Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.
Neuron Solutions Sdn. Bhd. seeks an experienced cyber security operations lead to act as the SPIOC for our MSSP Tier 1 SOC, handling SIEM alerts, incident response, and executive reporting across Malaysia and the UK.
You will conduct RCA, produce incident reports, and drive weekly/monthly security updates, while monitoring Entra ID/AD for risks and coordinating vulnerability management.
Serve as the primary Point of Contact (SPOC) for the MSSP's Tier 1 SOC team, managing SIEM (Microsoft Sentinel), CrowdStrike Falcon EDR alerts, and ITSM tickets across Malaysia and UK properties.
Investigate and respond to security incidents in line with the Cyber Incident Response (CIR) plan, ensuring timely threat containment and remediation within defined SLAs.
Lead Root Cause Analysis (RCA), prepare incident reports, and deliver weekly and monthly security updates to technical teams, stakeholders, and executives.
Monitor Entra ID and on-premises Active Directory for suspicious account activity, privilege abuse, MFA gaps, and risky sign-ins.
Coordinate vulnerability scanning, High and Critical CVE patch reviews, firewall configuration audits, and Joiner/Mover/Leaver access reviews.
Develop and maintain security policies, incident response playbooks, Disaster Recovery and Business Continuity Plans, risk registers, and risk management frameworks.
Create and fine-tune Sentinel detection rules, KQL queries, automation scripts, and threat hunting use cases.
Deliver cyber security awareness training, phishing simulations, and threat intelligence briefings to IT teams and users across Malaysia and the UK.
Bachelor's degree in Cyber Security, Information Technology, or a related field.
7–9 years of experience in cyber security operations, including 3–4 years in a Tier 2 SOC, incident response, or security engineering role. Experience working with an MSSP-managed Tier 1 SOC is preferred.
Hands‑on experience with Microsoft Sentinel, including KQL queries, analytics rules, log source onboarding, and detection tuning.
Strong knowledge of Microsoft 365 and Entra ID security monitoring, including MFA, Conditional Access, PIM, and risky sign‑ins.
Experience with CrowdStrike Falcon EDR or comparable platforms, covering alert triage, IOC management, detection rules, and endpoint protection.
Working knowledge of Fortinet FortiGate firewalls and network security monitoring across multi‑site environments.
Proven experience in incident response, threat containment, RCA, and executive‑level incident reporting.
Good understanding of NIST CSF, ISO 27001, vulnerability management, compliance audits, and user access reviews.
Strong communication and stakeholder management skills, with the ability to liaise with technical teams and executive stakeholders across Malaysia and the UK.