Information Security Operations Lead
Brooks Automation is a rapidly growing technology leader in automation solutions serving the semiconductor and laboratory automation markets. We are seeking a highly skilled and motivated Information Security Operations Lead with expertise in on‑premise and cloud security technology stacks, and a deep understanding of information security, networking, traditional infrastructure, and general cloud environments.
Work Location
Onsite – Johor (or Penang).
Key Responsibilities
Own Security Tool Effectiveness
- Be accountable for the health, configuration, and outcomes of the following security platforms:
- CrowdStrike Falcon
- Microsoft Intune, Entra ID, Conditional Access Security Modules
- DLP and Code42
- Sumo Logic (logging, detection, alerting)
- Palo Alto firewalls
- Cisco Email Security, DMARC/DKIM/SPF
- Cisco Umbrella (DNS security)
- HP Aruba Clearpass
- Tune detections, reduce alert fatigue, and ensure alerts map to real risk.
- Validate controls continuously – not just at deployment.
Security Operations & Incident Response
- Respond to and investigate security alerts across endpoint, identity, network, email, and cloud.
- Perform root‑cause analysis, evidence collection, and impact assessment.
- Lead or support containment and remediation efforts.
- Produce clear, actionable incident write‑ups – what happened, why, and what changes.
Network & Email Security
- Design, implement, and maintain network security controls, including Palo Alto firewall policy and segmentation.
- Own email security posture, phishing protection, and DMARC enforcement.
- Improve DNS‑layer visibility and control with Cisco Umbrella.
Build Operational Maturity
- Create and maintain runbooks, playbooks, and escalation paths.
- Help standardize how security events are handled globally.
- Partner with infrastructure, endpoint, and identity teams to embed security into real designs – not bolt‑ons.
- Mentor junior engineers and raise the bar on execution.
- Any other duties or projects as assigned.
Required Qualifications & Competencies
- At least 7-10 years in security engineering, network engineering, or SecOps with real, hands‑on responsibility.
- Proven experience operating and troubleshooting security tools – not just implementing them.
- Strong understanding of:
- Endpoint and identity security
- Enterprise networking and firewalls
- Email and DNS security
- Logging, detection, and investigation workflows
- Comfortable working incidents end‑to‑end and driving them to closure.
- Clear communicator who can explain technical risk without drama.
Nice to Have
- Cloud experience (Azure, AWS, OCI)
- Scripting or automation (PowerShell, Python)
- Security or network certifications (CISSP, Palo Alto, Cisco, Microsoft)
Work Location & Flexibility
Brooks offers a mix of in‑office and remote work arrangements, depending on the nature of the role and business needs. Specific expectations will be shared during the interview process.
Brooks is committed to fostering a diverse and inclusive workplace and proudly serves as an equal‑opportunity employer. We welcome all qualified applicants regardless of race, color, religion, gender identity or expression, sexual orientation, national origin, genetics, disability, age, veteran status, or any other legally protected characteristics. Diversity enhances our innovative capabilities and strengthens our ability to serve our customers and communities effectively.
For applicants with disabilities requiring accommodations, please contact talentattraction@brooks.com or call +1 (978) 262-2400 to discuss your needs.
Review EEO Law & EEO Statement.