JOB SUMMARY
- This role supports the organization's cybersecurity monitoring, threat detection, incident response, and cyber resilience activities by monitoring security events, investigating cybersecurity incidents, analyzing emerging threats, and coordinating response activities.
- The role is responsible for supporting security monitoring operations, cyberthreat intelligence activities, cybersecurity incident management, cyber crisis preparedness, and security event analysis. It also assists in preparing management reporting, coordinating incident investigations, and collaborating with stakeholders to strengthen the organization's cyber resilience and security posture.
KEY DUTIESAND RESPONSIBILITIES
Main roles and responsibilities
Security Monitoring &Cyber Defence
- Monitor, review, and manage cybersecurity alerts, events, incidents, and escalations generated through internal and external cybersecurity monitoring capabilities, including SIEM, SOC, and other security monitoring platforms.
- Perform or coordinate the identification, triage, investigation, and escalation of suspicious activities and cybersecurity threats.
- Review security eventtrends and threat patterns to identify emerging risks, operational issues, and opportunities for improvement.
- Support continuous improvement of security monitoring processes, detection capabilities, use cases, and operational procedures.
Cybersecurity Incident Management &Response
- Lead and coordinate cybersecurity incident investigations and response activities throughout the incident lifecycle.
- Recommend and coordinate containment, remediation, recovery, and corrective actions with relevant stakeholders.
- Coordinate with internal teams, service providers, and third parties to ensure timely incident response and resolution.
- Prepare incident reports, management updates, lessons learnt, and post-incident reviews.
- Monitor remediation progress, track closure of corrective actions, and support continuous improvement of incident response processes and plans.
Security Event Analysis & Investigation
- Conduct analysis of security events, indicators of compromise, and potential cybersecurity incidents.
- Correlate event information from multiple sources to support investigations and incident response activities.
- Assist in identifying root causes, attack vectors, and controlimprovement opportunities arising from security incidents.
Cyber Crisis Preparedness &Resilience
- Support cyber drill simulations, tabletop exercises, and incident response testing activities.
- Participate in cybercritic preparedness activities and document observations, lessons learned, and improvement actions.
- Support continuous improvement of incident response procedures and operational readiness.
- Monitor emergingcyber threats, vulnerabilities, and threat landscape trends.
Collaboration & Advisory
- Collaborate with internal and external stakeholders, including Infrastructure, Network, Cloud, Application, Operational Technology, and third-party service providers during investigations and incident response activities.
- Support the implementation of cybersecurity operational improvements arising from incidents, assessments, and threat intelligence activities.
- Work closely with Policy, Compliance, Risk, and business functions to strengthen organisational cybersecurity capabilities and resilience.
Other roles and responsibilities:
(Do not delete, mandatory to carry out these roles and responsibilities)
Compliance with ISO Clause5.3 Organisational roles, responsibilities and authority
- Always adhere to Air Selangor Integrated Management System(AIMS) and HSE policy and involvement in implementing the Management System.
- Ensure the objective/KPI are established in line with the Company's contexts, strategic direction, and purpose.
- Aware, understand and manage key risks, hazards, and aspects of your work activities.
- Acknowledge your right not to conductany work deemed to be harmful to your health and safety
- Aware and understand your roles and responsibility to provide support during the execution of Emergency Response Plan (ERP) and Business Continuity Plan (BCP) during crisis/emergency, ensuring the continuation of water supply to the consumer at highest quality and providing the best service and customer experience.
- Aware and understand the asset criticality in the operational activities and ensure all assets are maintained in good working conditions.
- Aware and understand the confidentiality, availability, and integrity of information assets under your custodian.
- Aware and understand the whistle-blower policy and carry out daily job activity with full integrity
- Practice SACRED personality while carrying out daily job activity, which includes:
- Safety Conscious
- Agile
- Creative
- Reliable
- Efficient
Minimum Qualifications
- Bachelor’s degree in Cybersecurity, IT, Information Systems or equivalent technical or professional qualification.
- 3 to 7 years of relevant cybersecurity experience, preferably covering the majority of the key duties and responsibilities described in this role.
- Interpersonal skills: open minded, ability to operate within business organizations through social communication and interactions.
- Problem solving skills: Can get to the root of the problem, objectively identify, analyse and solveproblems that means being solution oriented.
- Communication skills: Ability to express clear articulate and encourage open communication. Effective interpersonal presentation and interpersonal skills.
- Listening skills: Patient and attentive.
- Public Relations skills: Project and market positiveproactive image of the team.
- Collaboration skills: Build close relationships with all levels and a strong team player