L2 SOC Analyst / Engineer

Insyghts Security Sdn Bhd

Iskandar Puteri

On-site

MYR 60,000 - 100,000

Full time

8 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Insyghts Security Sdn Bhd is seeking a skilled L2 SOC Analyst/Engineer to act as the escalation point for the L1 SOC team and lead advanced investigations across endpoints, networks, cloud, and identity telemetry.

The role focuses on root-cause analysis, threat hunting, and driving detection engineering to mature the security monitoring program, including incident containment and post-incident lessons learned.

Qualifications

  • 3+ years of hands-on SOC experience with progression to L2/senior analyst.
  • Strong knowledge of the attack lifecycle, MITRE ATT&CK framework.
  • Hands-on experience with SIEM platforms and writing/tuning correlation rules.
  • Cloud security monitoring experience (AWS/Azure/GCP) and incident response processes.

Responsibilities

  • Serve as primary escalation point for L1 analysts on alerts requiring deeper analysis
  • Conduct in-depth investigations across endpoint, network, cloud, identity, and application telemetry
  • Correlate data across SIEM, EDR, NDR, cloud logs to determine scope and impact
  • Distinguish true positives from false positives and refine triage logic
  • Lead containment, eradication, and recovery during security incidents
  • Design, build, test, and tune detection rules/use cases (SIEM, EDR, Sigma)
  • Mentor and provide guidance to L1 analysts

Skills

SOC experience
Threat hunting
Incident response
MITRE ATT&CK
Scripting (Python/PowerShell)
Communication skills

Tools

Splunk
Sentinel
QRadar
Elastic
CrowdStrike
Microsoft Defender
SentinelOne
TrendAI

Job description

We are looking for a L2 SOC Analyst/Engineer to serve as the escalation point for our L1 SOC team. This role owns in-depth investigation of escalated alerts, performs root cause analysis, leads incident response activities, and drives detection engineering and threat hunting initiatives to continuously mature our security monitoring program. You will be a technical anchor for the SOC - turning raw alerts into confirmed incidents, confirmed incidents into lessons learned, and lessons learned into better detections.

Key responsibilities

Serve as the primary technical escalation point for L1 analysts on alerts requiring deeper analysis

Conduct in-depth investigations across endpoint, network, cloud, identity, and application telemetry

Correlate data across multiple tools/log sources (SIEM, EDR, NDR, cloud logs, identity providers) to determine scope and impact

Distinguish true positives from false positives and refine triage logic accordingly

Perform root cause analysis on confirmed incidents to determine initial vector, method, and any control gaps

Document attack timelines/kill chains and produce clear technical findings for stakeholders

Lead or co-lead containment, eradication, and recovery activities for security incidents

Design, build, test, and tune detection rules/use cases (SIEM correlation rules, EDR detections, Sigma rules, etc.)

Conduct proactive, hypothesis-driven threat hunts using threat intelligence, ATT&CK TTPs, and anomaly analysis

Mentor and provide technical guidance to L1 analysts, including escalation reviews and knowledge transfer

About you

3+ years of hands-on SOC experience, with demonstrated progression into L2/senior analyst responsibilities

Strong understanding of the attack lifecycle, common TTPs, and the MITRE ATT&CK framework

Hands-on experience with SIEM platforms (e.g., Splunk, Sentinel, QRadar, Elastic) - writing/tuning correlation rules and queries

Experience with EDR/XDR tools (e.g., CrowdStrike, Microsoft Defender, SentinelOne, TrendAI) for endpoint investigation

Solid grasp of networking fundamentals (TCP/IP, DNS, HTTP/S, proxies) and ability to read packet captures

Experience with incident response processes: containment, eradication, recovery, and post-incident reporting

Familiarity with cloud security monitoring (AWS/Azure/GCP logs, IAM, CloudTrail or equivalent)

Scripting/automation skills (Python, PowerShell, or similar) for detection logic, parsing, or workflow automation

Excellent written and verbal communication skills - able to translate technical findings for non-technical stakeholders

Ability to remain calm and methodical under pressure during active incidents

*Opportunity to be transferred to Singapore office for suitable candidates.

Researching careers? Find all the information and tips you need on career advice.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

L2 SOC Analyst / Engineer
L2 SOC Analyst / Engineer

Insyghts Security • Iskandar Puteri

On-site
MYR 120,000 - 180,000
Transfer opportunity to Singapore
L2 SOC Analyst / Security Delivery Consultant
L2 SOC Analyst / Security Delivery Consultant

ABP Group • Kuala Lumpur

On-site
MYR 60,000 - 120,000
Security Analyst (Intelligence & Operations)
Security Analyst (Intelligence & Operations)

GXS Bank • Petaling Jaya

On-site
MYR 90,000 - 150,000
Senior SOC Analyst: Incident Response & Threat Hunting
Senior SOC Analyst: Incident Response & Threat Hunting

Insyghts Security Sdn Bhd • Iskandar Puteri

On-site
MYR 60,000 - 100,000
Lead L2 SOC Analyst: Threat Detection & Incident Response
Lead L2 SOC Analyst: Threat Detection & Incident Response

Insyghts Security • Iskandar Puteri

On-site
MYR 120,000 - 180,000
Transfer opportunity to Singapore
L2 - Security Analyst
L2 - Security Analyst

Ensign Infosecurity • Kuala Lumpur

On-site
MYR 60,000 - 100,000
Security Analyst (Intelligence - Operations)
Security Analyst (Intelligence - Operations)

GXS Bank • Selangor

On-site
MYR 90,000 - 130,000
Senior Security Analyst
Senior Security Analyst

Logicalis • Kuala Lumpur

On-site
MYR 180,000 - 300,000
Senior SOC Analyst / SOC Engineer (L3)
Senior SOC Analyst / SOC Engineer (L3)

Jobstreet Malaysia • Klang City

On-site
MYR 120,000 - 180,000
SENIOR SOC ANALYST L2
SENIOR SOC ANALYST L2

TechLab Security • Shah Alam

On-site
MYR 120,000 - 180,000