Cyber Defense Specialist

Posted 6 Hours Ago
Be an Early Applicant
Shah Alam, Petaling, Selangor, MYS
In-Office
Senior level
Cloud • Information Technology • Internet of Things • Machine Learning • Software • Cybersecurity • Infrastructure as a Service (IaaS)
We are shaping the future of digital connectivity the world relies on.
The Role
Monitor, detect, investigate, and respond to cybersecurity threats within a SOC. Perform incident response, threat hunting, malware analysis, forensics, vulnerability management, compliance support, and detection engineering. Coordinate with infrastructure and cloud teams, develop SIEM/SOAR playbooks, and produce incident reports and dashboards.
Summary Generated by Built In
Grow with us
As the tech firm that created the mobile world, and with more than 54,000 patents to our name, we've made it our business to make a mark. When joining our team at Ericsson you are empowered to learn, lead and perform at your best, shaping the future of technology. This is a place where you're welcomed as your own perfectly unique self, and celebrated for the skills, talent, and perspective you bring to the team. Are you in?
Come, and be where it begins.
Job Summary We are seeking an experienced Cyber Defence Specialist responsible for monitoring, detecting, investigating, and responding to cybersecurity threats while ensuring compliance with regulatory and organizational security requirements. The ideal candidate possesses strong hands-on experience in Security Operations Center (SOC) functions, incident response, threat intelligence, vulnerability management, and security governance.
The role also requires supporting cybersecurity compliance initiatives, forensic investigations, and continuously improving the organization's cyber defence capabilities.
Key Responsibilities
Security Operations Center (SOC)
  • Monitor security events using SIEM, EDR, NDR, SOAR, IDS/IPS, and other security monitoring platforms.
  • Perform Level 2/Level 3 incident investigation and response.
  • Conduct malware analysis and threat hunting activities.
  • Investigate phishing, ransomware, insider threats, account compromise, and advanced persistent threats (APT).
  • Analyze logs from servers, firewalls, cloud platforms, endpoints, databases, and network devices.
  • Develop and optimize SIEM correlation rules and detection use cases.
  • Lead incident triage, containment, eradication, recovery, and post-incident reviews.
  • Coordinate with infrastructure, application, cloud, and network teams during security incidents.
  • Maintain incident documentation, root cause analysis (RCA), and lessons learned.

Threat Intelligence & Threat Hunting
  • Monitor emerging cyber threats and vulnerabilities.
  • Correlate Indicators of Compromise (IOCs) and Indicators of Attack (IOAs).
  • Integrate threat intelligence feeds into SOC operations.
  • Perform proactive threat hunting using MITRE ATT&CK techniques.
  • Recommend improvements to security controls based on threat trends.

Forensics
  • Perform forensic acquisition of endpoints, servers, virtual machines, and cloud workloads.
  • Support cyber investigations with law enforcement or external agencies where required.
  • Support customer in investigation related to respective OS.
  • Knowledge of telco network applications and interfaces.

.
Compliance & Governance
  • ISO/IEC 27001
  • NIST Cybersecurity Framework (CSF)
  • CIS Controls
  • Local regulatory requirements (e.g., MCMC NCII, PDPA, sector-specific regulations)
  • Assist with internal and external security audits.
  • Review and maintain security policies, procedures, and standards.
  • Track compliance findings and remediation activities.

Vulnerability & Security Management
  • Coordinate vulnerability assessments and penetration testing.
  • Prioritize remediation based on business risk.
  • Track vulnerabilities through closure.
  • Validate security hardening across Windows, Linux, cloud, databases, and network devices.
  • Support secure configuration reviews.

Security Engineering & Automation
  • Enhance SOC automation using SOAR platforms.
  • Develop security playbooks and response procedures.
  • Improve detection engineering using Sigma, YARA, and SIEM rules.
  • Support integration of security tools through APIs and automation scripts.

.
Reporting & Communication
  • Prepare executive and technical incident reports.
  • Present security findings to management and stakeholders.
  • Develop SOC dashboards and KPIs.
  • Conduct awareness sessions for technical teams.
  • Support cyber crisis management and tabletop exercises.

