AIA Digital+ is a Technology, Digital and Analytics innovation hub dedicated to powering AIA to be more efficient, connected and innovative as it fulfils its Purpose to help millions of people across Asia-Pacific live Healthier, Longer, Better Lives.
If you are hungry and driven to play an active role in shaping a better tomorrow, we want to hear from you. Because the work we do at AIA Digital+ makes a difference in the lives of millions of people, every day. We will equip you with the critical skills, tools and technology, and endless opportunities to learn, contribute and thrive in a dynamic and exciting environment.
If you want to shape a brighter future at AIA Digital+, please read on.
About the Role
The role of the candidate is to be a part of GIS Cybersecurity team to function as a Manager in the Cyber Threat Intelligence Team.
The role requires to proactively investigate security events to identify artifacts of a cyber-attack detect advanced threats that evade traditional security solutions, threat actor-based investigations, creating new detection methodology, support incident investigations and monitoring functions. Threat hunting includes using both manual and machine-assisted capabilities, that aims to find the Tactics, Techniques and Procedures (TTPs) of advanced adversaries.
The candidate must have a curious investigative mindset, experienced in information security, and the ability to communicate complex ideas to varied stakeholders.
• Develop, document, and maintain cyber threat hunting framework
• Hunt and identify for threat actor groups, techniques, tools and procedures (TTPs)
• Perform threat hunting through analysis of anomalous log data to detect and mitigate cyber threat activities
• Actively develop threat hunting hypothesis, translating hunt activities into an iterative process, and automating the process of hunting for cyber threats
• Review alerts generated by security monitoring tools and provide recommendation to enhance alerts for more efficient monitoring
• Provide forensic analysis of network packet captures, DNS, proxies, malware, host-based security, and application logs, as well as logs from various data sources
• Provide expert investigative support during large scale and complex security incidents
• Analysis of security incidents to enhance security monitoring and alert catalogue
• Investigate and validate suspicious events by using open-source and proprietary intelligence sources
• Document and communicate findings to an array of audiences which includes both technical and executive teams
• Continuously improving processes and use cases on security monitoring tools
• Keep up to date with information security news, adversary techniques and threat landscape
. Support day-to-day operations, ensuring efficient delivery of Cyber Threat Intel services.
. Candidate may be asked to be involved in additional supporting role for strategical work and security related projects