Ericsson logo

Cyber Defense Specialist

Ericsson

On-site
Shah Alam, Selangor
Full-time
Senior
5+ yrs
Salary not listedPosted 1h ago

Real job — pulled straight from Ericsson’s careers page · Verified August 16, 2026 · No reposts.

Job description

Ericsson is hiring a Cyber Defense Specialist — a full-time, based in Shah Alam, Selangor role. Apply directly on Ericsson's careers page below.

Cyber Defense Specialist

Location: Shah Alam,Selangor Darul Ehsan,Malaysia

Department: 82 Service Delivery

Work Location: onsite

Grow with us

As the tech firm that created the mobile world, and with more than 54,000 patents to our name, we’ve made it our business to make a mark. When joining our team at Ericsson you are empowered to learn, lead and perform at your best, shaping the future of technology. This is a place where you're welcomed as your own perfectly unique self, and celebrated for the skills, talent, and perspective you bring to the team. Are you in?

Come, and be where it begins.

 

Job Summary
We are seeking an experienced Cyber Defence Specialist responsible for monitoring, detecting, investigating, and responding to cybersecurity threats while ensuring compliance with regulatory and organizational security requirements. The ideal candidate possesses strong hands-on experience in Security Operations Center (SOC) functions, incident response, threat intelligence, vulnerability management, and security governance.
The role also requires supporting cybersecurity compliance initiatives, forensic investigations, and continuously improving the organization's cyber defence capabilities.

Key Responsibilities

Security Operations Center (SOC)

  • Monitor security events using SIEM, EDR, NDR, SOAR, IDS/IPS, and other security monitoring platforms.
  • Perform Level 2/Level 3 incident investigation and response.
  • Conduct malware analysis and threat hunting activities.
  • Investigate phishing, ransomware, insider threats, account compromise, and advanced persistent threats (APT).
  • Analyze logs from servers, firewalls, cloud platforms, endpoints, databases, and network devices.
  • Develop and optimize SIEM correlation rules and detection use cases.
  • Lead incident triage, containment, eradication, recovery, and post-incident reviews.
  • Coordinate with infrastructure, application, cloud, and network teams during security incidents.
  • Maintain incident documentation, root cause analysis (RCA), and lessons learned.

Threat Intelligence & Threat Hunting

  • Monitor emerging cyber threats and vulnerabilities.
  • Correlate Indicators of Compromise (IOCs) and Indicators of Attack (IOAs).
  • Integrate threat intelligence feeds into SOC operations.
  • Perform proactive threat hunting using MITRE ATT&CK techniques.
  • Recommend improvements to security controls based on threat trends.

Forensics

  • Perform forensic acquisition of endpoints, servers, virtual machines, and cloud workloads.
  • Support cyber investigations with law enforcement or external agencies where required.
  • Support customer in investigation related to respective OS.
  • Knowledge of telco network applications and interfaces.

.

Compliance & Governance

  • ISO/IEC 27001
  • NIST Cybersecurity Framework (CSF)
  • CIS Controls
  • Local regulatory requirements (e.g., MCMC NCII, PDPA, sector-specific regulations)
  • Assist with internal and external security audits.
  • Review and maintain security policies, procedures, and standards.
  • Track compliance findings and remediation activities.

Vulnerability & Security Management

  • Coordinate vulnerability assessments and penetration testing.
  • Prioritize remediation based on business risk.
  • Track vulnerabilities through closure.
  • Validate security hardening across Windows, Linux, cloud, databases, and network devices.
  • Support secure configuration reviews.

Security Engineering & Automation

  • Enhance SOC automation using SOAR platforms.
  • Develop security playbooks and response procedures.
  • Improve detection engineering using Sigma, YARA, and SIEM rules.
  • Support integration of security tools through APIs and automation scripts.

.

Reporting & Communication

  • Prepare executive and technical incident reports.
  • Present security findings to management and stakeholders.
  • Develop SOC dashboards and KPIs.
  • Conduct awareness sessions for technical teams.
  • Support cyber crisis management and tabletop exercises.

Required Technical Skills

  • Security Operations
  • SIEM (Splunk, Microsoft Sentinel, QRadar, ArcSight, Elastic)
  • EDR/XDR (Microsoft Defender, CrowdStrike, SentinelOne, Carbon Black)
  • SOAR platforms

 

.

Networking

  • TCP/IP
  • DNS
  • HTTP/HTTPS
  • SMTP
  • VPN
  • Routing and Switching
  • Network packet analysis (Wireshark)

 Threat Frameworks: MITRE ATT&CK; Cyber Kill Chain; Diamond Model

Qualifications

  • Bachelor's degree in Computer Science, Cyber Security, Information Technology, or related discipline.
  • 5–10 years of cybersecurity experience and telco network background is preferred.
  • Minimum 3 years in a Security Operations Center (SOC).
  • Experience handling major cyber incidents.
  • Experience performing forensic investigations.
  • Strong understanding of compliance and audit processes.
  • ITIL certification, CEH, Security +, CompTIA Security+, CCNA Security, or similar will be an advantage
  • Basic knowledge of telecommunications networks will be an added advantage

Why join Ericsson?At Ericsson, you´ll have an outstanding opportunity. The chance to use your skills and imagination to push the boundaries of what´s possible. To build solutions never seen before to some of the world’s toughest problems. You´ll be challenged, but you won’t be alone. You´ll be joining a team of diverse innovators, all driven to go beyond the status quo to craft what comes next.
 
What happens once you apply?Click Here to find all you need to know about what our typical hiring process looks like.Encouraging a diverse and inclusive organization is core to our values at Ericsson, that's why we champion it in everything we do. We truly believe that by collaborating with people with different experiences we drive innovation, which is essential for our future growth. We encourage people from all backgrounds to apply and realize their full potential as part of our Ericsson team. Ericsson is proud to be an Equal Opportunity Employer. learn more.

 

Primary country and city: Malaysia (MY) || Shah Alam

Req ID: 788892

 





Get Cyber Defense Specialist jobs like this

New roles from thousands of companies land hourly, straight from their careers pages. Get the freshest matches by email so you never miss one.

Email me new jobs
Hewlett Packard Enterprise logo

Principal Presales Systems Engineer (Remote)

$199k–$412kRemote · US-eligible
✓ From careers page· 9h ago
Imprint logo

Senior Engineering Manager, Security

$220k–$235kSan Francisco, CA
✓ From careers page· 14h ago
Commonwealth Bank of Australia logo

Cyber Defence Analyst

Bangalore
✓ From careers page· 15h ago
Strategic Data Systems logo

Senior Systems Security Engineer

Dahlgren, VA
✓ From careers page· 18h ago

Frequently asked questions

What skills are required for Cyber Defense Specialist at Ericsson?

The required skills for Cyber Defense Specialist at Ericsson include: SIEM, ISO 27001, TCP/IP, DNS, VPN, Splunk, CompTIA Security+.

What is the seniority level for Cyber Defense Specialist at Ericsson?

Cyber Defense Specialist at Ericsson is a Senior level position.

How do I apply for Cyber Defense Specialist at Ericsson?

You can view the full description and apply for Cyber Defense Specialist at Ericsson on EchoJobs: https://echojobs.io/job/ericsson-cyber-defense-specialist-04w3v.