{"id":1303540,"url":"https://alion.io/job/cybertron-cybersecurity-analyst-use-case-developer","title":"Cybersecurity Analyst (Use case Developer)","company":{"id":3814868,"name":"Cybertron","domain":"cybertron.co.th","url":"https://alion.io/company/cybertron-2","size_band":null,"is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":null,"truth_index":null},"role":"Security","role_family":"Security","seniority":null,"employment_type":"full_time","work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Bangkok, Thailand"],"countries":["TH"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":13500,"max_usd":38000,"period":"year","method":null,"sample_n":2929},"experience_years_min":null,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"IBM QRadar","optional":false},{"name":"SIEM","optional":false},{"name":"Splunk","optional":false}],"status":"live","first_seen_at":"2026-09-24T00:00:00Z","employer_posted_date":null,"last_verified_at":"2026-09-24T00:00:00Z","board_verified":false,"closed_at":null,"days_open":7,"trust":{"level":"not_scored","repost_count":null,"flags":[],"days_open":7},"description":"1. ออกแบบ พัฒนา และปรับปรุง Use Case, Detection Logic และ Correlation Rule สำหรับระบบ SIEM (เช่น Splunk, QRadar, ArcSight หรือระบบอื่นที่องค์กรใช้งาน)\nเพื่อเพิ่มประสิทธิภาพในการตรวจจับภัยคุกคามทางไซเบอร์ \n\n2. วิเคราะห์ Log จากระบบต่าง\nๆ เช่น Network, Endpoint, Server, Application, Cloud และ Security\nDevice เพื่อทำความเข้าใจพฤติกรรมของเหตุการณ์และออกแบบเงื่อนไขการตรวจจับที่เหมาะสม\n\n3. สนับสนุนการพัฒนาและปรับปรุง Detection Rule โดยอ้างอิงจาก\nIncident จริง ผลการ Threat Hunting และข้อเสนอแนะจากทีม\nSecurity Operation Center (SOC) \n\n4. ทดสอบ ตรวจสอบ (Validation) และปรับแต่ง\nUse Case / Correlation Rule ก่อนนำขึ้นใช้งานจริง\nรวมถึงปรับปรุงเพื่อลด False Positive และเพิ่มประสิทธิภาพการตรวจจับ\n\n5. ติดตามข้อมูล Threat Intelligence, ช่องโหว่ (Vulnerability), IOC, TTP และเทคนิคการโจมตีใหม่\nๆ เพื่อนำมาประยุกต์ใช้ในการพัฒนา Detection \n\n6. จัดทำและปรับปรุงเอกสารที่เกี่ยวข้องกับ\nUse Case และ Detection เช่น Detection Logic, Flow\nDiagram, Logic Diagram, Rule Documentation และเอกสารทางเทคนิคอื่น\nๆ \n\n7. สนับสนุนทีม Incident Response และทีม SOC ในการวิเคราะห์เหตุการณ์ที่เกี่ยวข้องกับ\nDetection Rule รวมถึงช่วยตรวจสอบและปรับปรุง Rule ตามผลการสืบสวน \n\n8. ปฏิบัติตามมาตรฐานการพัฒนา Use Case, Workflow, Change\nManagement และ Version Control ขององค์กร \n\n9. ศึกษาและพัฒนาความรู้ด้าน Cybersecurity, SIEM,\nDetection Engineering และเทคโนโลยีที่เกี่ยวข้องอย่างต่อเนื่อง\nพร้อมเข้าร่วมกิจกรรม Training และ Knowledge Sharing\nของทีม\n\n10. ปฏิบัติงานอื่น ๆ\nตามที่ได้รับมอบหมายจากผู้บังคับบัญชา เพื่อสนับสนุนการดำเนินงานของทีมและองค์กร\nQualifications\n1. ปริญญาตรีขึ้นไป สาขา Cybersecurity, Computer Science, IT, Computer Engineering หรือสาขาที่เกี่ยวข้อง\n2. มีประสบการณ์ด้าน Cybersecurity, SOC, SIEM หรือ Detection อย่างน้อย 1-3 ปี\n3. มีความรู้และประสบการณ์ด้าน SIEM Use Case, Detection Rule และ Correlation Rule\n4. สามารถวิเคราะห์ Log จาก Network, Endpoint, Server, Application, Cloud และ Security Device ได้\n5. มีความรู้ด้าน Threat Intelligence, IOC, TTP และ MITRE ATT&CK รวมถึงสามารถนำมาประยุกต์ใช้ในการพัฒนา Detection ได้\n6. สามารถเขียน Query/Rule สำหรับ SIEM เช่น SPL, AQL, KQL หรือเทคโนโลยีที่เกี่ยวข้องได้\n7. มีทักษะการวิเคราะห์ปัญหา เรียนรู้เทคโนโลยีใหม่ ๆ ได้ดี และสามารถทำงานร่วมกับทีม SOC / Incident Response ได้","description_format":"text","description_chars":2199,"description_truncated":false,"requirements":{"experience_years_min":null,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Cybersecurity","Information Security","Incident Response"],"lifecycle":[{"event":"open","at":"2026-09-26T12:33:12Z"}],"liveness":{"score":85,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.854,"p_room":1,"age_days":6,"expected_fill_days":21,"reasons":["seen:6","velocity","win:early"],"computed_at":"2026-09-30T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/cybertron-cybersecurity-analyst-use-case-developer","json_url":"https://alion.io/job/cybertron-cybersecurity-analyst-use-case-developer.json","meta":{"generated_at":"2026-10-01T03:26:14Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":2891,"day_limit":5000,"remaining_today":2109,"minute_limit":60,"resets_at":"2026-10-02T00:00:00Z"}}}