Manager Endpoint Protection (Operation)
Telekom Malaysia- Posted 15 hours ago
- Be among the first 10 applicants
Job Description
ABOUT THE JOB
Lead the XDR security operations program with responsibility for technical leadership, platform optimization, and functional oversight of the analyst team-members. Balances hands-on technical involvement in critical incidents with initiatives around detection engineering, security policy, and organizational security posture. Partners with SOC leadership on roadmap, budget, vendor management, and team development.
KEY RESPONSIBILITIES
XDR Platform Administration
- Finetuning and maintain XDR security platform inclusive of reducing False Positive alerts, setting detection rules
- Ensure integration of XDR solution with SIEM, SOAR etc.
- Manage XDR platform and agent upgrades, patches and system health monitoring
- Ensure proper log collection and telemetry integration across security tools
- Develop automated workflows and response playbooks
- Optimize alerting mechanisms and detection capabilities
- Support SOC & analysts process improvements
Incident Response
- Set incident response strategy, escalation policies, and runbooks
- Lead critical incident response and 24/7 on-call rotation
- Report incident status/risk to execs and customers; coordinate breach investigation and disclosure with IR
- Set detection/response/containment targets and drive post-incident reviews for improvement
Escalation:
- Escalate strategic platform/detection decisions to management
- Coordinate with IT, compliance, etc. on policy and infrastructure changes
- Manage vendor relationships for SLA-impacting issues
- Report budget overages and staffing/training gaps affecting performance
Reporting & Documentation:
- Prepare monthly XDR/KPI reports and quarterly business reviews for leadership
- Document platform architecture, configuration standards, and detection roadmap
- Maintain audit trails for policy/platform changes and access controls
- Document threats, detection gaps, and improvement recommendations
- Maintain team performance/coaching records
- Maintain runbooks, playbooks, and troubleshooting guide
Collaboration:
- Align XDR strategy/budget with leadership
- Partner with security, compliance, IT, and infrastructure teams on platform integration and deployment
- Coordinate with Product on licensing, SLAs, and roadmap feedback
Long-term XDR strategy:
- Develop multi-year XDR strategy aligned with threat profile and business goals
- Lead platform modernization, tool consolidation, and detection optimization
- Evaluate new technologies and drive adoption of best practices and automation
- Advise senior management on endpoint security strategy, risk, and compliance
Strategic & Program Management:
- Set and track KPIs (detection coverage, false positives, MTTR, on-call health)
- Set platform configuration standards, detection policies, and security baselines
- Lead cross-functional projects (cloud migration, threat intel, automation)
- Manage budget (licensing, tools, training, hiring) and platform modernization
- Conduct annual threat assessments to guide platform enhancements
Mentorship:
- Mentor and develop team members through performance feedback, career guidance, and knowledge-sharing sessions, while monitoring detection coverage, alert quality, and response SLA
CANDIDATE MUST HAVE
- Bachelor's degree in Cybersecurity, Information Security, or related field (or equivalent experience)
- CISSP, GCIH, GCIA, or equivalent advanced cybersecurity certifications are highly preferred
- 8+ years of hands-on experience with deep expertise in EDR/XDR architecture, detection engineering, threat hunting, and threat research
WE VALUE
- Expert-level proficiency in two or more leading XDR platforms and detection engineering practices
- Advanced capabilities in threat analysis, detection development, and MITRE ATT&CK framework mapping
- Ability to thrive in a lean, fast-paced environment, balancing multiple responsibilities effectively.
- Strong expertise in endpoint security, EDR/XDR operations, incident investigation, and threat hunting
- Excellent troubleshooting, root cause analysis, and performance optimization skills.
- Technical Competencies: Palo Alto Cortex XDR, Microsoft Defender XDR, Crowd Strike Falcon, Sentinel One, Trend Micro Vision One, Splunk, Microsoft Sentinel (Azure Sentinel) & Elasticsearch
LOCATION
- TM Annexe 2, Telekom Malaysia Berhad, Jalan Pantai Baharu, Kuala Lumpur.
More Info
Key Skills
Palo Alto Cortex XDR
Azure Sentinel
Microsoft Defender XDR
Detection development
MITRE ATT&CK framework
Detection engineering
Trend Micro Vision One
Threat research
Microsoft Sentinel
XDR platforms
