Job Summary
We are seeking a highly skilled SIEM / Detection Engineer with 5–8 years of experience in cybersecurity, security monitoring, and detection engineering. The ideal candidate will be responsible for designing, developing, tuning, and maintaining security detection use cases, SIEM content, and monitoring capabilities to identify and respond to cyber threats effectively. The role requires strong expertise in SIEM platforms, threat detection methodologies, log analysis, and security operations.
Key Responsibilities
- Design, develop, and maintain SIEM use cases, correlation rules, dashboards, and alerts.
- Create and optimize detection content to identify malicious activities, security threats, and suspicious behaviors.
- Perform continuous tuning of SIEM rules to reduce false positives and improve detection accuracy.
- Analyze logs from various sources including endpoints, servers, network devices, cloud platforms, and security tools.
- Collaborate with SOC analysts, incident responders, and threat intelligence teams to enhance detection capabilities.
- Develop detection logic based on threat intelligence, attack techniques, and emerging cyber threats.
- Map detection use cases to frameworks such as MITRE ATT&CK, NIST, and CIS Controls.
- Support security investigations by providing log analysis and detection insights.
- Identify monitoring gaps and implement new log sources and detection mechanisms.
- Create and maintain documentation for detection rules, monitoring processes, and SIEM configurations.
- Participate in threat hunting activities and proactively identify indicators of compromise (IOCs).
- Monitor SIEM platform performance and ensure optimal operation of security monitoring solutions.
Required Skills & Qualifications
- Bachelor's Degree in Computer Science, Information Security, Cybersecurity, or a related field.
- 5–8 years of experience in SIEM engineering, detection engineering, SOC operations, or cybersecurity.
- Hands-on experience with SIEM platforms such as:
- Splunk
- Microsoft Sentinel
- IBM QRadar
- ArcSight
- LogRhythm
- Elastic SIEM
- Strong understanding of log management, event correlation, and security monitoring.
- Experience creating and tuning detection rules, alerts, and correlation searches.
- Knowledge of network protocols, operating systems, Active Directory, and cloud security concepts.
- Familiarity with cyber attack techniques, indicators of compromise, and threat actor behaviors.
- Experience with MITRE ATT&CK framework and threat detection methodologies.
- Strong analytical, troubleshooting, and problem-solving skills.
- Excellent communication and stakeholder management abilities.
Preferred Skills
- Experience with security automation and orchestration tools (SOAR).
- Knowledge of scripting languages such as Python, PowerShell, or Bash.
- Experience with cloud security monitoring in AWS, Azure, or GCP environments.
- Exposure to threat hunting and incident response activities.
- Understanding of EDR/XDR platforms and security telemetry.
Pay: RM6,000.00 - RM12,000.00 per month
Benefits:
- Health insurance
- Opportunities for promotion
- Professional development
Work Location: In person