L2 - Security Analyst

Ensign Infosecurity

Kuala Lumpur

On-site

MYR 60,000 - 100,000

Full time

7 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jora Malaysia is seeking a Level 2 Security Analyst in a multi-tenant MSSP environment. You will serve as an advanced escalation point for Tier 1 analysts, investigating complex threats, guiding incident response, and improving detection across multiple client environments.

You will analyze escalated alerts, conduct in-depth investigations with SIEM/EDR/NDR, perform malware analysis, containment and recovery, and mentor Tier 1 staff.

Qualifications

  • Bachelor’s degree in Cybersecurity, IT, CS or related field, or equivalent.
  • 2–4 years of experience in a SOC or similar cybersecurity environment.
  • Experience in MSSP or multi-tenant environment is highly desirable.

Responsibilities

  • Analyze and respond to escalated alerts across multiple clients.
  • Conduct in-depth investigations using SIEM, EDR, NDR, and firewall logs.
  • Perform malware analysis, log correlation, and network traffic analysis.
  • Execute containment, eradication, and recovery using runbooks.
  • Escalate with Level 3 analysts for high-severity incidents.
  • Provide guidance and mentoring to Tier 1 analysts.
  • Identify gaps and improve correlation rules and alerts.
  • Support proactive threat hunting using IOCs and threat intel.
  • Monitor threat intel feeds and correlate with client telemetry.
  • Document investigations and incident outcomes clearly.
  • Contribute to SOC process improvements with runbooks.
  • Ensure activities comply with SLAs and policies.
  • Participate in onboarding and ensure monitoring tools configured.
  • Attend incident reviews and provide root cause analysis.

Skills

SIEM platforms
EDR tools
NDR
SOAR platforms
Networking & log analysis
Malware analysis
Scripting (Python, PowerShell)
Case management tools
Documentation & reporting
Client-facing communication

Education

Bachelor’s degree in Cybersecurity/IT/CS or equivalent

Tools

Splunk
Microsoft Sentinel
QRadar
CrowdStrike
SentinelOne
Microsoft Defender
Darktrace
Corelight
Cortex XSOAR
Jira
ServiceNow
TheHive

Job description

Jora Malaysia will close on 9th September 2026. Thank you for being with us, we are cheering you on as you continue your career journey.

As a Level 2 Security Analyst in a Managed Security Service Provider (MSSP) environment, you will serve as an advanced escalation point for Tier 1 analysts, handling complex alerts and security incidents across multiple client environments. Your primary responsibility is to investigate threats in-depth, guide incident response efforts, enhance detection capabilities, and ensure clients are protected with timely and accurate responses. This role demands strong technical, analytical, and communication skills to succeed in a fast-paced, multi-tenant SOC.

Key Responsibilities:

Analyze and respond to escalated alerts from Tier 1 analysts across multiple clients.

Conduct in-depth investigations using SIEM, EDR, NDR, firewall logs, and other security tools.

Perform malware analysis, log correlation, and network traffic analysis to identify attack vectors.

Execute containment, eradication, and recovery procedures using predefined runbooks and playbooks.

Escalate and coordinate with Level 3 analysts or incident response teams for high-severity incidents.

Provide technical guidance, support, and mentoring to Tier 1 analysts.

Identify gaps in detection capabilities and recommend improvements in correlation rules, tuning, and alerts.

Support proactive threat hunting initiatives based on IOCs, TTPs, and contextual threat intelligence.

Monitor external threat intelligence feeds and correlate them with client telemetry to identify potential risks.

Maintain clear and accurate documentation of all investigations, actions taken, and incident outcomes.

Contribute to the continuous improvement of SOC processes, including the development of SOPs, playbooks, and runbooks.

Ensure all activities are performed in compliance with client-specific SLAs, internal policies, and applicable regulatory standards.

Participate in client-specific onboarding activities and ensure monitoring tools are correctly configured.

Join incident review meetings and provide root cause analysis and post-incident reporting when required.

Handle shift handovers with detailed summaries and ensure continuity of investigations and tasks.

Participate in internal knowledge-sharing sessions and contribute to SOC-wide initiatives and improvements.

Requirements:
Education & Experience:

Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or related field—or equivalent work experience.

2–4 years of experience in a Security Operations Center or similar cybersecurity environment.

Experience working in an MSSP or multi-tenant environment is highly desirable.

Technical Skills:

Strong experience with SIEM platforms (e.g., Splunk, Sentinel, QRadar).

Hands-on experience with EDR tools (e.g., CrowdStrike, SentinelOne, Microsoft Defender).

Familiarity with NDR and SOAR platforms is a plus (e.g., Darktrace, Corelight, Cortex XSOAR).

Strong understanding of networking protocols, log analysis, and system administration (Windows/Linux).

Knowledge of malware behaviors, phishing techniques, and MITRE ATT&CK framework.

Experience with scripting and automation tools (e.g., Python, PowerShell) is a plus.

Familiarity with case management tools (e.g., Jira, ServiceNow, TheHive).

Certifications (preferred):

CompTIA Security+, CySA+, or equivalent.

GIAC certifications (e.g., GCIH, GCIA, GCFA).

CEH, or vendor-specific certifications (e.g., Microsoft SC-200, CrowdStrike CCFR).

Strong analytical and problem-solving skills.

Excellent written and verbal communication—especially in client-facing documentation and briefings.

Ability to handle multiple investigations and prioritize effectively under pressure.

Customer-centric mindset with attention to SLA adherence and service quality.

Collaborative, team-oriented, and proactive with continuous learning attitude.

Participation in shift rotations (24/7 support model, if applicable), including weekends and public holidays.

On-call support may be required depending on client SLAs and incident severity.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

L2 SOC Analyst
L2 SOC Analyst

Pride Global • Kuala Lumpur

On-site
MYR 67,000 - 100,000
Senior Specialist - Security Operation Analyst (L2)
Senior Specialist - Security Operation Analyst (L2)

Commerz Global Service Solutions • Selangor

On-site
MYR 70,000 - 120,000
SENIOR SOC ANALYST L2
SENIOR SOC ANALYST L2

TechLab Security • Shah Alam

On-site
MYR 120,000 - 180,000
Senior SOC Analyst
Senior SOC Analyst

Pride Global • Kuala Lumpur

On-site
MYR 120,000 - 180,000
L2 SOC Analyst / Engineer
L2 SOC Analyst / Engineer

Insyghts Security • Iskandar Puteri

On-site
MYR 120,000 - 180,000
Transfer opportunity to Singapore
L1 - SOC Analyst
L1 - SOC Analyst

Dwell Technologies Sdn. Bhd. • Kuala Lumpur

On-site
MYR 54,000 - 90,000
Security Analyst (Intelligence - Operations)
Security Analyst (Intelligence - Operations)

GXS Bank • Selangor

On-site
MYR 90,000 - 130,000
Cyber Security Analyst/Support (SOC)
Cyber Security Analyst/Support (SOC)

MSP Systems • Kuala Lumpur

On-site
MYR 60,000 - 90,000
Senior SOC Analyst / SOC Engineer (L3)
Senior SOC Analyst / SOC Engineer (L3)

Jobstreet Malaysia • Klang City

On-site
MYR 120,000 - 180,000
SOC Analyst L2
SOC Analyst L2

PERSOL • Kuala Lumpur

On-site
MYR 60,000 - 90,000
Health insurance