Responsibilities
- Support daily SOC team operations to ensure effective monitoring, detection, and response to security threats across client environments.
- Oversee the SOC analyst team in Kuala Lumpur, including conducting regular one-on-one meetings, performance evaluations, and career development planning; managing shift schedules and staffing; and serving as the primary contact for team escalations and well-being.
- Continuously review and analyze security alerts from EDR, SIEM, and other tools to identify suspicious activities or potential threats.
- Carry out investigations and respond to security incidents, implementing containment, mitigation, and remediation actions as needed.
- Apply expertise to refine detection rules, automate workflows, and enhance incident detection accuracy.
- Perform detailed log analysis from firewalls, endpoint protection platforms, and other solutions to investigate complex incidents.
- Ensure thorough documentation of all incidents, including timelines, analysis, mitigation steps, and lessons learned, and provide regular reports to stakeholders.
- Act as second-line escalation and support for on-shift SOC analysts in the 24x7 SOC team.
- Support onboarding and service request activities for regional MDR clients.
- Proactively search for indicators of compromise and advanced threats within the environment using automated tools and manual analysis.
- Stay current with the latest cybersecurity threats, vulnerabilities, and attack techniques, and integrate threat intelligence into detection and response efforts.
- Provide guidance and mentorship to junior SOC analysts, promoting skill development and adherence to security best practices.
- Collaborate with the SOC team to develop and implement SOC strategies, improve processes, and introduce new technologies to strengthen client security postures.
- Work with SOC analysts, security engineers, and IT teams to ensure smooth operation of security tools and alignment with broader cybersecurity practices.
- Identify areas for improvement in security monitoring and response capabilities, and propose and assist in implementing new solutions as appropriate.
- Assist with onboarding and configuring SOC services and technology for new customers.
- Collaborate closely with other cybersecurity service lines to ensure seamless integration of SOC operations with broader cybersecurity initiatives and business units, particularly Incident Response.
- When schedule permits, participate in and contribute to internal technical development initiatives to enhance tools, processes, and overall incident response capabilities.
Requirements
- Bachelor's or Master's degree in a relevant field such as cybersecurity or computer science.
- At least 3 years of experience in a SOC or cybersecurity operations role, with demonstrated team leadership or supervisory experience.
- Strong understanding of EDR and SecOps toolsets, with experience configuring and using these tools for incident detection and response.
- Proven line management experience, ideally in a SOC environment, including performance management, coaching, and developing analysts at various career stages; strong communication and team-building skills.
- Customer-oriented: comfortable in client-facing situations and able to discuss cybersecurity issues in language accessible to customers.
- Investigative mindset: comfortable solving problems with limited information and guidance, and curious to learn.
- Reliability: dependable.
- Personal interest: demonstrable knowledge of cyber threat actors and their tactics, techniques, and interest in cybersecurity matters, security monitoring, and threat detection techniques.
- Clear and concise communication skills, with the ability to work effectively across teams; able to communicate technical findings to a non-technical audience in a professional setting; able to review and quality-assure incident reports and summaries.
- Permission to work in Malaysia by the start of employment.
Nice to Have
- Relevant industry certifications are advantageous, including any of the following or evidence of working towards attaining them: Blue Team, CISSP, Security+.
Work Arrangement
Hybrid — Kuala Lumpur, Hong Kong, Singapore, Malaysia
Other
- Hybrid role: involves both remote work and some in-office presence for collaboration, teamwork, and development projects.
- APAC regional client focus.
- Global delivery role: act as second-line escalation and support to on-shift SOC analysts in the 24x7 SOC team.
- The successful candidate must have permission to work in Malaysia by the start of their employment.