Search Jobs

Search by job, company or skills

Manager Endpoint Protection (Operation)

Manager Endpoint Protection (Operation)

Telekom Malaysia
  • Posted 15 hours ago
  • Be among the first 10 applicants

Job Description

ABOUT THE JOB

Lead the XDR security operations program with responsibility for technical leadership, platform optimization, and functional oversight of the analyst team-members. Balances hands-on technical involvement in critical incidents with initiatives around detection engineering, security policy, and organizational security posture. Partners with SOC leadership on roadmap, budget, vendor management, and team development.

KEY RESPONSIBILITIES

XDR Platform Administration

  • Finetuning and maintain XDR security platform inclusive of reducing False Positive alerts, setting detection rules
  • Ensure integration of XDR solution with SIEM, SOAR etc.
  • Manage XDR platform and agent upgrades, patches and system health monitoring
  • Ensure proper log collection and telemetry integration across security tools
  • Develop automated workflows and response playbooks
  • Optimize alerting mechanisms and detection capabilities
  • Support SOC & analysts process improvements

Incident Response

  • Set incident response strategy, escalation policies, and runbooks
  • Lead critical incident response and 24/7 on-call rotation
  • Report incident status/risk to execs and customers; coordinate breach investigation and disclosure with IR
  • Set detection/response/containment targets and drive post-incident reviews for improvement

Escalation:

  • Escalate strategic platform/detection decisions to management
  • Coordinate with IT, compliance, etc. on policy and infrastructure changes
  • Manage vendor relationships for SLA-impacting issues
  • Report budget overages and staffing/training gaps affecting performance

Reporting & Documentation:

  • Prepare monthly XDR/KPI reports and quarterly business reviews for leadership
  • Document platform architecture, configuration standards, and detection roadmap
  • Maintain audit trails for policy/platform changes and access controls
  • Document threats, detection gaps, and improvement recommendations
  • Maintain team performance/coaching records
  • Maintain runbooks, playbooks, and troubleshooting guide

Collaboration:

  • Align XDR strategy/budget with leadership
  • Partner with security, compliance, IT, and infrastructure teams on platform integration and deployment
  • Coordinate with Product on licensing, SLAs, and roadmap feedback

Long-term XDR strategy:

  • Develop multi-year XDR strategy aligned with threat profile and business goals
  • Lead platform modernization, tool consolidation, and detection optimization
  • Evaluate new technologies and drive adoption of best practices and automation
  • Advise senior management on endpoint security strategy, risk, and compliance

Strategic & Program Management:

  • Set and track KPIs (detection coverage, false positives, MTTR, on-call health)
  • Set platform configuration standards, detection policies, and security baselines
  • Lead cross-functional projects (cloud migration, threat intel, automation)
  • Manage budget (licensing, tools, training, hiring) and platform modernization
  • Conduct annual threat assessments to guide platform enhancements

Mentorship:

  • Mentor and develop team members through performance feedback, career guidance, and knowledge-sharing sessions, while monitoring detection coverage, alert quality, and response SLA

CANDIDATE MUST HAVE

  • Bachelor's degree in Cybersecurity, Information Security, or related field (or equivalent experience)
  • CISSP, GCIH, GCIA, or equivalent advanced cybersecurity certifications are highly preferred
  • 8+ years of hands-on experience with deep expertise in EDR/XDR architecture, detection engineering, threat hunting, and threat research

WE VALUE

  • Expert-level proficiency in two or more leading XDR platforms and detection engineering practices
  • Advanced capabilities in threat analysis, detection development, and MITRE ATT&CK framework mapping
  • Ability to thrive in a lean, fast-paced environment, balancing multiple responsibilities effectively.
  • Strong expertise in endpoint security, EDR/XDR operations, incident investigation, and threat hunting
  • Excellent troubleshooting, root cause analysis, and performance optimization skills.
  • Technical Competencies: Palo Alto Cortex XDR, Microsoft Defender XDR, Crowd Strike Falcon, Sentinel One, Trend Micro Vision One, Splunk, Microsoft Sentinel (Azure Sentinel) & Elasticsearch

LOCATION

  • TM Annexe 2, Telekom Malaysia Berhad, Jalan Pantai Baharu, Kuala Lumpur.

More Info

Job Type:
Industry:
Function:
Employment Type:

Key Skills

Palo Alto Cortex XDR

Azure Sentinel

Microsoft Defender XDR

Detection development

MITRE ATT&CK framework

Detection engineering

Trend Micro Vision One

Threat research

Microsoft Sentinel

XDR platforms

About Company