jobs in Maybank

全职 Lead Security Engineer (SIEM) I IT Security 工作, 薪水, Maybank Federal Territory 公司招聘中 - Ricebowl

Lead Security Engineer (SIEM) I IT Security

KL City, Federal Territory

分享
保存

工作地点

  • Kuala Lumpur Federal Territory Malaysia

职位描述

岗位职责

Job Purposes

  • Lead the overall architecture, engineering roadmap, and continuous improvement of the enterprise SIEM platform.
  • Define SIEM engineering standards, governance frameworks, operating models, and best practices across the organisation.
  • Serve as the primary technical authority and escalation point for all SIEM engineering-related matters.
  • Provide strategic recommendations on platform scalability, modernization, optimization, and future-state capabilities.
  • Drive collaboration across SOC, Incident Response, Threat Intelligence, Cloud, Infrastructure, and Application teams.


Job Responsibilities

  • Architect, build, and operate large-scale SIEM platforms across on-premises, cloud, and hybrid environments with high availability, reliability, performance, and cost efficiency.
  • Lead the design, implementation, and maintenance of SIEM infrastructure components.
  • Own capacity planning, EPS/TPS modelling, storage optimization, compute utilization, search concurrency, workload management, and licensing optimization.
  • Drive platform performance tuning initiatives to ensure operational excellence and service stability.
  • Lead onboarding of enterprise log sources, including endpoint, network, cloud, identity, SaaS, and custom applications.
  • Champion automation and engineering efficiency through Infrastructure as Code (IaC), CI/CD pipelines, configuration management, and content version control.
  • Lead SIEM deployment, upgrade, and configuration automation initiatives.
  • Establish repeatable engineering practices that improve platform reliability, consistency, and operational efficiency.
  • Lead the design, review, and optimization of high-fidelity detection use cases aligned with the MITRE ATT&CK framework.
  • Translate evolving threat scenarios, adversary tactics, techniques, and procedures (TTPs) into scalable and effective detection capabilities.
  • Oversee detection tuning activities to improve detection accuracy, reduce false positives, and optimize SOC analyst workload.
  • Partner with SOC and Incident Response teams to enhance alert quality, investigation workflows, and response effectiveness.
  • Ensure SIEM content and data sources are aligned with operational security and incident response requirements.
  • Support threat hunting initiatives by enabling efficient search, analytics, and data visibility capabilities.
  • Act as the senior escalation point during SIEM platform incidents, outages, and major service disruptions.
  • Lead root cause analysis and remediation efforts involving complex issues across operating systems, databases, networks, storage, queries, and data pipelines.
  • Provide technical leadership during major cybersecurity incidents and post-incident reviews.
  • Drive continuous improvement initiatives based on lessons learned and operational insights.
  • Provide technical leadership, coaching, and mentorship to SIEM Engineers, Detection Engineers, and junior security team members.
  • Conduct knowledge-sharing sessions and establish engineering excellence within the team.
  • Review engineering designs, detection content, and platform changes to ensure adherence to standards and best practices.
  • Foster a culture of continuous learning, innovation, and operational excellence.


Job Requirements

  • 8+ years of hands-on experience in security engineering, SIEM engineering, or large-scale security monitoring platforms (on-prem, cloud or hybrid).
  • Proven experience supporting 24x7 SOC environments and high-volume log ingestion.
  • Demonstrated ownership of SIEM architecture, performance tuning, and detection engineering.
  • SIEM Platform Expertise – Deep hands-on experience designing, operating, and optimizing enterprise SIEM platforms, including architecture, performance tuning, and capacity planning.
  • Security Detection & SOC Knowledge – Strong understanding of SOC operations, incident response workflows, and the ability to design and tune effective, high fidelity security detections.
  • Systems, Cloud & Infrastructure Skills – Solid foundation in Linux, networking, and cloud platforms, with experience integrating and managing security telemetry across hybrid environments.
  • Automation & Engineering Discipline – Proficiency in scripting and automation to standardize SIEM deployments, content management, and operational processes.
  • Advanced Troubleshooting & Problem Solving – Ability to diagnose and resolve complex, multi-layer technical issues under pressure in mission-critical environments.
  • Technical Leadership & Collaboration – Acts as a technical authority, mentors engineers, and collaborates effectively across SOC, cloud, and infrastructure teams to deliver secure outcomes.

重要安全守则

申请工作时,切勿提供您的银行或信用卡详细资料。不要转账或完成无关的在线调查问卷。如果您发现可疑内容,请举报此招聘广告。

了解更多