Job Overview
The SIEM Team Lead is responsible for managing the day-to-day SIEM operations team, ensuring platform health, log-source availability, detection quality, timely resolution of technical issues, and effective support to SOC operations.
Principal Duties & Responsibilities
Team Leadership & Escalation
- Lead and manage the SIEM team and allocate daily operational activities.
- Act as the primary technical escalation point for complex SIEM issues.
- Support SOC teams during major incidents and provide technical expertise.
Platform Health & Monitoring
- Monitor SIEM platform health, log ingestion, connectors, parsing, and data quality.
- Ensure critical log sources are onboarded and continuously monitored.
- Support onboarding of new log sources, integrations, and security use cases.
Detection Engineering & Tuning
- Review and manage detection rules, correlation rules, tuning, and false-positive reduction.
- Review SIEM changes and ensure appropriate testing and implementation.
Incident, SLA & Coordination
- Coordinate with SOC, infrastructure, cloud, network, and application teams to resolve SIEM-related issues.
- Ensure incidents and service requests are resolved within agreed SLA/OLA timelines.
- Review technical incidents, identify root causes, and implement corrective actions.
Documentation, Governance & Reporting
- Track team activities, pending tasks, technical issues, and operational milestones.
- Maintain SIEM SOPs, runbooks, and technical documentation.
- Participate in DR/BCP testing and ensure SIEM monitoring continuity.
- Provide regular updates and operational reports to management.
Job Specification
Technical Skills
- Strong hands-on experience with Microsoft Sentinel or another enterprise SIEM platform.
- Good knowledge of KQL and log analysis.
- Strong understanding of log ingestion and data connectors.
- Strong understanding of analytics and detection rules.
- Strong understanding of alert tuning and false-positive reduction.
- Strong understanding of data parsing and normalization.
- Strong understanding of SIEM troubleshooting and health monitoring.
- Strong understanding of use-case development and testing.
- Experience handling technical escalations and coordinating with multiple teams.
- Good understanding of incident, change, and problem management.
Good-to-Have Skills
- Experience with Microsoft Sentinel, Defender XDR, Entra ID, and Azure security.
- Knowledge of SOAR, Automation Rules, Logic Apps, and Playbooks.
- Experience with Splunk, QRadar, ArcSight, or Trellix.
- Knowledge of MITRE ATT&CK, Threat Hunting, and Threat Intelligence.
- Experience with SIEM migration or onboarding projects.
- Knowledge of SIEM cost optimization and ingestion monitoring.
- Preferred certifications: Microsoft Security Operations Analyst (SC-200), GCIH or GCIA, ITIL 4.
Experience Required
- 5–7+ years of experience in SIEM, SOC, or cybersecurity operations.
Generic Managerial Skills
- Strong troubleshooting, leadership, and communication skills.
- Ability to manage a team and allocate daily operational activities.
- Strong stakeholder coordination across multiple technical teams.
Education
- Bachelor’s degree in Computer Science, Information Security, or a related field.
Pay: RM9,000.00 - RM11,000.00 per month
Application Question(s):
- How many years of experience do you have in SIEM, SOC, or cybersecurity operations?
- Do you have hands-on experience with Microsoft Sentinel or another enterprise SIEM platform?
- Do you have knowledge of KQL and log analysis?
- Do you have experience leading a team and handling technical escalations?
- Do you hold any relevant certifications (e.g., SC-200, GCIH, GCIA, ITIL 4)? (Yes/No, please specify)
- What is your expected monthly salary?
- What is your notice period?
Work Location: In person