The Lead is the senior technical authority across security monitoring, incident response (IR) and platform engineering, and leads a combined team on a day-to-day basis. Reporting to the Operations Manager, the Lead sets technical direction, uplifts the maturity of operations and acts as the final escalation point for complex investigations. Three groups report into this role: IR responders, SOC L1/L2 analysts, and Platform Engineering (PE) / SIEM engineers.
The role demands both a hands-on investigator who can independently drive incidents to root cause and remediation, and a leader who can coordinate IR, direct a shift, and steer the platform engineering function that onboards clients, answers their coverage questions and builds the detections their environments require.
Key Responsibilities
Incident Response & Coordination
Lead and coordinate high-severity incidents (P1/P2) end-to-end, running bridge calls and directing the IR responders through detection, containment, eradication and recovery
Serve as the senior escalation and decision point for complex investigations, providing technical validation and clear direction under pressure
Investigate hands-on to find solutions — deep-dive analysis of endpoint, network and identity telemetry, malware behaviour and adversary TTPs to establish root cause and remediation, not just triage
Guide forensic examination (endpoints, servers, logs, memory, network traffic) to support investigative outcomes and attribution
Maintain IR SOPs, forensic playbooks and escalation workflows, feeding lessons learned back into detections and process
Lead technical coordination for cyber drills and tabletop exercises, translating outcomes into concrete improvements
Platform Engineering (PE) & Detection
Lead the PE / SIEM engineering function, directing onboarding of new clients, log sources and assets onto the monitoring platform and ensuring healthy, complete data ingestion
Act as the senior technical contact for client queries — advising on asset coverage, answering questions about their monitored estate, and translating their needs into monitoring outcomes
Own the detection lifecycle — design, build, test and tune SIEM use cases and correlation rules, including new detections requested by clients or driven by their specific markets and threat landscape
Build and mature automation across monitoring, IR and platform engineering — orchestration and SOAR playbooks that cut manual effort and accelerate response
Continuously evaluate best-in-market approaches and tooling (SIEM, SOAR, EDR/XDR, threat intel, AI-assisted triage) and drive adoption where they add clear value
Operationalize threat intelligence into detections and run threat hunting / hypothesis-driven investigations to close coverage gaps
Team Leadership
Lead the combined team — IR responders, SOC L1/L2 analysts and PE / SIEM engineers — allocating work, managing shift coverage and ensuring the team consistently follows the right process
Uplift the team and set direction — mentor and coach across IR, monitoring and platform engineering, raise technical standards and build a clear path for capability improvement
Provide quality assurance over the team's output (triage accuracy, escalation quality, onboarding, detection changes, documentation) and hold the team accountable to SLAs and standards
Act as the day-to-day technical face of the team to the Operations Manager, surfacing risks, gaps and improvement opportunities
Key Performance Indicators (KPIs)
Incident handling: number of incidents contained/resolved within SLA; MTTD and MTTR trend improvements, particularly for P1/P2
Detection quality: number of use cases tuned with measurable false positive reduction; increase in high-fidelity true-positive alerts
Onboarding & platform delivery: client/asset onboarding delivered on schedule; new client detection requests actioned within agreed timelines; monitoring coverage completeness
Automation & maturity: number of automated/SOAR workflows implemented; number of incidents leveraging automation; number of playbooks reviewed and validated on cadence
Team performance: adherence to process/SLA; QA scores across IR, SOC and PE; measurable uplift in team capability and feedback on guidance
Person Specifications
Qualifications & Experience
8+ years hands-on experience across security monitoring, incident response and digital forensics, including senior/escalation responsibility
Demonstrable experience leading P1/P2 incidents and coordinating multiple teams under pressure
Experience leading or supervising a SOC / IR / engineering team, including shift coverage
Experience in SIEM platform engineering — client/log-source onboarding and building detections to meet client requirements
Degree/Diploma in Information Technology, Cybersecurity or a related discipline
Certifications — preferred: GCIH, GCFA, GREM, CHFI. Good to have: GCIA, GCDA, GMON, Microsoft SC-200, AZ-500, SC-100, CISSP
Knowledge & Technical Skills
Required Skills
Deep, hands-on SIEM capability — building, tuning and maintaining use cases, correlation rules and dashboards; strong grounding in detection engineering as a discipline
Proven platform engineering experience — onboarding log sources/assets, data ingestion and coverage, and building detections tailored to client environments
Proven automation/SOAR experience — designing and implementing orchestration and playbooks to improve SOC and IR efficiency
Strong operational IR and digital forensics capability, including malware analysis and threat hunting
Solid knowledge of APTs, adversary tools/techniques and MITRE ATT&CK TTPs
Strong networking / TCP-IP knowledge and exposure to firewall, IPS, EPP/EDR, DLP, proxy and email security controls
Ability to review and integrate PT / vulnerability findings into monitoring and IR workflows
Cloud security monitoring across Azure, AWS and GCP
Excellent written/verbal communication with the ability to work with clients and lead under pressure during major incidents
Desired Skills
Microsoft security stack (strong plus — aligned to our current environment): Microsoft Sentinel (SIEM/SOAR), Microsoft Defender XDR, KQL, Logic Apps automation and Security Copilot
Experience with other market-leading platforms (e.g. Splunk, QRadar) and EDR solutions (CrowdStrike, Carbon Black)
Scripting/programming for automation (e.g. PowerShell, Python, KQL)
Threat intelligence platform experience and the ability to operationalize intel feeds
Familiarity with regulatory/compliance-driven incident handling (e.g. NIST, ISO 27035, PDPA/GDPR)
Semua Iklan Pekerjaan adalah tertakluk kepada Terms of Service GrabJobs. Kami membenarkan pengguna membenderakan siaran yang mungkin melanggar syarat tersebut. Iklan Pekerjaan juga mungkin dibenderakan oleh pasukan penyederhana GrabJobs. Walau bagaimanapun, tiada sistem penyederhanaan yang sempurna dan membenderakan siaran tidak memastikan bahawa ia akan dialih keluar.
Jadilah orang yang pertama menerima Others Full-Time Jobs terkini di Malaysia.
Sediakan makluman pekerjaan:
Dengan mengaktifkan makluman kerja, saya bersetuju menerima GrabJobs Terms & Privacy Policy. Saya boleh berhenti melanggan makluman kerja pada bila-bila masa.
Langkau
Anda mencapai bilangan maksimum makluman kerja anda.
GrabJobs ialah portal pekerjaan no1 di Malaysia, menghubungkan anda dengan beribu-ribu pekerjaan dengan pantas!
Cari kerja terbaik di Malaysia, mohon dalam 1 klik dan dapatkan pekerjaan hari ini!