Our Employee Value Proposition
Advancing our People.
Advancing our World.
At CrimsonLogic, we put your Career and Well-being first.
We are committed to advancing your career through a full spectrum of professional Development programs with the support of a strong Total Rewards philosophy that focus on your well-being.
We believe that by investing in each and every one of our employees professional and personal growth, we can collectively make a positive impact on the world as we strive for greatness together in a nurturing and inclusive workplace.
Role Purpose:
The Lead Specialist (Cyber Security) supports the organisation's security posture by assisting in the design, operation, and improvement of key cybersecurity platforms such as Privileged Access Management (PAM), Vulnerability Management Systems (VMS), Security Information and Event Management (SIEM), and Endpoint Detection & Response (EDR).
The role contributes to daily security operations, helps identify and reduce threats, and supports compliance with internal policies and regulatory requirements.
The incumbent works closely with cross‑functional teams to support security projects, participate in incident investigations, and ensure that security tools and processes are effectively maintained across both on‑premises and cloud environments.
Key Accountabilities:
- Support the administration and maintenance of PAM, VMS, SIEM, and EDR platforms, ensuring they operate effectively and remain updated.
- Assist in monitoring threats, vulnerabilities, and security alerts, contributing to timely remediation and reporting.
- Follow established governance processes and assist in improving security procedures, documentation, and compliance activities (e.g., PDPA, Cybersecurity Act).
- Participate in incident investigations by gathering logs, performing preliminary analysis, and supporting containment activities under guidance.
- Work with IT and application teams to ensure security requirements are understood and incorporated into systems and operational processes.
Job Responsibilities & Duties:
- Assist in configuring, updating and operating PAM tools, including access reviews, credential management, and monitoring privileged sessions.
- Manage VMS platforms for continuous vulnerability scanning, risk prioritization and remediation workflows across hybrid environments.
- Help maintain SIEM systems for log aggregation, advanced threat detection, correlation rule development, real-time alerting, and incident triage.
- Manage EDR tools for endpoint protection, behavioral threat hunting, automated response actions, and forensic investigations.
- Support audits, compliance checks, and security assessments by providing required evidence and artefacts.
Key Job Competencies:
- Technical Aptitude
- Analytical & Problem-Solving Skills
- Collaboration & Communication
- Attention to Detail
- Continuous Learning & Adaptability
Education Requirements:
- Bachelor's degree in Computer Science, Cybersecurity, or related field.
Working Experience Requirements:
- 2–5 years of experience in cybersecurity operations or security engineering roles.
- Exposure to PAM, VMS, SIEM, or EDR tools with hands‑on experience operating at least one platform.
- Basic scripting experience (Python, Bash, or PowerShell) for small automations or reporting tasks.
- Experience supporting audits, incident handling, or vulnerability management is an advantage.
Skills Required:
Must-have skills
- Hands‑on experience working with at least one of the following security platforms:
- PAM (e.g., CyberArk / BeyondTrust), VMS (e.g., Qualys / Tenable), SIEM (e.g., Splunk / Microsoft Sentinel), or EDR (e.g., CrowdStrike / Microsoft Defender).
- Basic to intermediate understanding of threat detection, vulnerability assessment, and incident response processes, with willingness to further develop technical depth.
- Foundational scripting ability in Python, PowerShell, or Bash for simple automation or reporting tasks (advanced automation not required).
- Assist in configuring, updating and operating PAM tools, including access reviews, credential management, and monitoring privileged sessions.
- Manage VMS platforms for continuous vulnerability scanning, risk prioritization and remediation workflows across hybrid environments.
- Help maintain SIEM systems for log aggregation, advanced threat detection, correlation rule development, real-time alerting, and incident triage.
- Manage EDR tools for endpoint protection, behavioral threat hunting, automated response actions, and forensic investigations.
- Support audits, compliance checks, and security assessments by providing required evidence and artefacts.
Preferred skills
- Relevant certifications such as CISSP, CISM, or vendor-neutral security credentials.
- Knowledge of specific standards like ISO 27001 and Cyber Trust Mark