Cyber Security Operations Lead

EPAM Systems

Malaysia

On-site

MYR 180,000 - 280,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

EPAM Systems in Malaysia is seeking a Cyber Security Operations Lead to own detection and incident response in a hedge fund environment, tuning Microsoft Sentinel and Defender. You will collaborate with an outsourced SOC/MDR while supporting regional offices with threat hunting, reporting and continuous control improvements.

The role requires hands-on experience in security operations, detection engineering and incident response, plus strong governance of SLAs and threat intelligence

Qualifications

  • Proven experience in security operations, SOC leadership, detection engineering or incident response.
  • Hands-on expertise with Microsoft Sentinel, including analytics rules, workbooks and KQL.
  • Strong background with Microsoft Defender for Endpoint and Defender for Cloud.
  • Experience with outsourced SOC/MDR governance and SLA management.
  • Knowledge of vulnerability management, patch governance and CSPM.
  • Ability to report metrics to senior leaders.
  • Familiarity with regulated financial services is a plus.
  • Certifications like SC-200, AZ-500, GCIA, GCIH, or CISSP are desirable.

Responsibilities

  • Own and manage detection content and threat-hunting workflows.
  • Govern outsourced SOC/MDR provider including onboarding and SLA performance.
  • Maintain security logging across endpoints, identity, network and cloud.
  • Triage escalations, coordinate containment and incident communications.
  • Lead incident response lifecycle: detection to closure.
  • Oversee vulnerability scanning, remediation tracking and cloud posture improvements.
  • Deliver security operations reporting with KRIs, KPIs, MTTD, MTTR and vendor performance.
  • Coach analysts and maintain runbooks, playbooks and audit-ready docs.

Job description

About the role

We are seeking a Cyber Security Operations Lead . You will own detection and incident response in a regulated hedge fund environment, partnering with an outsourced SOC/MDR while tuning Microsoft Sentinel and Microsoft Defender. Based in Malaysia, you will support Singapore and regional offices with hands-on threat hunting, reporting and continuous control improvements.

Responsibilities
  • Own and enhance Microsoft Sentinel detection content including analytics rules, workbooks, Kusto Query Language (KQL) and threat-hunting workflows
  • Govern the outsourced SOC/MDR provider including onboarding, service reviews, escalation quality and service level agreement (SLA) performance
  • Maintain security logging coverage across endpoint, identity, network and cloud environments
  • Triage SOC escalations, assess severity, coordinate containment and drive incident communications
  • Lead critical incident response through detection, containment, eradication, recovery and closure
  • Oversee vulnerability scanning, remediation tracking, patch SLA compliance and cloud security posture improvements
  • Deliver security operations reporting including key risk indicators (KRIs), key performance indicators (KPIs), mean time to detect (MTTD), mean time to respond (MTTR) and vendor performance
  • Coach the Security Operations Analyst while maintaining runbooks, escalation paths, playbooks and audit-ready documentation
Requirements
  • Proven experience in security operations, security operations center (SOC) leadership, detection engineering or incident response
  • Hands-on expertise with Microsoft Sentinel including analytics rules, workbooks, Kusto Query Language (KQL), threat hunting and detection tuning
  • Strong background with Microsoft Defender, especially Microsoft Defender for Endpoint and Microsoft Defender for Cloud
  • Demonstrated ability to manage or partner with an outsourced SOC/MDR provider including SLA governance and escalation management
  • Working knowledge of incident triage, response coordination, post-incident reviews and detection improvement
  • Practical understanding of vulnerability management, patch governance, threat intelligence and cloud security posture management (CSPM)
  • Ability to collaborate with security architecture, engineering and project delivery teams to improve detection and response outcomes
  • Clear communication with confidence translating technical metrics into business-relevant reporting for senior leaders
  • Nice to have Experience working in regulated financial services such as asset management, investment management or hedge funds
  • Microsoft certifications such as SC-200 or AZ-500 or industry certifications such as GCIA, GCIH or CISSP
  • Experience integrating threat intelligence feeds and indicators of compromise (IOCs) into detection workflows
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Operations Lead - Threat Hunting & Sentinel
Cyber Security Operations Lead - Threat Hunting & Sentinel

EPAM Systems • Malaysia

On-site
MYR 180,000 - 280,000
Cloud Security Engineer (Azure)
Cloud Security Engineer (Azure)

EPAM Systems • Malaysia

On-site
MYR 180,000 - 320,000
Security Operations Center Lead
Security Operations Center Lead

Altera • Bayan Lepas

On-site
MYR 180,000 - 280,000
SOC & Cyber Incident Response Lead
SOC & Cyber Incident Response Lead

Epergne Solutions • Kuala Lumpur

On-site
MYR 100,000 - 140,000
Senior SOC Analyst / SOC Engineer (L3)
Senior SOC Analyst / SOC Engineer (L3)

Jobstreet Malaysia • Klang City

On-site
MYR 120,000 - 180,000
Senior Cyber Security Consultant (SOC) Cyber security Kuala Lumpur
Senior Cyber Security Consultant (SOC) Cyber security Kuala Lumpur

S-RM Intelligence and Risk Consulting • Kuala Lumpur

Hybrid
MYR 120,000 - 180,000
Senior Security Analyst
Senior Security Analyst

Logicalis • Kuala Lumpur

On-site
MYR 180,000 - 300,000
Cybersecurity Manager
Cybersecurity Manager

Flintex Consulting • Kuala Lumpur

On-site
MYR 240,000 - 360,000
Senior SOC Consultant
Senior SOC Consultant

S-RM • Kuala Lumpur

Hybrid
MYR 180,000 - 240,000
Hybrid work model
Global collaboration
L2 - Security Analyst
L2 - Security Analyst

Ensign Infosecurity • Kuala Lumpur

On-site
MYR 60,000 - 100,000