L2 SOC Engineer

Neuron Solutions Sdn. Bhd.

Kuala Lumpur

Hybrid

MYR 180,000 - 280,000

Full time

2 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Neuron Solutions Sdn. Bhd. seeks an experienced cyber security operations lead to act as the SPIOC for our MSSP Tier 1 SOC, handling SIEM alerts, incident response, and executive reporting across Malaysia and the UK.

You will conduct RCA, produce incident reports, and drive weekly/monthly security updates, while monitoring Entra ID/AD for risks and coordinating vulnerability management.

Qualifications

  • Bachelor's degree in Cyber Security, Information Technology, or related field.
  • 7–9 years of experience in cyber security operations, incl. Tier 2 SOC or IR.
  • Experience with MSSP-managed Tier 1 SOC is preferred.
  • Hands-on with Microsoft Sentinel, KQL, rules, onboarding, tuning.
  • Strong knowledge of Microsoft 365, Entra ID security monitoring.
  • Experience with CrowdStrike Falcon EDR and firewall security.
  • Familiarity with NIST CSF, ISO 27001, vulnerability management, audits.

Responsibilities

  • Serve as SPOC for MSSP's Tier 1 SOC team across Malaysia and UK.
  • Manage SIEM alerts, ITSM tickets, and incident response per CIR plan.
  • Lead RCA, incident reports, and weekly/monthly security updates.
  • Monitor Entra ID and on-prem AD for risky sign-ins and MFA gaps.
  • Coordinate vulnerability scans, CVE reviews, and firewall audits.
  • Develop security policies, playbooks, DR/BCP, and risk registers.
  • Create Sentinel rules, KQL queries, and automation for threat hunting.
  • Deliver cyber security awareness training and phishing simulations.

Skills

Incident response
Root Cause Analysis
Threat hunting
Executive reporting
Stakeholder management
SLA compliance
Cloud security monitoring

Education

Bachelor's degree in Cyber Security or IT

Tools

Microsoft Sentinel
CrowdStrike Falcon EDR
Entra ID
Active Directory
NIST CSF / ISO 27001
Fortinet FortiGate

Job description

Serve as the primary Point of Contact (SPOC) for the MSSP's Tier 1 SOC team, managing SIEM (Microsoft Sentinel), CrowdStrike Falcon EDR alerts, and ITSM tickets across Malaysia and UK properties.

Investigate and respond to security incidents in line with the Cyber Incident Response (CIR) plan, ensuring timely threat containment and remediation within defined SLAs.

Lead Root Cause Analysis (RCA), prepare incident reports, and deliver weekly and monthly security updates to technical teams, stakeholders, and executives.

Monitor Entra ID and on-premises Active Directory for suspicious account activity, privilege abuse, MFA gaps, and risky sign-ins.

Coordinate vulnerability scanning, High and Critical CVE patch reviews, firewall configuration audits, and Joiner/Mover/Leaver access reviews.

Develop and maintain security policies, incident response playbooks, Disaster Recovery and Business Continuity Plans, risk registers, and risk management frameworks.

Create and fine-tune Sentinel detection rules, KQL queries, automation scripts, and threat hunting use cases.

Deliver cyber security awareness training, phishing simulations, and threat intelligence briefings to IT teams and users across Malaysia and the UK.

Requirements

Bachelor's degree in Cyber Security, Information Technology, or a related field.

7–9 years of experience in cyber security operations, including 3–4 years in a Tier 2 SOC, incident response, or security engineering role. Experience working with an MSSP-managed Tier 1 SOC is preferred.

Hands‑on experience with Microsoft Sentinel, including KQL queries, analytics rules, log source onboarding, and detection tuning.

Strong knowledge of Microsoft 365 and Entra ID security monitoring, including MFA, Conditional Access, PIM, and risky sign‑ins.

Experience with CrowdStrike Falcon EDR or comparable platforms, covering alert triage, IOC management, detection rules, and endpoint protection.

Working knowledge of Fortinet FortiGate firewalls and network security monitoring across multi‑site environments.

Proven experience in incident response, threat containment, RCA, and executive‑level incident reporting.

Good understanding of NIST CSF, ISO 27001, vulnerability management, compliance audits, and user access reviews.

Strong communication and stakeholder management skills, with the ability to liaise with technical teams and executive stakeholders across Malaysia and the UK.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

L2 SOC Analyst
L2 SOC Analyst

Neuron Solutions Sdn Bhd • Kuala Lumpur

On-site
MYR 180,000 - 280,000
Senior SOC Analyst: Incident Response & SIEM Expert
Senior SOC Analyst: Incident Response & SIEM Expert

Neuron Solutions Sdn Bhd • Kuala Lumpur

On-site
MYR 180,000 - 280,000
Senior Incident Response Specialist
Senior Incident Response Specialist

Starhub Ltd • Petaling Jaya

On-site
MYR 60,000 - 90,000
L2 SOC Engineer
L2 SOC Engineer

Oxydata Software Sdn Bhd • Petaling Jaya

Hybrid
MYR 90,000 - 130,000
Senior Cyber Security Consultant (SOC) Cyber security Kuala Lumpur
Senior Cyber Security Consultant (SOC) Cyber security Kuala Lumpur

S-RM Intelligence and Risk Consulting • Kuala Lumpur

Hybrid
MYR 120,000 - 180,000
Security Operations Center Lead
Security Operations Center Lead

Altera • Bayan Lepas

On-site
MYR 180,000 - 280,000
L2 SOC Analyst - Sentinel
L2 SOC Analyst - Sentinel

Oxydata Software Sdn Bhd • Petaling Jaya

Hybrid
MYR 80,000 - 120,000
Senior SOC Engineer — Incident Response & Threat Hunting
Senior SOC Engineer — Incident Response & Threat Hunting

Neuron Solutions Sdn. Bhd. • Kuala Lumpur

Hybrid
MYR 180,000 - 280,000
L2 SOC Analyst - Sentinel
L2 SOC Analyst - Sentinel

Oxydata Software Sdn Bhd • Selangor

Hybrid
MYR 70,000 - 100,000
Cybersecurity Analyst L2/L3
Cybersecurity Analyst L2/L3

Tech Staffing • Kuala Lumpur

On-site
MYR 90,000 - 150,000