Job Role: SOC Analyst
Employer: IT consulting and technology services, including software development, system integration, digital transformation, cybersecurity, analytics, enterprise solutions, and IT infrastructure.
Location: Kuala Lumpur, Malaysia
Job Type: Full Time - Permanent
Working Mode: Rotational Shift
Experience: 7–9 years of experience in cyber security operations, with at least 3–4 years in a Tier 2 SOC, incident response, or security engineering role; prior experience working alongside an MSSP-managed Tier 1 SOC is strongly preferred.
Applicant: Local Malaysian citizens only
JOB DESCRIPTION
- Act as the primary Point of Contact for the MSSP's Tier 1 SOC team, monitoring and managing SIEM (Azure Sentinel) alerts, CrowdStrike Falcon EDR alerts, and ITSM ticket queues across Malaysian and other country properties.
- Analyze and investigate security incidents, lead incident response in accordance with the Cyber Incident Response (CIR) plan, and take action to mitigate threats and contain incidents within defined SLAs.
- Perform Root Cause Analysis (RCA) on escalated incidents and generate incident reports for both technical teams and non-technical stakeholders, including weekly and monthly summary reporting to executives.
- Monitor identity and access management (Entra-ID and on-prem AD), detecting suspicious account activity, abuse of privileges, MFA gaps, and risky sign-ins.
- Plan and coordinate monthly vulnerability scanning, patch management reviews of High and Critical CVEs, quarterly firewall configuration audits, and user access reviews for Joiners/Movers/Leavers.
- Develop and maintain security policies, Incident Response playbooks, Disaster Recovery and Business Continuity Plans, and maintain the information security risk register and risk management framework.
- Write and tune detection rules, automation scripts, and use-cases in Azure Sentinel; participate in quarterly fine-tuning reviews and IOC-driven and hypothesis-based threat hunting activities.
- Conduct Third Party Risk Management (TPRM) assessments of suppliers and act as the YTL Hotels security representative on the Cyber Security Task Force.
- Deliver cyber security awareness training, phishing simulations, and threat intelligence briefings to client's IT teams and users across Malaysia and other country properties.
JOB REQUIREMENTS
- 7–9 years of experience in cyber security operations, with at least 3–4 years in a Tier 2 SOC, incident response, or security engineering role; prior experience working alongside an MSSP-managed Tier 1 SOC is strongly preferred.
- Hands-on expertise with SIEM platforms — specifically Microsoft Azure Sentinel — including KQL query authoring, analytics rule creation, log source onboarding, and detection tuning; experience with Microsoft 365 and Entra-ID security monitoring (MFA, Conditional Access, PIM, risky sign-ins).
- Strong experience with endpoint detection and response (CrowdStrike Falcon EDR or comparable), including alert triage, IOC management, detection rule management, and AV signature upkeep.
- Working knowledge of firewall technologies (Fortinet FortiGate) and network security monitoring across distributed, multi-site environments.
- Proven incident response experience, including leading investigations, containment coordination, RCA, and producing executive-level incident reports.
- Solid understanding of security frameworks and standards such as NIST CSF and ISO 27001, with experience supporting compliance audits, vulnerability management programs, and user access reviews.
- Excellent communication and stakeholder management skills, with the ability to act as a SPOC, liaise with hotel IT teams across Malaysia and other country, and brief both technical and executive audiences.
Other Skill Sets (Plus point)
- Relevant certifications such as GCIA, CEH, ECIH, GCIH, or Microsoft Security certifications (e.g., SC-200, SC-100) are highly desirable.
- Experience in the hospitality, travel, or multi-property/retail sector, or supporting geographically distributed operations across APAC and EMEA.
- Familiarity with threat intelligence platforms, threat hunting methodologies, and open-source intelligence feeds.
- Scripting and automation skills (e.g., PowerShell, Python, Logic Apps) for automating detection and response workflows.
- Exposure to PKI/certificate management, IdAM, and Third Party Risk Management (TPRM) processes is a plus.