JOB SUMMARY:
We are looking for a Cybersecurity Engineer to support the deployment, integration, maintenance, and optimization of SIEM and EDR platforms for internal and customer environments. The role requires a combination of cybersecurity knowledge, system administration, network troubleshooting, and security platform engineering capabilities.
The engineer will work closely with SOC analysts, project teams, and customers to ensure security solutions are properly deployed, stable, scalable, and operationally effective. This includes onboarding log sources, troubleshooting data collection issues, supporting endpoint security deployments, and assisting in security monitoring platform enhancements.
REQUIREMENTS:
Technical Requirements
- Diploma or Bachelor’s Degree in Cybersecurity, Information Technology, Computer Science, Network Engineering, or related field.
- Minimum 2–3 years of experience in cybersecurity engineering, SIEM, SOC, or infrastructure security implementation.
- Basic to intermediate knowledge of cybersecurity concepts and security operations.
- Experience with SIEM platforms such as Splunk, Wazuh, Microsoft, Elastic, or similar technologies.
- Familiarity with EDR/XDR platforms such as CrowdStrike, Microsoft, SentinelOne, or equivalent.
- Knowledge of Windows and Linux system administration.
- Familiarity with Linux distributions such as RHEL, Ubuntu, CentOS, or Debian.
- Basic understanding of networking concepts including TCP/IP, DNS, DHCP, VPN, routing, firewall, and VLAN.
- Experience troubleshooting log forwarding, connectivity, agent communication, and system performance issues.
- Basic scripting or automation knowledge using Bash, PowerShell, or Python is an advantage.
- Understanding of log formats and protocols such as Syslog, WinEventLog, NetFlow, JSON, and API-based integrations.
- Familiarity with virtualization and cloud environments is an added advantage.
Soft-skill Requirements
- Strong troubleshooting and analytical skills.
- Good communication and documentation abilities.
- Ability to work independently and within a team environment.
- Willingness to learn new cybersecurity technologies and platforms.
- Able to support after-hours maintenance or urgent troubleshooting when required.
Preferred Certifications (Optional)
- CompTIA Security+
- Red Hat RHCSA
- Vendor-specific SIEM or EDR certifications
KEY RESPONSIBILITIES:
- Deploy, configure, and maintain SIEM, EDR, and related cybersecurity platforms.
- Perform log source onboarding, parser validation, and troubleshooting for security devices, servers, applications, and cloud platforms.
- Support endpoint security deployment and troubleshooting across Windows and Linux environments.
- Manage and maintain SIEM collectors, agents, forwarders, and connectors.
- Perform system administration tasks for Linux and Windows servers supporting cybersecurity platforms.
- Troubleshoot network connectivity, firewall rules, DNS, routing, and communication issues related to security solutions.
- Monitor SIEM platform health, storage utilization, ingestion performance, and service availability.
- Assist SOC analysts during incident investigations by validating logs, telemetry, and data availability.
- Work with customers and internal teams during implementation, testing, onboarding, and maintenance activities.
- Create and maintain technical documentation, deployment guides, architecture diagrams, and operational procedures.
- Support patching, upgrades, tuning, and optimization activities for security platforms.
- Participate in proof-of-concept (POC), testing, and deployment projects for new cybersecurity technologies.
- Assist in automation and integration activities using scripts, or APIs where applicable.
Pay: RM3,000.00 - RM5,000.00 per month
Benefits:
- Opportunities for promotion
- Professional development
Work Location: In person