Senior Security Engineer - Cyber Defense
Kredivo Group · Ho Chi Minh City, Vietnam
قدّم وتابع مع أبلاي إيدجWe are looking for a Senior Security Engineer to join Kredivo Group’s Cyber Defense team. Thisrole is designed for professionals who can bridge enterprise security engineering, threat huntingand incident response.You will play a critical role in protecting our infrastructure, endpoints and applications fromadvanced threats, while also proactively hunting for malicious activity and leading IR efforts.You’ll collaborate with IT, engineering and other security teams based in Indonesia & India tobuild, monitor and evolve security defenses, while staying ahead of adversaries through threatintelligence and detection engineering.ResponsibilitiesDFIR - Windows, macOS, Linux & CloudLead DFIR investigations across Windows, macOS and Linux endpoints/servers,identifying attack vectors, persistence mechanisms, lateral movement and root cause.Perform disk, memory, file-system, registry and artifact analysis to reconstruct attackeractivity and establish timelines.Analyze Windows artifacts including Event Logs, Registry, Prefetch, Amcache,Shimcache, SRUM, PowerShell, scheduled tasks and browser artifacts.Investigate macOS artifacts including Unified Logs, LaunchAgents/LaunchDaemons,persistence mechanisms, shell history, browser data and file-system activity.Perform timeline analysis and artifact correlation to reconstruct attacker behavior anddetermine the scope and impact of incidents.Threat Hunting & DetectionsContinuous monitoring of both internal and external systems to detect threats, uncovervulnerabilities and ensure policy compliance.Correlate IOCs/TTPs with internal activity using SIEM, EDR and custom automation.Deploy, configure and monitor security tools (EDR, DLP, VMDR).Analyze dark web chatter, OSINT sources and intelligence platforms to identify emergingthreats.Generate weekly/monthly hunting & intel reports with actionable recommendations.Incident ResponseLead incident response, perform forensics and log analysis to identify root causes.Support containment, eradication and remediation efforts with cross functional teams.Develop security automations and workflows using scripting languages Python or Bash.Collaborate with the Threat Detection team to fine tune alerts and improve detectioncoverage.Contribute to IR playbooks, runbooks and post incident reviews.Qualifications4 to 7 years of experience in cybersecurity with exposure to enterprise security, threathunting and incident response.Hands on with security platforms like EDR, DLP, Wazuh, Vulnerability Management, andCloudflare WAF.Good understanding of adversary tactics like MITRE ATT&CK, TTPs, IOC handling.Working knowledge of scripting/automation (Python, Bash, PowerShell).Knowledge of forensic techniques, log analysis, and security monitoring platforms.Strong grasp of enterprise IT & SaaS security (GSuite, VPNs, cloud security, IAM).Preferred certifications: Security+, CCNA/P, GIAC (GCIA/GCTI/GCIH) or equivalent.Experience in Fintech or financial services is a plus.Behavioral & Soft SkillsOwnership mindset: can lead initiatives independently with minimal supervision.Strong analytical and problem solving skills in high-pressure situations.Excellent communicator and be able to explain technical security concepts to technicaland non-technical stakeholders.Team player that collaborates effectively across IT, engineering and security.Passionate about continuous learning, automation and staying current with the threatlandscape.