jobs in TIME DotCom Berhad

Kerja Sepenuh Masa, Security Operations Center Analyst di TIME DotCom Berhad Selangor - Maukerja

Kongsi
Simpan

Lokasi Kerja

  • Shah Alam Selangor Malaysia

Penerangan Kerja

Tanggungjawab

The position reports to the Head of Group SOC.


Job Overview:

The SOC Analyst (Threat & Exposure) is responsible for proactively identifying, assessing, and reducing security exposures across the organization's technology landscape. As part of the Group Security Operations Center (GSOC), the role focuses on vulnerability management, attack surface analysis, security assessments, and security validation activities across multiple technology domains. The role helps ensure security weaknesses, misconfigurations, and control gaps are identified and addressed before they can be exploited by threat actors.


Working closely with Cybersecurity and IT teams, this role supports the continuous improvement of the organization's security posture through risk-based assessments, exposure management, and remediation validation. While expertise in every technology domain is not expected, the successful candidate should demonstrate strong analytical thinking, curiosity, adaptability, and a commitment to continuously expanding their cybersecurity knowledge and capabilities.


Roles & Responsibilities

Exposure Management

  • Identify and assess security exposures across infrastructure, network, endpoint, identity, cloud, and application environments.
  • Perform attack surface reviews to identify attack paths, security weaknesses, misconfigurations, and control gaps.
  • Analyze attack paths and potential opportunities for privilege escalation, lateral movement, unauthorized access, credential compromise, and data exposure.
  • Assess exploitability and potential business impact of excessive privileges, insecure configurations, weak controls, technology vulnerabilities, and exposed services.
  • Recommend, track, and validate remediation activities to reduce organizational cyber exposure.
  • Support adversary simulation and purple team exercises to assess security control effectiveness.


Security Validation

  • Perform technical validation of security controls to verify they are operating effectively and providing the intended protection.
  • Assess the effectiveness of preventive, detective, and responsive controls across identity, endpoint, network, cloud, and application environments.
  • Validate remediation effectiveness through targeted testing and verification activities.
  • Conduct technical reviews and validation activities to identify deviations from approved security baselines, hardening standards, and security requirements.
  • Support adversary simulation, purple team exercises, and security validation initiatives.
  • Work closely with other team members to ensure critical exposures are adequately monitored, detectable, and responsive.
  • Identify control gaps and recommend improvements to strengthen cyber resilience.


Vulnerability Management

  • Manage the vulnerability management lifecycle from discovery through remediation validation.
  • Coordinate vulnerability scanning activities across servers, endpoints, network devices, cloud environments, and applications.
  • Assess vulnerability exploitability, business impact, and remediation priority.
  • Monitor remediation progress and validate closure of identified vulnerabilities.
  • Produce vulnerability metrics, trends, and management reports.


Penetration Test & Security Assessment Coordination

  • Coordinate internal and external penetration testing and security assessment activities where required.
  • Review findings and support risk prioritization.
  • Track remediation actions and verify closure of identified findings.
  • Maintain assessment records, trends, and exposure metrics.


Reporting & Stakeholder Engagement

  • Prepare exposure management dashboards, metrics, and reports.
  • Present findings and recommendations to technology teams and management.
  • Support risk discussions and remediation prioritization activities.
  • Maintain visibility of organizational attack surface, exposure trends, and remediation effectiveness.


Your Traits

  • Possess an attacker-minded approach when assessing systems, configurations, and security controls.
  • Strong analytical and problem-solving skills with the ability to identify meaningful risks from technical findings.
  • Curious and eager to learn across multiple technology domains and cybersecurity disciplines.
  • Able to balance technical risks with business priorities and practical remediation approaches.
  • Detail-oriented and methodical in assessing security weaknesses and validating control effectiveness.
  • Strong communication and stakeholder engagement skills, with the ability to influence remediation outcomes.
  • Self-motivated with a continuous improvement mindset and passion for cybersecurity.


