Lead - Platform Engineer

Axonect

Kuala Lumpur

On-site

MYR 180,000 - 240,000

Full time

11 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Axonect is seeking a Senior SIEM Engineer in Kuala Lumpur to own the detection engineering lifecycle for Microsoft Sentinel. You will translate attacker TTPs into telemetry, map detections to MITRE ATT&CK, and collaborate with Red Team to validate and improve playbooks.

The role involves designing data requirements, building KQL logic, and deploying automated, CI/CD-driven improvements across the platform. Strong cloud identity and scripting skills are essential.

Qualifications

  • Hands-on with Microsoft Sentinel, KQL, ASIM, Logic Apps, Content Hub and Watchlists
  • Experience partnering with Red Team and running Purple Team validations
  • Translate attacker TTPs into telemetry and high-fidelity detections
  • CI/CD for SIEM using Git and Azure DevOps; Detection-as-Code and promotions
  • Scripting for automation (PowerShell/Python) and API integrations

Responsibilities

  • Convert Red Team and adversary simulation insights into formal detection enhancements
  • Map detections to MITRE ATT&CK, define telemetry requirements, and validate log sources & enrichments
  • Post-engagement gap analysis, prioritize fixes in backlog
  • Update triage guidance and analyst notes
  • Logic Apps playbook enhancements; testing with Red Team; CI/CD deployment; retirement/archive

Skills

Microsoft Sentinel
KQL
ASIM
Logic Apps
PowerShell
Python
Git
Azure DevOps

Tools

Content Hub
Watchlists
Workbooks

Job description

  • Convert Red Team and adversary simulation insights into formal detectionenhancements
  • Map detections to MITRE ATT&CK, define telemetry requirements, and validate log sources & enrichments (ASIM-aligned where applicable)
  • Perform post-engagement gap analysis, prioritize fixes in a transparent detectionbacklog
  • Ensure each finding results in:
    • o Improved/validated use case (KQL logic + entity mapping + suppression)
    • o Updated triage guidance and analyst notes
    • o Logic Apps playbook enhancement (if applicable)
    • o Re-testing with Red Team
Full Use Case Development & Improvement Lifecycle
  • Design: data requirements, ASIM mapping, entity model, severity, rationale, ATT&CKcoverage
  • Build: KQL logic, enrichment (watchlists/UEBA/context), suppression thresholds,incident settings
  • Test: lab data, adversarial replay, quality gates (TP/FP rates, performance)
  • Deploy: CI/CD with approvals, release notes, rollback plan
  • Retire: deprecate & archive with justification
  • Structured improvement cycles: SOC feedback - Engineering validation -Red Teamre-test - Content update.
Red Team – Engineering Collaboration
  • Log all Red Team findings as use case candidates in a tracked backlog
  • Partner with identity, network, cloud, and platform teams to enable telemetryand close platform gaps
SOAR / Logic Apps Playbook Enhancement
  • Lead improvements to Logic Apps playbooks and automation patterns
    (enrichment, notifications, ticketing, containment orchestration)
  • Apply attacker-driven learnings to harden playbooks (anti-bypass steps, validation &guardrails)
  • Ensure robust error handling, retry policies, timeout controls, connection healthmonitoring, and Managed Identities/Key Vault hygiene
  • Instrument playbooks with telemetry (success/failure, latency, step metrics)
Platform Ownership (Microsoft Sentinel)
  • Own connectors, DCR/AMA, ASIM parsers, cost controls (table selection,
    Basic/Analytics tiers, data caps), Watchlists, Workbooks, Content Hub solutions
  • Govern RBAC, CI/CD promotion gates, API permissions & service principals
  • Drive data quality & health: missing sources, parsing failures, schema drift, timeskew, volume anomalies
  • Optimize storage/retention/archival, tune query performance and workspacecosts
Governance, Reporting & Compliance
  • Produce coverage reports (by ATT&CK, asset class, control family) and Red Teamuplift metrics
  • Enforce segregation of duties and least privilege for SIEM operations
Person Specifications
  • 06 – 10 years in SIEM engineering/detection engineering (Sentinel preferred)
  • Deep hands-on with Microsoft Sentinel, KQL, ASIM, Logic Apps, Content Hub,Watchlists, Workbooks
  • Proven experience partnering with Red Team/Pentesters and running Purple Teamvalidations
  • Ability to translate attacker TTPs into telemetry + high-fidelity detections
  • Skilled with CI/CD for SIEM (Git, Azure DevOps), Detection-as-Code, andenvironment promotion
  • Strong grasp of cloud identity & auth (Entra ID/OAuth/SAML/Kerberos), networkprotocols, and Windows/Linux telemetry
  • Scripting for automation (PowerShell/Python), API integrations, and datanormalization
Nice To Have
  • Experience with M365 Defender and its bi-directional integrations with Sentinel
  • Familiarity with Fusion/UEBA, ML anomalies, and custom parsers (KQL functions)
  • Cost engineering for Sentinel (table strategy, Basic vs Analytics, archive/search)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SOC Lead
SOC Lead

Axonect • Kuala Lumpur

Hybrid
MYR 140,000 - 180,000
Senior Security Analyst
Senior Security Analyst

Logicalis • Kuala Lumpur

On-site
MYR 180,000 - 300,000
Security Analyst (Intelligence & Operations)
Security Analyst (Intelligence & Operations)

GXS Bank • Petaling Jaya

On-site
MYR 90,000 - 150,000
Senior Security Analyst
Senior Security Analyst

Logicalis Asia Pacific • Kuala Lumpur

On-site
MYR 80,000 - 100,000
Senior Security Analyst
Senior Security Analyst

All jobs • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Security Analyst (Intelligence - Operations)
Security Analyst (Intelligence - Operations)

GXS Bank • Selangor

On-site
MYR 90,000 - 130,000
Lead Analyst, Digital Security
Lead Analyst, Digital Security

AIA Digital+ • Kuala Lumpur

On-site
MYR 60,000 - 90,000
Senior Manager, Digital Security
Senior Manager, Digital Security

AIA Digital+ • Kuala Lumpur

On-site
MYR 180,000 - 360,000
Security Engineer (Blue Team)
Security Engineer (Blue Team)

PARTECH PARTNERS • Kuala Lumpur

On-site
MYR 60,000 - 120,000
Lead Platform Engineer, SIEM & Detection Architect
Lead Platform Engineer, SIEM & Detection Architect

Axonect • Kuala Lumpur

On-site
MYR 180,000 - 240,000