Senior SOC Engineer
hytech · Kuala Lumpur, Kuala Lumpur, Malaysia
About The Role
Job Description Implement & manage the security tools that are currently used as required. Involve into POC for any new security products that will be used in the future. Write, review & enhance the cybersecurity SOP & playbook as required. Investigate the alerts from different security technologies (SIEM, XDR, Anti-Malware, Email Security etc) end-to-end, perform root cause analysis, and mitigate security threats. Analyse the emerging threat & provide actionable threat intelligence. Perform threat hunting periodically based on the latest threat intelligence. Create & review use cases based on the latest threat intelligence. Implement & perform Breach & Attack Simulation within the environment to identify & close the possible gaps between the latest threat & the current capabilities of security tools. Implement & manage honeypots to identify & analyse the potential threat that may be targeting the environment. Requirements Passionate in Cybersecurity, interested in different aspects of technical expertise in Cybersecurity, which includes (but not limited to): Penetration Testing, Digital Forensic & Incident Response, Threat Intelligence, Threat Hunting, Active Directory Assessment, Configuration Assessment, Compromise Assessment etc. Willingness to solve the challenges in a practical/hands-on manner. Hands-on experience in different types of OS (Mainly Windows 10/11, Windows Server 2022/2025, Rocky Linux, Amazon Linux, Debian & their derivatives), experienced in macOS will be a plus. Understand (on a high level) how different technologies work, such as Active Directory, Databases, EDR/XDR, Anti-Malware, Firewall, WAF, IDS/IPS, VPN etc. Keep up to date with the latest technologies, threats & vulnerabilities. Understand different types of logs, and be able to analyse & correlate based on different types of logs. 7+ years of experience in security operations, detection engineering, incident response, threat hunting, Blue Team operations, or security monitoring platform development. Expert-level SOC detection capability, with the ability to design detection programs across attack paths, log sources, detection logic, false positive reduction, and response workflows. Good to Have Ability to perform automation when required, with any programming language such as PowerShell, Bash, Python, Java, Go. Hands-on experience in setting up a home lab & configuring different technologies, including but not limited to: SIEM (Eg: OpenSearch, ElasticSearch, Wazuh, Splunk Free), Firewall (Eg: pfSense), Active Directory, VPN, vulnerable VMs etc. Familiar (at a high level) with different standards, guidelines & best practices, such as MITRE ATT&CK, ISO 27001, NIST, PCI DSS, CIS Benchmark etc. Pursue/Obtained Cybersecurity Certification, such as CompTIA, EC-Council, ISC2, ISACA, INE, OffSec etc. Experienced in multiple offerings in AWS, such as EC2, GuardDuty, ALB, S3 etc. Maintain a personal blog on the review/introduction of certain technologies/skills/certifications.
Similar roles you might like
See all →This is an external listing. JobSpring does not represent or verify the employer. Report this listing