Required Technical Skills
  • Security Operations
  • SIEM (Splunk, Microsoft Sentinel, QRadar, ArcSight, Elastic)
  • EDR/XDR (Microsoft Defender, CrowdStrike, SentinelOne, Carbon Black)
  • SOAR platforms

.
Networking
  • TCP/IP
  • DNS
  • HTTP/HTTPS
  • SMTP
  • VPN
  • Routing and Switching
  • Network packet analysis (Wireshark)

Threat Frameworks: MITRE ATT&CK; Cyber Kill Chain; Diamond Model
Qualifications
  • Bachelor's degree in Computer Science, Cyber Security, Information Technology, or related discipline.
  • 5-10 years of cybersecurity experience and telco network background is preferred.
  • Minimum 3 years in a Security Operations Center (SOC).
  • Experience handling major cyber incidents.
  • Experience performing forensic investigations.
  • Strong understanding of compliance and audit processes.
  • ITIL certification, CEH, Security +, CompTIA Security+, CCNA Security, or similar will be an advantage
  • Basic knowledge of telecommunications networks will be an added advantage

Why join Ericsson?At Ericsson, you'll have an outstanding opportunity. The chance to use your skills and imagination to push the boundaries of what's possible. To build solutions never seen before to some of the world's toughest problems. You'll be challenged, but you won't be alone. You'll be joining a team of diverse innovators, all driven to go beyond the status quo to craft what comes next.
What happens once you apply? Click Here to find all you need to know about what our typical hiring process looks like.Encouraging a diverse and inclusive organization is core to our values at Ericsson, that's why we champion it in everything we do. We truly believe that by collaborating with people with different experiences we drive innovation, which is essential for our future growth. We encourage people from all backgrounds to apply and realize their full potential as part of our Ericsson team. Ericsson is proud to be an Equal Opportunity Employer. learn more.
Primary country and city: Malaysia (MY) || Shah Alam
Req ID: 788892

Skills Required

  • Bachelor's degree in Computer Science, Cyber Security, Information Technology, or related discipline
  • Minimum 3 years in a Security Operations Center (SOC)
  • 5-10 years of cybersecurity experience
  • Hands-on experience with SIEM platforms (Splunk, Microsoft Sentinel, QRadar, ArcSight, Elastic)
  • Hands-on experience with EDR/XDR solutions (Microsoft Defender, CrowdStrike, SentinelOne, Carbon Black)
  • Experience with SOAR platforms and SOC automation
  • Experience performing forensic investigations and forensic acquisition of endpoints, servers, VMs, and cloud workloads
  • Experience handling major cyber incidents and Level 2/Level 3 incident response
  • Threat hunting and threat intelligence experience; familiarity with MITRE ATT&CK, Sigma, YARA
  • Strong understanding of compliance and audit processes (ISO/IEC 27001, NIST CSF, CIS Controls, local regulations)
  • Networking knowledge: TCP/IP, DNS, HTTP/HTTPS, SMTP, VPN, routing and switching, network packet analysis (Wireshark)
  • ITIL, CEH, CompTIA Security+, CCNA Security, or similar certifications
  • Basic knowledge of telecommunications networks / telco network background

What the Team is Saying

Vishal
Mayank
Granville
Sneha
Olga
Emily
Nicole
Sola
Aditi
Ericsson
Ericsson

Ericsson Compensation & Benefits Highlights

  • Healthcare Strength Health coverage options are described as broad, with multiple medical plan choices (often three) plus dental and mental health resources. U.S. materials also reference PPO and HDHP options, and some teams contribute to HSAs.
  • Retirement Support U.S. postings outline a 401(k) with an automatic 3% company contribution plus matching that reaches 4% when employees contribute 5%. This combination is repeatedly listed in role postings and characterized as strong for the sector.
  • Parental & Family Support U.S. job descriptions frequently cite up to 16 weeks paid maternity leave and 6 weeks paid parental/adoption leave at 100% pay. These benefits are positioned as exceeding many U.S. corporate policies.

