jobs in Virtual Calibre Sdn Bhd

全职 SIEM Team Lead 工作, 薪水 up to MYR 11,000, Virtual Calibre Selangor 公司招聘中 - Ricebowl

SIEM Team Lead

Virtual Calibre Sdn Bhd

分享
保存

工作地点

  • Cyberjaya Selangor Malaysia

职位描述

岗位职责

Job Overview

The SIEM Team Lead is responsible for managing the day-to-day SIEM operations team, ensuring platform health, log-source availability, detection quality, timely resolution of technical issues, and effective support to SOC operations.

Principal Duties & Responsibilities

Team Leadership & Escalation

  • Lead and manage the SIEM team and allocate daily operational activities.
  • Act as the primary technical escalation point for complex SIEM issues.
  • Support SOC teams during major incidents and provide technical expertise.

Platform Health & Monitoring

  • Monitor SIEM platform health, log ingestion, connectors, parsing, and data quality.
  • Ensure critical log sources are onboarded and continuously monitored.
  • Support onboarding of new log sources, integrations, and security use cases.

Detection Engineering & Tuning

  • Review and manage detection rules, correlation rules, tuning, and false-positive reduction.
  • Review SIEM changes and ensure appropriate testing and implementation.

Incident, SLA & Coordination

  • Coordinate with SOC, infrastructure, cloud, network, and application teams to resolve SIEM-related issues.
  • Ensure incidents and service requests are resolved within agreed SLA/OLA timelines.
  • Review technical incidents, identify root causes, and implement corrective actions.

Documentation, Governance & Reporting

  • Track team activities, pending tasks, technical issues, and operational milestones.
  • Maintain SIEM SOPs, runbooks, and technical documentation.
  • Participate in DR/BCP testing and ensure SIEM monitoring continuity.
  • Provide regular updates and operational reports to management.

Job Specification

Technical Skills

  • Strong hands-on experience with Microsoft Sentinel or another enterprise SIEM platform.
  • Good knowledge of KQL and log analysis.
  • Strong understanding of log ingestion and data connectors.
  • Strong understanding of analytics and detection rules.
  • Strong understanding of alert tuning and false-positive reduction.
  • Strong understanding of data parsing and normalization.
  • Strong understanding of SIEM troubleshooting and health monitoring.
  • Strong understanding of use-case development and testing.
  • Experience handling technical escalations and coordinating with multiple teams.
  • Good understanding of incident, change, and problem management.

Good-to-Have Skills

  • Experience with Microsoft Sentinel, Defender XDR, Entra ID, and Azure security.
  • Knowledge of SOAR, Automation Rules, Logic Apps, and Playbooks.
  • Experience with Splunk, QRadar, ArcSight, or Trellix.
  • Knowledge of MITRE ATT&CK, Threat Hunting, and Threat Intelligence.
  • Experience with SIEM migration or onboarding projects.
  • Knowledge of SIEM cost optimization and ingestion monitoring.
  • Preferred certifications: Microsoft Security Operations Analyst (SC-200), GCIH or GCIA, ITIL 4.

Experience Required

  • 5–7+ years of experience in SIEM, SOC, or cybersecurity operations.

Generic Managerial Skills

  • Strong troubleshooting, leadership, and communication skills.
  • Ability to manage a team and allocate daily operational activities.
  • Strong stakeholder coordination across multiple technical teams.

Education

  • Bachelor’s degree in Computer Science, Information Security, or a related field.

Pay: RM9,000.00 - RM11,000.00 per month

Application Question(s):

  • How many years of experience do you have in SIEM, SOC, or cybersecurity operations?
  • Do you have hands-on experience with Microsoft Sentinel or another enterprise SIEM platform?
  • Do you have knowledge of KQL and log analysis?
  • Do you have experience leading a team and handling technical escalations?
  • Do you hold any relevant certifications (e.g., SC-200, GCIH, GCIA, ITIL 4)? (Yes/No, please specify)
  • What is your expected monthly salary?
  • What is your notice period?

Work Location: In person

重要安全守则

申请工作时,切勿提供您的银行或信用卡详细资料。不要转账或完成无关的在线调查问卷。如果您发现可疑内容,请举报此招聘广告。

了解更多