L2 SOC Analyst / Engineer

Insyghts Security

Iskandar Puteri

On-site

MYR 120,000 - 180,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Transfer opportunity to Singapore

Job summary

Jora Malaysia is seeking an L2 SOC Analyst/Engineer to serve as the escalation point for the L1 SOC team. This role owns in-depth investigation of escalated alerts, performs root cause analysis, leads incident response activities, and drives detection engineering and threat hunting to mature our security monitoring program.

You will be a technical anchor for the SOC — turning raw alerts into confirmed incidents, then lessons learned into better detections.

Qualifications

  • 3+ years of hands-on SOC experience and progression into L2/senior analyst responsibilities.
  • Solid understanding of attack lifecycle, common TTPs, and MITRE ATT&CK framework.
  • Hands-on experience with SIEM platforms and writing/tuning correlation rules and queries.
  • Experience with EDR/XDR tools for endpoint investigation.
  • Good grasp of networking fundamentals (TCP/IP, DNS, HTTP/S) and packet captures.
  • Experience with incident response processes: containment, eradication, recovery, and post-incident reporting.

Responsibilities

  • Serve as the primary technical escalation point for L1 analysts on alerts requiring deeper analysis.
  • Conduct in-depth investigations across endpoint, network, cloud, identity, and application telemetry.
  • Correlate data across multiple tools/log sources to determine scope and impact.
  • Distinguish true positives from false positives and refine triage logic accordingly.
  • Perform root cause analysis on confirmed incidents to determine initial vector and gaps.
  • Document attack timelines/kill chains and produce clear technical findings for stakeholders.
  • Lead or co-lead containment, eradication, and recovery activities for security incidents.
  • Design, build, test, and tune detection rules/use cases (SIEM, EDR, Sigma).
  • Conduct proactive threat hunts using threat intelligence and ATT&CK TTPs.
  • Mentor and provide guidance to L1 analysts, including escalation reviews and knowledge transfer.

Skills

SOC fundamentals
MITRE ATT&CK
SIEM proficiency
EDR/XDR tools
Networking basics
Incident response

Tools

Splunk
Sentinel
QRadar
Elastic
CrowdStrike
Microsoft Defender
SentinelOne
TrendAI

Job description

Jora Malaysia will close on 9th September 2026. Thank you for being with us, we are cheering you on as you continue your career journey.

We are looking for a L2 SOC Analyst/Engineer to serve as the escalation point for our L1 SOC team. This role owns in-depth investigation of escalated alerts, performs root cause analysis, leads incident response activities, and drives detection engineering and threat hunting initiatives to continuously mature our security monitoring program. You will be a technical anchor for the SOC — turning raw alerts into confirmed incidents, confirmed incidents into lessons learned, and lessons learned into better detections.

Key responsibilities

Serve as the primary technical escalation point for L1 analysts on alerts requiring deeper analysis

Conduct in-depth investigations across endpoint, network, cloud, identity, and application telemetry

Correlate data across multiple tools/log sources (SIEM, EDR, NDR, cloud logs, identity providers) to determine scope and impact

Distinguish true positives from false positives and refine triage logic accordingly

Perform root cause analysis on confirmed incidents to determine initial vector, method, and any control gaps

Document attack timelines/kill chains and produce clear technical findings for stakeholders

Lead or co-lead containment, eradication, and recovery activities for security incidents

Design, build, test, and tune detection rules/use cases (SIEM correlation rules, EDR detections, Sigma rules, etc.)

Conduct proactive, hypothesis-driven threat hunts using threat intelligence, ATT&CK TTPs, and anomaly analysis

Mentor and provide technical guidance to L1 analysts, including escalation reviews and knowledge transfer

About you

3+ years of hands-on SOC experience, with demonstrated progression into L2/senior analyst responsibilities

Strong understanding of the attack lifecycle, common TTPs, and the MITRE ATT&CK framework

Hands-on experience with SIEM platforms (e.g., Splunk, Sentinel, QRadar, Elastic) — writing/tuning correlation rules and queries

Experience with EDR/XDR tools (e.g., CrowdStrike, Microsoft Defender, SentinelOne, TrendAI) for endpoint investigation

Solid grasp of networking fundamentals (TCP/IP, DNS, HTTP/S, proxies) and ability to read packet captures

Experience with incident response processes: containment, eradication, recovery, and post-incident reporting

Familiarity with cloud security monitoring (AWS/Azure/GCP logs, IAM, CloudTrail or equivalent)

Scripting/automation skills (Python, PowerShell, or similar) for detection logic, parsing, or workflow automation

Excellent written and verbal communication skills — able to translate technical findings for non-technical stakeholders

Ability to remain calm and methodical under pressure during active incidents

*Opportunity to be transferred to Singapore office for suitable candidates.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SENIOR SOC ANALYST L2
SENIOR SOC ANALYST L2

TechLab Security • Shah Alam

On-site
MYR 120,000 - 180,000
L2 SOC Analyst / Engineer
L2 SOC Analyst / Engineer

Insyghts Security Sdn Bhd • Iskandar Puteri

On-site
MYR 60,000 - 100,000
L1 - SOC Analyst
L1 - SOC Analyst

Dwell Technologies Sdn. Bhd. • Kuala Lumpur

On-site
MYR 54,000 - 90,000
L2 - Security Analyst
L2 - Security Analyst

Ensign Infosecurity • Kuala Lumpur

On-site
MYR 60,000 - 100,000
Senior SOC Analyst / SOC Engineer (L3)
Senior SOC Analyst / SOC Engineer (L3)

Jobstreet Malaysia • Klang City

On-site
MYR 120,000 - 180,000
Lead L2 SOC Analyst: Threat Detection & Incident Response
Lead L2 SOC Analyst: Threat Detection & Incident Response

Insyghts Security • Iskandar Puteri

On-site
MYR 120,000 - 180,000
Transfer opportunity to Singapore
Cyber Security Analyst/Support (SOC)
Cyber Security Analyst/Support (SOC)

MSP Systems • Kuala Lumpur

On-site
MYR 60,000 - 90,000
SOC Manager
SOC Manager

Quess • Shah Alam

On-site
MYR 120,000 - 180,000
SOC Analyst (Splunk)
SOC Analyst (Splunk)

Lavu Tech Solutions • Kuala Lumpur

On-site
MYR 70,000 - 120,000
Security Analyst L1
Security Analyst L1

Ensign Infosecurity • Shah Alam

On-site
MYR 47,000 - 87,000