ตำแหน่งงาน
ที่ไหน

212 ตำแหน่ง

กลับไปยังหน้าหางาน
อัพโหลด CV ของคุณ

เราจะใช้ AI อ่าน แล้วช่วยหาโอกาสที่ใช่ให้คุณ

คลิกเพื่ออัพโหลด หรือลากไฟล์มาวาง · PDF, DOC, DOCX · ไม่เกิน 10 MB

Lumentum

IT Security Analyst

ประกาศจากแหล่งภายนอก
Lumentum
เทคโนโลยี
ปทุมธานีทำงานที่ออฟฟิศลงประกาศ 21 วันที่แล้ว
สมัครที่เว็บไซต์บริษัท

คุณสมัครได้โดยตรง — เราจะพาคุณไปยังหน้าสมัครงานของบริษัท ไม่ต้องสมัครสมาชิก ไม่มีคนกลาง ไม่ต้องล็อกอิน ThaiJobz

รายละเอียด
เงินเดือนตามตกลง
ประเภทการจ้าง
เต็มเวลา
รูปแบบ
ทำงานที่ออฟฟิศ

เกี่ยวกับตำแหน่ง

As an IT Security Analyst, you will protect organizational information assets by monitoring security events, investigating alerts, and administering security controls. You will also participate in incident response, vulnerability management, and ensuring compliance with security policies.

รายละเอียดงาน

Role purpose

The postholder supports the day-to-day protection of the organisation's information assets by monitoring security events, investigating alerts, administering security controls, gathering assurance evidence and supporting incident response in line with approved policies, standards and procedures.

Role scope and level

Operational practitioner working within approved standards, playbooks, change processes and escalation routes. Responsible for accurate triage, evidence capture, routine control activity and remediation follow-up. Expected to escalate high-risk, novel or complex issues to the relevant incident owner, service owner, risk owner or line manager. Focuses on consistent execution, timely service support and clear communication with technical and non-technical colleagues.

Key responsibilities

  • Security monitoring and alert triage Monitor Security Information and Event Management (SIEM), Endpoint Detection and Response (EDR), anti-malware, email security, web security and cloud security alerts. Validate, triage and prioritise security events using agreed playbooks, business impact and risk context. Create accurate incident records, preserve relevant evidence and escalate incidents through the agreed incident management process. Support containment, eradication and recovery activities under the direction of the incident owner.
  • Incident response and operational support Follow documented incident response procedures for malware, phishing, account compromise, data exposure, suspicious network activity and lost or stolen devices. Assist with post-incident actions, including evidence capture, timeline building, lessons learned and remediation tracking. Maintain security operations knowledge base articles and playbooks for repeatable response tasks.
  • Vulnerability and configuration management Run or support scheduled vulnerability scanning across servers, endpoints, network devices, applications and cloud services. Validate scan findings, remove false positives where evidence supports this, assign remediation tickets and monitor progress against agreed service levels. Support secure configuration checks against approved baselines, including endpoint hardening, logging configuration and privileged account controls. Provide clear remediation guidance to infrastructure, application and service teams.
  • Identity, access, Data Loss Prevention and Multi-Factor Authentication Support identity and access management processes, including joiners, movers, leavers, privileged access reviews and evidence collection for access recertification. Monitor and investigate Data Loss Prevention (DLP) alerts, applying agreed classification, privacy and escalation rules. Support Multi-Factor Authentication (MFA) administration, user enrolment, exception handling, break-glass access checks and failed authentication investigations. Assist with user access investigations where suspected compromise, misuse or policy breach is identified.
  • Security controls and tooling Operate security tools in line with documented procedures and change controls. Support maintenance of alert rules, watchlists, endpoint policies, email filtering rules and data protection controls under approved guidance. Record control issues, service defects and improvement opportunities. Carry out routine security checks for backup alerts, logging gaps, certificate expiry, secure configuration and monitoring coverage.
  • Policy, compliance and assurance support Gather evidence for audits, risk assessments, supplier checks and compliance reviews. Apply relevant internal policies, standards and data handling requirements. Support regular checks against security standards, control requirements and business processes. Identify policy exceptions or control gaps and raise them through the agreed risk management process.
  • Awareness and stakeholder support Provide practical security advice to users and technical teams. Support phishing exercises, security awareness activities and targeted communications. Explain security requirements in a clear, proportionate and helpful way. Promote secure behaviours, including reporting suspicious activity, protecting credentials and handling sensitive data correctly.
  • Reporting and documentation Maintain accurate incident, alert, remediation and evidence records. Prepare routine operational reports on alerts, incidents, vulnerabilities, Data Loss Prevention (DLP), Multi-Factor Authentication (MFA), control exceptions and remediation progress. Contribute to dashboards and management information using agreed metrics. Keep procedures, playbooks and technical notes up to date.

Required knowledge, skills and experience

Essential technical skills

  • Security monitoring and incident triage using Security Information and Event Management (SIEM), Endpoint Detection and Response (EDR), endpoint protection and cloud security tooling.
  • Data Loss Prevention (DLP) alert analysis, policy support and escalation.
  • Multi-Factor Authentication (MFA) administration, troubleshooting and exception checking.
  • Vulnerability scanning, remediation tracking and secure configuration review.
  • Understanding of common network, endpoint, identity, email and cloud security controls.
  • Awareness of firewalls, proxies, Virtual Private Network (VPN), Intrusion Detection System (IDS) and Intrusion Prevention System (IPS) technologies.
  • Strong documentation, evidence gathering and ticket management skills.
  • Basic scripting or automation capability, for example PowerShell or Python, is desirable.

Essential knowledge

  • Confidentiality, integrity and availability principles and their application to business information.
  • Common cyber threats, including phishing, malware, ransomware, credential theft.

คุณสมบัติผู้สมัคร

ประสบการณ์
3-5 ปี
การศึกษา
ไม่ระบุ
ใบรับรอง / ทักษะเพิ่มเติม
SIEMEDRIncident ResponseVulnerability ManagementDLPMFAIdentity and Access ManagementNetwork SecurityCloud SecurityPowerShellPythonSecurity MonitoringTriageEvidence GatheringRisk Management

เกี่ยวกับบริษัท

Lumentum
Lumentum