcomed as your own perfectly unique self, and celebrated for the skills, talent, and perspective you bring to the team. Are you in? Come, and be where it begins.
Job Summary
We are seeking an experienced Cyber Defence Specialist responsible for monitoring, detecting, investigating, and responding to cybersecurity threats while ensuring compliance with regulatory and organizational security requirements. The ideal candidate possesses strong hands-on experience in Security Operations Center (SOC) functions, incident response, threat intelligence, vulnerability management, and security governance. The role also requires supporting cybersecurity compliance initiatives, forensic investigations, and continuously improving the organization's cyber defence capabilities. Key Responsibilities Security Operations Center (SOC) Monitor security events using SIEM, EDR, NDR, SOAR, IDS/IPS, and other security monitoring platforms. Perform Level 2/Level 3 incident investigation and response. Conduct malware analysis and threat hunting activities. Investigate phishing, ransomware, insider threats, account compromise, and advanced persistent threats (APT). Analyze logs from servers, firewalls, cloud platforms, endpoints, databases, and network devices. Develop and optimize SIEM correlation rules and detection use cases. Lead incident triage, containment, eradication, recovery, and post-incident reviews. Coordinate with infrastructure, application, cloud, and network teams during security incidents. Maintain incident documentation, root cause analysis (RCA), and lessons learned. Threat Intelligence & Threat Hunting Monitor emerging cyber threats and vulnerabilities. Correlate Indicators of Compromise (IOCs) and Indicators of Attack (IOAs). Integrate threat intelligence feeds into SOC operations. Perform proactive threat hunting using MITRE ATT&CK techniques. Recommend improvements to security controls based on threat trends. Forensics Perform forensic acquisition of endpoints, servers, virtual machines, and cloud workloads. Support cyber investigations with law enforcement or external agencies where required. Support customer in investigation related to respective OS. Knowledge of telco network applications and interfaces. . Compliance & Governance ISO/IEC 27001 NIST Cybersecurity Framework (CSF) CIS Controls Local regulatory requirements (e.g., MCMC NCII, PDPA, sector-specific regulations) Assist with internal and external security audits. Review and maintain security policies, procedures, and standards. Track compliance findings and remediation activities. Vulnerability & Security Management Coordinate vulnerability assessments and penetration testing. Prioritize remediation based on business risk. Track vulnerabilities through closure. Validate security hardening across Windows, Linux, cloud, databases, and network devices. Support secure configuration reviews. Security Engineering & Automation Enhance SOC automation using SOAR platforms. Develop security playbooks and response procedures. Improve detection engineering using Sigma, YARA, and SIEM rules. Support integration of security tools through APIs and automation scripts. . Reporting & Communication Prepare executive and technical incident reports. Present security findings to management and stakeholders. Develop SOC dashboards and KPIs. Conduct awareness sessions for technical teams. Support cyber crisis management and tabletop exercises. Required Technical Skills Security Operations SIEM (Splunk, Microsoft Sentinel, QRadar, ArcSight, Elastic) EDR/XDR (Microsoft Defender, CrowdStrike, SentinelOne, Carbon Black) SOAR platforms . Networking TCP/IP