Search by job, company or skills

Resident Engineer Cybersecurity

Early Applicant
  • Posted 9 days ago
  • Be among the first 10 applicants

Job Description

Senior Threat Detection & SOAR Engineer

(Cybersecurity Resident Engineer)

Location: Malaysia

Employment Type: 12-month Renewable Employment Term

About the Role

We are seeking a hands-on Senior Threat Detection & SOAR Engineer to strengthen an enterprise customer's threat-detection and automated-response capabilities.

The role will focus on developing and tuning SIEM detection rules, building SOAR playbooks, improving MITRE ATT&CK coverage and integrating security workflows with case-management and ticketing platforms.

The successful candidate should be technically hands-on and comfortable working directly with security operations, threat intelligence and incident-response teams.

Key Responsibilities

• Design, build, test and tune SIEM correlation rules, detection queries and alerts.

• Develop detection use cases across endpoint, network, identity, email and cloud telemetry.

• Translate threat intelligence, attacker behaviours and incident findings into actionable detection rules.

• Map detection content to the MITRE ATT&CK framework and identify coverage gaps by tactic and technique.

• Investigate false positives and improve alert accuracy, quality and operational effectiveness.

• Build and document SOAR playbooks for alert enrichment, incident creation, containment, escalation and response.

• Integrate security platforms with case-management and ticketing systems through APIs and automated workflows.

• Conduct telemetry coverage assessments to identify threats that cannot be detected because of missing, insufficient or degraded log sources.

• Maintain detection content using proper lifecycle management, documentation, quality review, version control and retirement processes.

• Work with the customer's security team to define, prioritise and deliver the approved detection use-case backlog.

• Review existing automation and playbooks supporting the China environment and develop enhancements aligned with the organisation's global security standards.

• Support the evaluation and development of AI-assisted security automation, including an AI agent capable of drafting detection rules from threat-intelligence inputs.

• Mentor the customer's security team and transfer the knowledge required for independent operation after the engagement.

Required Experience and Skills

• At least five years of relevant cybersecurity experience, including hands-on exposure to SOC operations, detection engineering, threat hunting or incident response.

• Proven experience developing SIEM correlation rules, queries, dashboards or detection use cases.

• Hands-on experience with at least one enterprise SIEM platform, such as Microsoft Sentinel, Splunk, IBM QRadar, Google Security Operations, Elastic Security or a similar platform.

• Experience building SOAR playbooks, automated response workflows or security-platform integrations.

• Good understanding of MITRE ATT&CK, attacker techniques, threat intelligence and detection-use-case development.

• Experience analysing telemetry from endpoint, network, identity, email and cloud-security platforms.

• Scripting or automation experience using Python, PowerShell, REST APIs or similar technologies.

• Understanding of false-positive management, detection tuning, log quality and detection coverage gaps.

• Strong documentation, communication and stakeholder-management abilities.

Advantageous Experience

• Detection-as-code practices using Git, code review and automated testing.

• Integration with ServiceNow, Jira or other case-management and ticketing platforms.

• Experience supporting security operations within China or other complex regional environments.

• Experience with AI agents, large language models or AI-assisted cybersecurity automation.

• Relevant certifications in cybersecurity, SIEM, cloud security, incident response or threat detection.

Candidate Profile

This position is suitable for a detection engineer, SIEM engineer, SOAR engineer, threat hunter or senior SOC engineer who has progressed beyond alert monitoring and has hands-on experience building and improving detection and response capabilities.

Interested candidates may apply with an updated CV stating their current salary, expected salary, notice period and work-authorisation status.

More Info

Job Type:
Industry:
Function:
Employment Type:

Job ID: 152135725

Beware of Scammers

We don’t charge money for job offers