Senior SOC Analyst
- Location : Cyberjaya
- Salary : Max RM11000
- Employment Type: Full-time Employment
- Open for : Local/PR
Job Summary
We are seeking an experienced Senior SOC Analyst to handle advanced security alert investigation, incident response, threat hunting, and technical escalation. The role will also provide guidance to junior analysts and support continuous improvement of SOC detection and response capabilities.
Key Responsibilities
- Perform L2/L3 investigation of security alerts and high-severity incidents.
- Investigate threats across SIEM, EDR/XDR, identity, network, email, and cloud environments.
- Conduct threat hunting using IOCs, TTPs, Threat Intelligence, and MITRE ATT&CK.
- Analyze attack patterns, establish timelines, and identify root causes.
- Escalate critical incidents within defined SLAs and recommend containment/remediation actions.
- Provide technical guidance and mentoring to L1/L2 SOC analysts.
- Support SIEM use-case tuning, detection improvement, and false-positive reduction.
- Conduct RCA and prepare incident reports for stakeholders.
- Participate in incident response drills and tabletop exercises.
Requirements
- 4–6+ years of SOC/Cybersecurity experience.
- Hands-on experience with Microsoft Sentinel and Defender XDR/EDR or equivalent.
- Good knowledge of KQL and security log analysis.
- Strong incident investigation, response, and threat-hunting skills.
- Knowledge of MITRE ATT&CK and Threat Intelligence.
- Experience with malware, phishing, identity attacks, PowerShell, lateral movement, and data exfiltration.
- Strong analytical, communication, and escalation-management skills.
Preferred
- Experience with Defender for Endpoint, Defender for Identity, Entra ID, Purview, SOAR/Logic Apps, Splunk, QRadar, ArcSight, Trellix, or Palo Alto.
- Knowledge of cloud security and UEBA.
- Certifications such as GCIH, GCFA, SC-200, Security+, or CEH.
KPIs
- Accurate and timely alert investigation.
- SLA compliance and effective escalation.
- Quality of incident analysis and reporting.
- Successful threat hunting and detection improvements.
- Reduction in missed alerts and false positives.