L2 SOC Analyst – SIEM

S SQUAD SDN. BHD.

Labuan

On-site

MYR 60,000 - 90,000

Full time

34 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Ssquad Global is seeking an experienced L2 SOC Analyst for its Security Operations Centre in Malaysia. The role focuses on advanced security monitoring, incident investigation, threat hunting, SIEM operations, and detection rule tuning.

You will escalate security incidents and contribute to improving detection capabilities. Responsibilities include monitoring alerts, correlating logs from diverse sources, conducting root-cause analysis, and preparing incident reports.

Qualifications

  • 3-5 years of experience in SOC, security monitoring, incident response, or cybersecurity.
  • Hands-on experience as an L2 SOC Analyst or equivalent.
  • Strong experience with SIEM platforms and security event correlation.
  • Experience in SIEM rule creation, use-case development, tuning, and log-source onboarding.
  • Strong knowledge of TCP/IP, DNS, HTTP/HTTPS, VPN, firewalls, IDS/IPS, endpoint, and network security.
  • Experience in incident investigation and root cause analysis.
  • Knowledge of MITRE ATT&CK, Cyber Kill Chain, IoCs, IoAs, and TTPs.
  • Experience in threat hunting and threat intelligence.
  • Ability to work in an SLA-driven / 24×7 SOC environment.
  • Bachelor's Degree in Cybersecurity, Computer Science, IT, or a related field.

Responsibilities

  • Monitor and investigate security alerts using SIEM and integrated security tools.
  • Analyse and correlate logs from firewalls, endpoints, servers, networks, applications, authentication, email, and cloud environments.
  • Investigate L1 escalations and determine incident severity, impact, and scope.
  • Perform incident investigation, root cause analysis, containment, and escalation.
  • Develop, review, test, and tune SIEM correlation rules and detection use cases.
  • Identify and reduce false positives and improve detection capabilities.
  • Support SIEM log-source onboarding, parsing, normalization, and troubleshooting.
  • Conduct proactive threat hunting using IoCs, IoAs, threat intelligence, and MITRE ATT&CK.
  • Provide technical guidance and knowledge transfer to L1 SOC Analysts.
  • Prepare incident reports and SOC operational reports.

Skills

SOC operations
Security monitoring
Incident response
Threat hunting
Log analysis
Threat intelligence
MITRE ATT&CK
Incident reporting
SLA adherence
24x7 support

Education

Bachelor's Degree in Cybersecurity

Tools

SIEM platforms

Job description

Ssquad Global is looking for an experienced L2 SOC Analyst to join our Security Operations Centre. The role involves advanced security monitoring, incident investigation, threat hunting, SIEM operations, detection rule tuning, and escalation of security incidents.


Key responsibilities

Monitor and investigate security alerts using SIEM and integrated security tools.


Analyse and correlate logs from firewalls, endpoints, servers, networks, applications, authentication, email, and cloud environments.


Investigate L1 escalations and determine incident severity, impact, and scope.


Perform incident investigation, root cause analysis, containment, and escalation.


Develop, review, test, and tune SIEM correlation rules and detection use cases.


Identify and reduce false positives and improve detection capabilities.


Support SIEM log-source onboarding, parsing, normalization, and troubleshooting.


Conduct proactive threat hunting using IoCs, IoAs, threat intelligence, and MITRE ATT&CK.


Provide technical guidance and knowledge transfer to L1 SOC Analysts.


Prepare incident reports and SOC operational reports.


About you

3-5 years of experience in SOC, security monitoring, incident response, or cybersecurity.


Hands-on experience as an L2 SOC Analyst or equivalent.


Strong experience with SIEM platforms and security event correlation.


Experience in SIEM rule creation, use-case development, tuning, and log-source onboarding.


Strong knowledge of TCP/IP, DNS, HTTP/HTTPS, VPN, firewalls, IDS/IPS, endpoint, and network security.


Experience in incident investigation and root cause analysis.


Knowledge of MITRE ATT&CK, Cyber Kill Chain, IoCs, IoAs, and TTPs.


Experience in threat hunting and threat intelligence.


Ability to work in an SLA-driven / 24×7 SOC environment.


Bachelor's Degree in Cybersecurity, Computer Science, IT, or a related field.


About us

Ssquad Global is an IT Services & Cybersecurity company.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

L2 SOC Analyst
L2 SOC Analyst

Pride Global • Selangor

On-site
MYR 60,000 - 110,000
L2 SOC Analyst / Engineer
L2 SOC Analyst / Engineer

Insyghts Security Sdn Bhd • Iskandar Puteri

On-site
MYR 60,000 - 100,000
Senior SOC Analyst
Senior SOC Analyst

Pride Global • Selangor

On-site
MYR 120,000 - 180,000
Security Analyst (Intelligence & Operations)
Security Analyst (Intelligence & Operations)

GXS Bank • Petaling Jaya

On-site
MYR 90,000 - 150,000
L2 SOC Analyst - Threat Detection & Incident Response
L2 SOC Analyst - Threat Detection & Incident Response

S SQUAD SDN. BHD. • Labuan

On-site
MYR 60,000 - 90,000
SOC Specialist
SOC Specialist

Pride Global • Cyberjaya

On-site
MYR 120,000 - 180,000
L2 SOC Analyst
L2 SOC Analyst

Pride Global • Kuala Lumpur

On-site
MYR 67,000 - 100,000
Security Analyst (Intelligence - Operations)
Security Analyst (Intelligence - Operations)

GXS Bank • Selangor

On-site
MYR 90,000 - 130,000
Security Analyst L3
Security Analyst L3

Ensign Services • Rawang

On-site
MYR 120,000 - 180,000
L2 SOC Analyst
L2 SOC Analyst

Pride Global • Cyberjaya

On-site
MYR 60,000 - 90,000