L2 SOC Analyst

Neuron Solutions Sdn Bhd

Kuala Lumpur

On-site

MYR 180,000 - 280,000

Full time

10 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Neuron Solutions Sdn Bhd is seeking a senior security operations professional to serve as the Tier 1 SOC SPOC for MSSP operations across Malaysia and the UK. The role focuses on managing Microsoft Sentinel and CrowdStrike Falcon EDR while guiding incident response per CIR plans.

You will lead RCA efforts, produce incident reports, and deliver updates to technical teams, stakeholders, and executives, with emphasis on proactive monitoring and compliance alignment.

Qualifications

  • Bachelor's degree in Cyber Security, Information Technology, or related field.
  • 7–9 years in cyber security operations, including 3–4 years in Tier 2 SOC / IR / security engineering.
  • Hands-on with Microsoft Sentinel (KQL, analytics rules, onboarding, tuning) and CrowdStrike Falcon EDR.
  • Strong knowledge of Microsoft 365 and Entra ID security monitoring (MFA gaps, risky sign-ins).
  • Experience with Fortinet FortiGate firewalls and multi-site security monitoring.
  • Solid incident response, RCA, and executive-level reporting; familiarity with NIST/ISO controls.

Responsibilities

  • Serve as the primary SPOC for MSSP's Tier 1 SOC team across Malaysia and UK.
  • Manage SIEM alerts, CrowdStrike EDR alerts, and ITSM tickets.
  • Investigate and respond to security incidents per CIR plan with SLAs.
  • Lead RCA, prepare incident reports, and deliver security updates to teams and execs.
  • Monitor Entra ID and on-prem AD for suspicious activity, MFA gaps, and risky sign-ins.
  • Coordinate vulnerability scanning, CVE reviews, firewall audits, and access reviews.
  • Develop and maintain security policies, IR playbooks, DR/BCP, risk registers, and frameworks.
  • Create and fine-tune Sentinel detection rules, KQL queries, automation scripts, and hunting use cases.

Skills

Microsoft Sentinel
KQL queries
Security incident response
CrowdStrike Falcon EDR
Entra ID / AD monitoring
Vulnerability management
NIST CSF / ISO 27001
Stakeholder communication
Fortinet FortiGate
Threat hunting

Education

Bachelor's degree in Cyber Security or related field

Tools

Fortinet FortiGate
Entra ID

Job description

  • Serve as the primary Point of Contact (SPOC) for the MSSP's Tier 1 SOC team, managing SIEM (Microsoft Sentinel), CrowdStrike Falcon EDR alerts, and ITSM tickets across Malaysia and UK properties.
  • Investigate and respond to security incidents in line with the Cyber Incident Response (CIR) plan, ensuring timely threat containment and remediation within defined SLAs.
  • Lead Root Cause Analysis (RCA), prepare incident reports, and deliver weekly and monthly security updates to technical teams, stakeholders, and executives.
  • Monitor Entra ID and on-premises Active Directory for suspicious account activity, privilege abuse, MFA gaps, and risky sign-ins.
  • Coordinate vulnerability scanning, High and Critical CVE patch reviews, firewall configuration audits, and Joiner/Mover/Leaver access reviews.
  • Develop and maintain security policies, incident response playbooks, Disaster Recovery and Business Continuity Plans, risk registers, and risk management frameworks.
  • Create and fine-tune Sentinel detection rules, KQL queries, automation scripts, and threat hunting use cases.

Requirements

  • Bachelor's degree in Cyber Security, Information Technology, or a related field.
  • 7–9 years of experience in cyber security operations, including 3–4 years in a Tier 2 SOC, incident response, or security engineering role. Experience working with an MSSP-managed Tier 1 SOC is preferred.
  • Hands-on experience with Microsoft Sentinel, including KQL queries, analytics rules, log source onboarding, and detection tuning.
  • Strong knowledge of Microsoft 365 and Entra ID security monitoring, including MFA, Conditional Access, PIM, and risky sign-ins.
  • Experience with CrowdStrike Falcon EDR or comparable platforms, covering alert triage, IOC management, detection rules, and endpoint protection.
  • Working knowledge of Fortinet FortiGate firewalls and network security monitoring across multi-site environments.
  • Proven experience in incident response, threat containment, RCA, and executive-level incident reporting.
  • Good understanding of NIST CSF, ISO 27001, vulnerability management, compliance audits, and user access reviews.
  • Strong communication and stakeholder management skills, with the ability to liaise with technical teams and executive stakeholders across Malaysia and the UK.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

L2 SOC Engineer
L2 SOC Engineer

Neuron Solutions Sdn. Bhd. • Kuala Lumpur

Hybrid
MYR 180,000 - 280,000
Senior Incident Response Specialist
Senior Incident Response Specialist

Starhub Ltd • Petaling Jaya

On-site
MYR 60,000 - 90,000
Senior SOC Analyst: Incident Response & SIEM Expert
Senior SOC Analyst: Incident Response & SIEM Expert

Neuron Solutions Sdn Bhd • Kuala Lumpur

On-site
MYR 180,000 - 280,000
L2 SOC Analyst - Sentinel
L2 SOC Analyst - Sentinel

Oxydata Software Sdn Bhd • Petaling Jaya

Hybrid
MYR 80,000 - 120,000
Cybersecurity Analyst L2/L3
Cybersecurity Analyst L2/L3

Tech Staffing • Kuala Lumpur

On-site
MYR 90,000 - 150,000
L2 SOC Analyst - Sentinel
L2 SOC Analyst - Sentinel

Oxydata Software • Petaling Jaya

Hybrid
MYR 72,000 - 110,000
SOC Analyst — Threat Detection, Hunting & Response
SOC Analyst — Threat Detection, Hunting & Response

PERSOL Workforce Solutions Malaysia Sdn Bhd • Kuala Lumpur

On-site
MYR 60,000 - 100,000
L2 SOC Engineer
L2 SOC Engineer

Oxydata Software Sdn Bhd • Petaling Jaya

Hybrid
MYR 90,000 - 130,000
Senior Incident Response Specialist
Senior Incident Response Specialist

StarHub • Petaling Jaya

On-site
MYR 90,000 - 130,000
Senior Cyber Security Consultant (SOC) Cyber security Kuala Lumpur
Senior Cyber Security Consultant (SOC) Cyber security Kuala Lumpur

S-RM Intelligence and Risk Consulting • Kuala Lumpur

Hybrid
MYR 120,000 - 180,000