Lead Platform Engineer, SIEM & Detection Architect

Axonect

Kuala Lumpur

On-site

MYR 180,000 - 240,000

Full time

9 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Axonect is seeking a Senior SIEM Engineer in Kuala Lumpur to own the detection engineering lifecycle for Microsoft Sentinel. You will translate attacker TTPs into telemetry, map detections to MITRE ATT&CK, and collaborate with Red Team to validate and improve playbooks.

The role involves designing data requirements, building KQL logic, and deploying automated, CI/CD-driven improvements across the platform. Strong cloud identity and scripting skills are essential.

Qualifications

  • Hands-on with Microsoft Sentinel, KQL, ASIM, Logic Apps, Content Hub and Watchlists
  • Experience partnering with Red Team and running Purple Team validations
  • Translate attacker TTPs into telemetry and high-fidelity detections
  • CI/CD for SIEM using Git and Azure DevOps; Detection-as-Code and promotions
  • Scripting for automation (PowerShell/Python) and API integrations

Responsibilities

  • Convert Red Team and adversary simulation insights into formal detection enhancements
  • Map detections to MITRE ATT&CK, define telemetry requirements, and validate log sources & enrichments
  • Post-engagement gap analysis, prioritize fixes in backlog
  • Update triage guidance and analyst notes
  • Logic Apps playbook enhancements; testing with Red Team; CI/CD deployment; retirement/archive

Skills

Microsoft Sentinel
KQL
ASIM
Logic Apps
PowerShell
Python
Git
Azure DevOps

Tools

Content Hub
Watchlists
Workbooks

Job description

Axonect is seeking a Senior SIEM Engineer in Kuala Lumpur to own the detection engineering lifecycle for Microsoft Sentinel. You will translate attacker TTPs into telemetry, map detections to MITRE ATT&CK, and collaborate with Red Team to validate and improve playbooks.

The role involves designing data requirements, building KQL logic, and deploying automated, CI/CD-driven improvements across the platform. Strong cloud identity and scripting skills are essential.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior SOC Lead: IR, SIEM & Platform Engineering
Senior SOC Lead: IR, SIEM & Platform Engineering

Axonect • Kuala Lumpur

Hybrid
MYR 140,000 - 180,000
Cyber Security Operations Lead - Threat Hunting & Sentinel
Cyber Security Operations Lead - Threat Hunting & Sentinel

EPAM Systems • Malaysia

On-site
MYR 180,000 - 280,000
Splunk ES Platform Lead & Detection Engineer
Splunk ES Platform Lead & Detection Engineer

NTT DATA Business Solutions • Cyberjaya

On-site
MYR 150,000 - 210,000
Security Platform Lead: SIEM, SOAR & Automation
Security Platform Lead: SIEM, SOAR & Automation

AIA Digital+ • Kuala Lumpur

On-site
MYR 60,000 - 90,000
Lead - Platform Engineer
Lead - Platform Engineer

Axonect • Kuala Lumpur

On-site
MYR 180,000 - 240,000
Cyber Security Operations Lead
Cyber Security Operations Lead

EPAM Systems • Malaysia

On-site
MYR 180,000 - 280,000
Security Incident Response & Threat Hunter
Security Incident Response & Threat Hunter

Ensign InfoSecurity • Kuala Lumpur

On-site
MYR 60,000 - 90,000
SOC Engineer - Flexible MSSP Onboarding & Detection
SOC Engineer - Flexible MSSP Onboarding & Detection

S-RM Intelligence and Risk Consulting • Kuala Lumpur

Hybrid
MYR 60,000 - 90,000
20 days paid holiday plus additional leave
Flexible working hours
Pension scheme
+2
L2 SOC Analyst / Engineer
L2 SOC Analyst / Engineer

Insyghts Security Sdn Bhd • Iskandar Puteri

On-site
MYR 60,000 - 100,000
Senior Security Analyst
Senior Security Analyst

Logicalis • Kuala Lumpur

On-site
MYR 180,000 - 300,000