Your Merits

Experience

  • Minimum 5 years of cybersecurity experience in security operations, vulnerability management, security assessments, infrastructure security, cloud security, application security, or related disciplines.
  • Experience identifying security weaknesses and working with technology teams to implement remediation.
  • Experience performing security assessments, vulnerability analysis, or security validation activities.


Technical Knowledge

  • Exposure Management & Security Validation: Attack surface management, exposure management, attack path analysis, security control validation, remediation validation, adversarial thinking, and risk-based prioritization of security weaknesses.
  • Vulnerability Management & Security Assessment: Vulnerability assessment and prioritization, vulnerability lifecycle management, security assessments, security configuration reviews, hardening validation, and exposure analysis using vulnerability management and assessment platforms (e.g., Tenable, Qualys, Rapid7, Microsoft Defender Vulnerability Management).
  • Identity, Infrastructure & Cloud Security: Identity and access management security (e.g., Active Directory, Microsoft Entra ID, Okta), authentication, authorization, privileged access security, cloud security posture assessment (e.g., Microsoft Azure, AWS, Google Cloud), network security fundamentals, Linux and Windows security, and infrastructure hardening principles.
  • Application & API Security: Web application and API security concepts, OWASP Top 10, authentication and authorization controls, API security, application attack surfaces, and application security testing tools (e.g., Burp Suite, OWASP ZAP, Acunetix).
  • Security Analysis & Investigation: Log analysis, attack path reconstruction, threat-informed security assessments, security findings validation, attack simulation techniques, and security control effectiveness reviews.
  • Data Analysis, Scripting & Automation: Basic scripting and automation (e.g., PowerShell, Python, Bash), security data analysis, vulnerability data interpretation, database fundamentals (e.g., Microsoft SQL Server, MySQL, PostgreSQL), and reporting automation.



Preferred Qualifications

  • Relevant cybersecurity certifications and practical experience in security operations, vulnerability management, exposure management, cloud security, identity security, security assessment, and penetration testing would be advantageous.
  • Certifications: SC-200, SC-300, AZ-500, Security+, CySA+, CEH, CISSP, and other industry-recognized cybersecurity certifications.
  • Frameworks and methodologies: MITRE ATT&CK, MITRE D3FEND, OWASP Top 10, Threat Modeling, STRIDE, Attack Trees, Zero Trust Architecture, and CIS Benchmarks.


Success in this role will be measured by:

  • Reduction in critical and high-risk vulnerabilities.
  • Reduction in exploitable attack paths and excessive privileges.
  • Improvement in vulnerability remediation SLA compliance and reduction of overdue findings.
  • Number of critical exposures identified and remediated before exploitation.
  • Number of security control weaknesses identified through security validation activities.
  • Reduction in repeat findings from vulnerability assessments, penetration tests, and security reviews.
  • Increased maturity of Threat & Exposure Management capabilities, processes, and reporting.


Our Commitment to You

At Time, we believe great work deserves great support. Here’s what you can look forward to when you join us:

  • Comprehensive medical coverage for you and your immediate family, including outpatient care, hospitalisation, dental and optical benefits.
  • Wellness support with an annual spending account for health-related needs, alternative treatments, or even paid-up premiums for personal insurance.
  • Employee assistance during life’s big moments, from celebrations to times of bereavement.
  • Learning & growth opportunities through dedicated time for learning, access to LinkedIn Learning and rewards for upskilling.
  • Cash rewards for recognised certifications and full reimbursement for up to two approved professional memberships each year.


*Only shortlisted candidates will be notified.

Peringatan Penting

Jangan pernah kongsikan maklumat bank atau kad kredit anda semasa memohon pekerjaan. Elakkan membuat sebarang pembayaran atau mengisi survey yang tidak berkaitan. Jika ada yang mencurigakan, sila laporkan iklan pekerjaan ini segera.

Lebih Lanjut