ABOUT THE JOB
Lead the Palo Alto Cortex XDR security operations program with responsibility for technical leadership, platform optimization, and functional oversight of the analyst team-members. Balances hands-on technical involvement in critical incidents with initiatives around detection engineering, security policy, and organizational security posture.
Partners with SOC leadership on roadmap, budget, vendor management, and team development
KEY RESPONSBILITIES
Technical Specialist
Hands-on experience on XDR Platform Administration
- Finetuning and maintain Cortex XDR security platform inclusive of reducing False Positive alerts, setting detection rules
- Ensure integration of Cortex XDR solution with SIEM, SOAR etc.
- Manage Cortex XDR platform and agent upgrades, patches and system health monitoring
- Ensure proper log collection and telemetry integration across security tools
- Develop automated workflows and response playbooks
- Optimize alerting mechanisms and detection capabilities
- Support SOC & analysts process improvements
Incident Response
- Set incident response strategy, escalation policies, and runbooks
- Lead critical incident response and 24/7 on-call rotation
- Report incident status/risk to execs and customers; coordinate breach investigation and disclosure with IR
- Set detection/response/containment targets and drive post-incident reviews for improvement
Escalation:
- Escalate strategic platform/detection decisions to management
- Coordinate with IT, compliance, etc. on policy and infrastructure changes
- Manage vendor relationships for SLA-impacting issues
- Report budget overages and staffing/training gaps affecting performance
Reporting & Documentation:
- Prepare monthly Cortex XDR/KPI reports and quarterly business reviews for leadership
- Document platform architecture, configuration standards, and detection roadmap
- Maintain audit trails for policy/platform changes and access controls
- Document threats, detection gaps, and improvement recommendations
- Maintain team performance/coaching records
- Maintain runbooks, playbooks, and troubleshooting guide
Collaboration:
- Align XDR strategy/budget with leadership
- Partner with security, compliance, IT, and infrastructure teams on platform integration and deployment
- Coordinate with Product on licensing, SLAs, and roadmap feedback
Long-term XDR strategy:
- Develop multi-year XDR strategy aligned with threat profile and business goals
- Lead platform modernization, tool consolidation, and detection optimization
- Evaluate new technologies and drive adoption of best practices and automation
- Advise senior management on endpoint security strategy, risk, and compliance
General
Strategic & Program Management:
- Set and track KPIs (detection coverage, false positives, MTTR, on-call health)
- Set platform configuration standards, detection policies, and security baselines
- Lead cross-functional projects (cloud migration, threat intel, automation)
- Manage budget (licensing, tools, training, hiring) and platform modernization
- Conduct annual threat assessments to guide platform enhancements
Mentorship:
- Mentor and develop team members through performance feedback, career guidance, and knowledge-sharing sessions, while monitoring detection coverage, alert quality, and response SLA
CANDIDATE MUST HAVE
- Bachelor's degree in Cybersecurity, Information Security, or related field (or equivalent experience).
- Cortex XDR: Security Operations & Integration
- CISSP, GCIH, GCIA, or equivalent advanced certification strongly preferred
WE VALUE
- 5+ years of hands-on experience and deep expertise in Palo Alto EDR/XDR architecture, detection engineering, and threat research
- Expert-level knowledge of 2+ major XDR platforms and detection engineering
- Advanced threat analysis and detection engineering; MITRE ATT&CK expertise
- Comfort wearing multiple hats in a lean operational environment
Technical Proficiency:
- Proficient in endpoint security, Cortex XDR, threat hunting, and incident investigation
- Strong troubleshooting and performance optimization skills
- Proficient in Palo Alto Cortex XDR
Technology
- XDR: Palo Alto Cortex XDR, Trend Micro Vision One
- SIEM & Analytics: Splunk, Azure Sentinel, Elasticsearch
- Query Languages: SPL, KQL, XQL, PowerShell
- Threat Intelligence Platforms: Mandiant, CrowdStrike, Recorded Future
- Project Management: Jira, Confluence, Slack, Teams
- Reporting & Analytics: Tableau, Power BI, Splunk dashboards
- Malware Analysis: AnyRun, Hybrid Analysis, VirusTotal
- Scripting: Bash, Python, PowerShell (workflow automation)
Platform Experience (any equivalent):
- Palo Alto Networks Cortex XDR
- Microsoft Defender XDR
- CrowdStrike Falcon
- SentinelOne Singularity
Advantageous Experience:
- SIEM, cloud security, and threat intelligence platform administration
- Compliance and security frameworks (SOC 2, ISO 27001, NIST)
- Vendor management and security tool evaluation
LOCATION
- TM Annexe 2, Telekom Malaysia Berhad, Jalan Pantai Baharu, Kuala Lumpur.