Search by job, company or skills

SOC Specialist

  • Posted 14 hours ago
  • Be among the first 10 applicants

Job Description

SOC Specialist

  • Location : Cyberjaya
  • Salary : Max RM15,000
  • Employment Type: Full-time Employment
  • Open for : Local/PR

Job Summary

We are seeking an experienced SOC Specialist to provide specialist-level expertise in advanced security monitoring, complex incident investigation, threat hunting, detection engineering support, and technical escalation. The role will support major incident response, improve SOC detection capabilities, and provide technical guidance to SOC analysts.

Key Responsibilities

  • Perform advanced investigation of complex, high-risk, and escalated security incidents.
  • Analyze events across SIEM, EDR/XDR, identity, network, email, cloud, firewall, proxy, and application logs.
  • Correlate multiple data sources to establish attack timelines, entry points, affected assets, and scope.
  • Investigate suspicious processes, PowerShell, persistence, credential abuse, lateral movement, privilege escalation, and data exfiltration.
  • Conduct proactive threat hunting using IOCs, TTPs, behavioral indicators, threat intelligence, and MITRE ATT&CK.
  • Validate threat intelligence indicators and assess their relevance to the environment.
  • Review and tune SIEM analytics rules, detection logic, correlation rules, and alert thresholds.
  • Identify detection gaps and recommend new security use cases.
  • Support major incident response, containment, eradication, and recovery activities.
  • Perform RCA and recommend corrective/preventive actions.
  • Provide technical guidance and mentoring to L1/L2 SOC analysts.
  • Coordinate with infrastructure, endpoint, network, identity, cloud, and application teams for remediation.
  • Prepare detailed technical investigation reports and maintain SOC playbooks and documentation.
  • Participate in tabletop exercises, threat simulations, and incident-response testing.

Requirements

  • 5–7+ years of hands-on SOC/Cybersecurity experience.
  • Proven L2/L3 experience in security monitoring and incident investigation.
  • Experience handling critical/high-severity incidents and technical escalations.
  • Experience in an enterprise SOC/MDR/MSSP environment.
  • Strong hands-on experience with Microsoft Sentinel or equivalent SIEM.
  • Strong experience with Microsoft Defender XDR/Defender for Endpoint or equivalent EDR/XDR.
  • Strong KQL knowledge and ability to independently query and correlate security data.
  • Strong knowledge of:
  • Incident Response & Threat Hunting
  • Threat Intelligence & MITRE ATT&CK
  • Endpoint and Network Investigation
  • Identity/Authentication Attacks
  • Email/Phishing Investigation
  • Malware/Ransomware
  • PowerShell & Command-Line Analysis
  • Lateral Movement & Privilege Escalation
  • Persistence & Data Exfiltration
  • Ability to build end-to-end attack timelines, determine scope and impact, identify true/false positives, and recommend containment/remediation actions.
  • Strong technical documentation and communication skills.
  • Ability to mentor junior analysts and provide technical recommendations.

Preferred

  • Experience with Defender for Identity, Defender for Cloud, Entra ID, Purview, and Intune.
  • Experience with SOAR, Logic Apps, Playbooks, and security automation.
  • Experience with Trellix, Palo Alto, Splunk, QRadar, or ArcSight.
  • Knowledge of UEBA, behavioral analytics, malware analysis, and digital forensics.
  • Experience developing Sentinel analytics rules and advanced hunting queries.
  • Knowledge of Azure/AWS/GCP security.
  • Experience with SIEM/EDR migration or SOC transformation projects.
  • Familiarity with Threat Intelligence Platforms (TIP).

Preferred Certifications

  • GCIH – GIAC Certified Incident Handler
  • GCFA / GCIA
  • Microsoft SC-200
  • CISSP
  • Security+ / CEH

More Info

Job Type:
Industry:
Function:
Employment Type:

About Company

Job ID: 153850139

Beware of Scammers

We don’t charge money for job offers