Cyber Defense Senior Specialist
Sg. Besi, Malaysia
⚠️ We'll shut down after Aug 1st - try foo🦍 for all jobs in tech ⚠️
Maxis
Maxis is Malaysia's leading telco company, offering postpaid plans, internet plans, mobile plans, and more. Enhance your connectivity with our reliable services!Are you ready to get ahead in your career?
- We want to empower you to turn your ambitions into achievements.
- We thrive in inclusiveness, diversity and embrace close collaborations for you to create impact for yourself and others.
- Together, we aim to bring the best of technology to help people, businesses and the nation to be ahead in a changing world.
- To realise our vision to become Malaysia’s leading converged solutions company, we are looking for a new talent to innovate and grow with us in a culture that values commitment, performance and possibilities.
Why does this job exist and why is it critical?
Role Summary
This role is responsible for SIEM engineering, security use case lifecycle management, and security orchestration & automation (SOAR). Specialist will manage security partners to ensure SLA compliance and provide technical support for incident response, investigations, and cybersecurity resilience activities.
Principal Accountabilities:
Develop, build, test, and deploy security monitoring use cases in the SIEM platform to enhance detection capabilities, including continuous fine-tuning of rules to improve accuracy.
Manage the full lifecycle of security content, including correlation searches, dashboards, reports, and knowledge base articles.
Engineer and manage the Security Orchestration, Automation, and Response (SOAR) platform, developing playbooks to automate incident response workflows.
Manage the full lifecycle of security Playbooks and Runbooks by creating, updating, and improving them to streamline incident response processes.
Collaborate with security partners and vendors to automate security workflows by developing and implementing playbooks on the SOAR platform or other cloud security tools.
Oversee the log on-boarding process by developing custom integrations for applications, troubleshooting data ingestion issues, and ensuring log telemetries meet security and business monitoring needs.
Oversee work performed by security partners (MSSP) and vendors, ensuring that outcomes are delivered according to the agreed Service Level Agreements (SLA).
Drive security partners (MSSP) to meet key performance indicators (KPIs) by focusing on false positive reduction, aligning use cases with MITRE ATT&CK & CIS frameworks, and improving alert quality.
Provide expert technical support during security incident response and digital forensic investigations by analysing incidents, recommending remediation actions, and preparing detailed reports for stakeholders.
Proactively analyse security events and alerts to identify threat patterns and implement effective countermeasures, leveraging tools like Crowdstrike Falcon/LogScale/Cloud Security, DarkTrace, WAF, Email Security and cloud native security tools.
Participate in threat hunting and forensic activities by collecting intrusion artefacts, performing analysis of log files, and documenting incidents from detection through to resolution.
Participate in and support cybersecurity resilience activities, including tabletop exercises, red/purple team engagements, and Breach & Attack Simulations (BAS).
Collaborate with internal teams to ensure new systems and applications are properly integrated into the SIEM for comprehensive monitoring.
Skill level and requirements
- SIEM Platforms (e.g., Splunk, Google SecOps): Advanced
- SOAR Platforms (e.g., ServiceNow, Google SecOps): Experienced
- Security Use Case & Content Development: Advanced
- Scripting (e.g., Python, PowerShell): Experienced
- Incident Response & Investigation: Advanced
- MITRE ATT&CK Framework: Experienced
- Vendor & Partner Management: Experienced
What’s next?
- Once you’ve applied online, our team will carefully review your application. Due to a high volume of applications, we appreciate your patience to allow for a fair and timely review process.
- Should you be shortlisted for the role, we will send you an invitation via email for a digital interview. You can also check on your application status by logging into your candidate account.
Maxis values diverse voices & people. We hire and reward our employees based on capability & performance — regardless of ethnicity, gender, age, education, religion, nationality or physical ability.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Automation Cloud Compliance CrowdStrike Cyber defense Incident response KPIs Log files MITRE ATT&CK Monitoring PowerShell Python Scripting SecOps SIEM SOAR Splunk
Perks/benefits: Career development Team events
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.