Jobs Companies Ensign InfoSecurity L2 - Security Analyst

À propos de ce poste L2 - Security Analyst chez Ensign InfoSecurity

Ensign InfoSecurity · Sur site · Malaysia (Kuala Lumpur)

Ensign is hiring !

As a Level 2 Security Analyst in a Managed Security Service Provider (MSSP) environment, you will serve as an advanced escalation point for Tier 1 analysts, handling complex alerts and security incidents across multiple client environments. Your primary responsibility is to investigate threats in-depth, guide incident response efforts, enhance detection capabilities, and ensure clients are protected with timely and accurate responses. This role demands strong technical, analytical, and communication skills to succeed in a fast-paced, multi-tenant SOC.

Key Responsibilities:

Analyze and respond to escalated alerts from Tier 1 analysts across multiple clients.

Conduct in-depth investigations using SIEM, EDR, NDR, firewall logs, and other security tools.

Perform malware analysis, log correlation, and network traffic analysis to identify attack vectors.

Execute containment, eradication, and recovery procedures using predefined runbooks and playbooks.

Escalate and coordinate with Level 3 analysts or incident response teams for high-severity incidents.

Provide technical guidance, support, and mentoring to Tier 1 analysts.

Identify gaps in detection capabilities and recommend improvements in correlation rules, tuning, and alerts.

Support proactive threat hunting initiatives based on IOCs, TTPs, and contextual threat intelligence.

Monitor external threat intelligence feeds and correlate them with client telemetry to identify potential risks.

Maintain clear and accurate documentation of all investigations, actions taken, and incident outcomes.

Contribute to the continuous improvement of SOC processes, including the development of SOPs, playbooks, and runbooks.

Ensure all activities are performed in compliance with client-specific SLAs, internal policies, and applicable regulatory standards.

Participate in client-specific onboarding activities and ensure monitoring tools are correctly configured.

Join incident review meetings and provide root cause analysis and post-incident reporting when required.

Handle shift handovers with detailed summaries and ensure continuity of investigations and tasks.

Participate in internal knowledge-sharing sessions and contribute to SOC-wide initiatives and improvements.

Requirements:

Education & Experience:

Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or related field—or equivalent work experience.

2–4 years of experience in a Security Operations Center or similar cybersecurity environment.

Experience working in an MSSP or multi-tenant environment is highly desirable.

Technical Skills:

Strong experience with SIEM platforms (e.g., Splunk, Sentinel, QRadar).

Hands-on experience with EDR tools (e.g., CrowdStrike, SentinelOne, Microsoft Defender).

Familiarity with NDR and SOAR platforms is a plus (e.g., Darktrace, Corelight, Cortex XSOAR).

Strong understanding of networking protocols, log analysis, and system administration (Windows/Linux).

Knowledge of malware behaviors, phishing techniques, and MITRE ATT&CK framework.

Experience with scripting and automation tools (e.g., Python, PowerShell) is a plus.

Familiarity with case management tools (e.g., Jira, ServiceNow, TheHive).

Certifications (preferred):

CompTIA Security+, CySA+, or equivalent.

GIAC certifications (e.g., GCIH, GCIA, GCFA).

CEH, or vendor-specific certifications (e.g., Microsoft SC-200, CrowdStrike CCFR).

Key Competencies:

Strong analytical and problem-solving skills.

Excellent written and verbal communication—especially in client-facing documentation and briefings.

Ability to handle multiple investigations and prioritize effectively under pressure.

Customer-centric mindset with attention to SLA adherence and service quality.

Collaborative, team-oriented, and proactive with continuous learning attitude.

Shift Expectations:

Participation in shift rotations (24/7 support model, if applicable), including weekends and public holidays.

On-call support may be required depending on client SLAs and incident severity.

Prêt à postuler chez Ensign InfoSecurity ?
Postuler chez Ensign InfoSecurity

À propos de Ensign InfoSecurity

About Ensign InfoSecurity Ensign InfoSecurity is the largest pure-play cybersecurity service provider in Asia. The company is headquartered in Singapore. We specialise in the provision of these services; cybersecurity advisory and assurance, implementation and management of advanced cybersecurity controls, cybersecurity monitoring, threat hunting, and incident response. Underpinning these competencies is in-house research and development in cybersecurity. What Makes Ensign Special? We are a technology company with warmth and soul. We are ambitious, propelled by our vision to be the cyber defender of choice, and fueled by the dedication and camaraderie of individuals who are eager to make a d

Voir tous les emplois chez Ensign InfoSecurity →

Emplois similaires

Ensign InfoSecurity
L2 Security Analyst
Ensign InfoSecurity
⚡ Postuler tôt Malaysia (Kuala Lumpur) Sur site
● Nouveau 👁 Vu ✓ Postulé il y a 1 sem.
Ensign InfoSecurity
Security Analyst L3
Ensign InfoSecurity
⚡ Postuler tôt Malaysia (Kuala Lumpur) Sur site
● Nouveau 👁 Vu ✓ Postulé il y a 1 sem.
Ensign InfoSecurity
Senior Security Analyst (SOC Level 3)
Ensign InfoSecurity
⚡ Postuler tôt Malaysia (Kuala Lumpur) Sur site
● Nouveau 👁 Vu ✓ Postulé il y a 4 mois
HP
HR Technology Security Analyst
HP
⚡ Postuler tôt Tlaquepaque, Jalisco, Mexico Sur site
● Nouveau 👁 Vu ✓ Postulé il y a 4 h
HP
Cybersecurity Threat Detection & Response Engineer
HP
⚡ Postuler tôt Sant Cugat del Valles, Barcelo... Sur site
● Nouveau 👁 Vu ✓ Postulé il y a 4 h
HP
Cybersecurity Analyst - Detection and Response
HP
⚡ Postuler tôt Bengaluru, Karnataka, India Sur site
● Nouveau 👁 Vu ✓ Postulé il y a 4 h
MA
Oliver Wyman Vector - DevOps Engineer (AWS & Cybersecurity)
Marsh
⚡ Postuler tôt Atlanta - Hartsfield Sur site $90,000–$115,000
● Nouveau 👁 Vu ✓ Postulé il y a 7 h
Solventum
SAP Security Senior Analyst
Solventum
⚡ Postuler tôt IN, Bangalore Sur site
● Nouveau 👁 Vu ✓ Postulé il y a 7 h
Anduril Industries
Counterintelligence & Security Risk Analyst
Anduril Industries
⚡ Postuler tôt Costa Mesa, California, United... Sur site $129,000–$171,000
● Nouveau 👁 Vu ✓ Postulé il y a 12 h

Inscrivez-vous pour des suggestions adaptées aux emplois que vous ouvrez et aux recherches que vous enregistrez.

Plus d’emplois chez Ensign InfoSecurity

Voir tous les emplois chez Ensign InfoSecurity →

Postuler maintenant
🤖

Doucement — un instant

JobsRadar a été conçu pour de vraies personnes qui traversent une période difficile dans leur recherche d’emploi — pas pour des requêtes automatisées. Vous cliquez beaucoup trop vite et vous êtes maintenant temporairement bloqué.

Revenez plus tard. Si vous cherchez réellement un emploi, nous sommes de votre côté — agissez simplement comme un être humain.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Prenez une longueur d’avance dans votre recherche d’emploi.

Rejoignez notre canal Telegram pour ce qui vous aide à décrocher le poste — références salariales, le pouls hebdomadaire du marché et les annonces de nouveautés. Pas de spam, que du signal.

Rejoindre le canal — c’est gratuit