Ericsson Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Stockholm
88,000 Employees
Year Founded: 1876

What We Do

Ericsson builds the digital connectivity the world relies on. Our technology underpins the mobile networks, platforms, and systems that billions of people, businesses, and societies depend on every day. We are a global leader in communications technology, delivering mobile network infrastructure, cloud software, and wireless connectivity solutions for service providers and enterprises worldwide. Our networks support connectivity across 180+ countries, helping power everyday communication as well as critical digital services at global scale. Connectivity has evolved far beyond consumer mobile use. Today, nearly 80% of the world’s population accesses the internet via mobile networks, and Ericsson is helping shape what comes next. We are advancing 5G and 5G Advanced, developing network APIs that open connectivity to the global developer ecosystem, and applying automation and AI to make networks more intelligent, efficient, and resilient. Ericsson was the first company to launch live 5G networks on five continents, and our 5G platform is now commercially live in 150+ networks across 60+ countries. We also support more than 36,000 enterprise customers, enabling secure, high-performance connectivity for industries such as manufacturing, aviation, logistics, utilities, and public safety, where reliability and performance are mission critical. Innovation is central to how we work. Ericsson has approximately 28,000 employees in research and development, backed by one of the strongest intellectual property portfolios in the industry with 60,000+ granted patents. Our engineers, researchers, and technologists work across 100+ global R&D sites, helping define how networks evolve and how digital infrastructure is built for the long term. As the world moves toward a mobile-first, AI-powered, and cloud-driven future, connectivity becomes the foundation for digital transformation across every industry. Ericsson is building that foundation, shaping the future of digital connectivity through technology that operates at global scale and supports real-world impact, today and for what comes next.

Why Work With Us

Ericsson is a place for people who want to work on technology that powers everyday life. You’ll contribute to large-scale systems used every day, tackle complex challenges in live environments, and keep developing your skills and career in your own vision.

Gallery

Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery

Ericsson Offices

Hybrid Workspace

Employees engage in a combination of remote and on-site work.

Ericsson adopts a hybrid work model globally because we know balance matters. Sometimes things are better in real life. Other times we can be more productive at home. Our hybrid approach gives you the best of both worlds.

Typical time on-site: Flexible
Company Office Image
HQEricsson HQ - Kista, Sweden
Yokohama Office
Mexico City - Mexico Head Office
Indaiatuba-SP 5G Smart Factory
Athlone Software Campus
Austin ASIC Design Center
Beijing - China Headquarters
Bellevue Office
Bengaluru Hub
Boise - Ericsson Enterprise Wireless Solutions (formerly Cradlepoint) Headquarters
Bucharest Main Site
Budapest - Ericsson House
Company Office Image
Chennai Hub
Gurugram Hub - Ericsson India Global Services (Delhi NCR)
Company Office Image
Gurgaon Head Office - Ericsson India (Delhi NCR)
Irvine Office
Ottawa R&D Site
Kolkata Hub
Krakow R&D Center
Company Office Image
Lewisville 5G Smart Factory
Łódź R&D Site
Montreal AI & R&D Hub
Company Office Image
Morristown Office
Nanjing R&D & Manufacturing Hub
Noida Hub (Delhi NCR)
Overland Park Office
Plano Office - US Headquarters
Pune Hub
Company Office Image
Santa Clara D-15 Innovation Center
São Paulo - Brazil Main Office
Tokyo Head Office
Learn more

Similar Jobs

Ericsson Logo Ericsson

Material Planner

Cloud • Information Technology • Internet of Things • Machine Learning • Software • Cybersecurity • Infrastructure as a Service (IaaS)
In-Office
Shah Alam, Petaling, Selangor, MYS
88000 Employees

Ericsson Logo Ericsson

Head of MOAI NEO EHS

Cloud • Information Technology • Internet of Things • Machine Learning • Software • Cybersecurity • Infrastructure as a Service (IaaS)
In-Office or Remote
9 Locations
88000 Employees

Ericsson Logo Ericsson

Customer Security Director

Cloud • Information Technology • Internet of Things • Machine Learning • Software • Cybersecurity • Infrastructure as a Service (IaaS)
In-Office
3 Locations
88000 Employees

Ericsson Logo Ericsson

Site Management Intern

Cloud • Information Technology • Internet of Things • Machine Learning • Software • Cybersecurity • Infrastructure as a Service (IaaS)
In-Office
Sunway Rahman Putra, Petaling Jaya, Petaling, Selangor, MYS
88000 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account