Manager Endpoint Protection (Operation)

Telekom Malaysia

Kuala Lumpur

On-site

MYR 180,000 - 320,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Telekom Malaysia is seeking a senior XDR Security Lead to drive the XDR operations program, provide technical leadership, platform optimization and oversee an analyst team. You will balance hands-on incident work with detection engineering and security posture improvements.

Reporting to SOC leadership, you will manage roadmap, budget, vendor relationships, and mentor staff while aligning with compliance and IT teams on deployment and modernization.

Qualifications

  • Bachelor's degree in Cybersecurity, Information Security, or related field.
  • CISSP, GCIH, GCIA, or equivalent advanced cybersecurity certifications are highly preferred
  • 8+ years of hands-on experience with deep expertise in EDR/XDR architecture, detection engineering, threat hunting, and threat research

Responsibilities

  • XDR Platform Administration: Finetuning and maintaining the XDR security platform, reduce false positives, set detection rules, ensure SIEM/SOAR integrations, manage upgrades and health monitoring, log collection and telemetry integration, develop automated workflows and playbooks, optimize alerts and detection.
  • Incident Response: Define incident response strategy, escalation policies, runbooks; lead critical incident response and 24/7 on-call rotation; report status and risk to execs and customers; coordinate breach investigation and post-incident reviews.
  • Escalation: Escalate platform/detection decisions to management; coordinate with IT, compliance on policy changes; manage vendor relationships; report budget and staffing gaps.
  • Reporting & Documentation: Prepare monthly XDR/KPI reports and quarterly business reviews; document platform architecture and configuration; maintain audit trails and runbooks; document threats and improvements; tracking team performance.
  • Collaboration: Align XDR strategy/budget with leadership; partner with security, compliance, IT, infra on deployment; coordinate with Product on licensing and roadmap feedback.
  • Long-term XDR strategy: Develop multi-year strategy; lead platform modernization and automation; evaluate new tech and drive best practices; advise senior management on endpoint security strategy.

Skills

EDR/XDR architecture
Threat hunting
Detection engineering
Incident response leadership
Team mentorship

Education

Bachelor's degree in Cybersecurity or related field

Tools

Palo Alto Cortex XDR
Microsoft Defender XDR
CrowdStrike Falcon
SentinelOne
Trend Micro Vision One
Splunk
Microsoft Sentinel (Azure Sentinel)
Elasticsearch

Job description

ABOUT THE JOB

Lead the XDR security operations program with responsibility for technical leadership, platform optimization, and functional oversight of the analyst team-members. Balances hands-on technical involvement in critical incidents with initiatives around detection engineering, security policy, and organizational security posture. Partners with SOC leadership on roadmap, budget, vendor management, and team development.

KEY RESPONSIBILITIES
XDR Platform Administration
  • Finetuning and maintain XDR security platform inclusive of reducing False Positive alerts, setting detection rules
  • Ensure integration of XDR solution with SIEM, SOAR etc.
  • Manage XDR platform and agent upgrades, patches and system health monitoring
  • Ensure proper log collection and telemetry integration across security tools
  • Develop automated workflows and response playbooks
  • Optimize alerting mechanisms and detection capabilities
  • Support SOC & analysts process improvements
Incident Response
  • Set incident response strategy, escalation policies, and runbooks
  • Lead critical incident response and 24/7 on-call rotation
  • Report incident status/risk to execs and customers; coordinate breach investigation and disclosure with IR
  • Set detection/response/containment targets and drive post-incident reviews for improvement
Escalation:
  • Escalate strategic platform/detection decisions to management
  • Coordinate with IT, compliance, etc. on policy and infrastructure changes
  • Manage vendor relationships for SLA-impacting issues
  • Report budget overages and staffing/training gaps affecting performance
Reporting & Documentation:
  • Prepare monthly XDR/KPI reports and quarterly business reviews for leadership
  • Document platform architecture, configuration standards, and detection roadmap
  • Maintain audit trails for policy/platform changes and access controls
  • Document threats, detection gaps, and improvement recommendations
  • Maintain team performance/coaching records
  • Maintain runbooks, playbooks, and troubleshooting guide
Collaboration:
  • Align XDR strategy/budget with leadership
  • Partner with security, compliance, IT, and infrastructure teams on platform integration and deployment
  • Coordinate with Product on licensing, SLAs, and roadmap feedback
Long-term XDR strategy:
  • Develop multi-year XDR strategy aligned with threat profile and business goals
  • Lead platform modernization, tool consolidation, and detection optimization
  • Evaluate new technologies and drive adoption of best practices and automation
  • Advise senior management on endpoint security strategy, risk, and compliance
Strategic & Program Management:
  • Set and track KPIs (detection coverage, false positives, MTTR, on-call health)
  • Set platform configuration standards, detection policies, and security baselines
  • Lead cross-functional projects (cloud migration, threat intel, automation)
  • Manage budget (licensing, tools, training, hiring) and platform modernization
  • Conduct annual threat assessments to guide platform enhancements
Mentorship:
  • Mentor and develop team members through performance feedback, career guidance, and knowledge-sharing sessions, while monitoring detection coverage, alert quality, and response SLA
CANDIDATE MUST HAVE
  • Bachelor's degree in Cybersecurity, Information Security, or related field (or equivalent experience)
  • CISSP, GCIH, GCIA, or equivalent advanced cybersecurity certifications are highly preferred
  • 8+ years of hands-on experience with deep expertise in EDR/XDR architecture, detection engineering, threat hunting, and threat research
WE VALUE
  • Expert-level proficiency in two or more leading XDR platforms and detection engineering practices
  • Advanced capabilities in threat analysis, detection development, and MITRE ATT&CK framework mapping
  • Ability to thrive in a lean, fast-paced environment, balancing multiple responsibilities effectively.
  • Strong expertise in endpoint security, EDR/XDR operations, incident investigation, and threat hunting
  • Excellent troubleshooting, root cause analysis, and performance optimization skills.
  • Technical Competencies: Palo Alto Cortex XDR, Microsoft Defender XDR, Crowd Strike Falcon, Sentinel One, Trend Micro Vision One, Splunk, Microsoft Sentinel (Azure Sentinel) & Elasticsearch
LOCATION
  • TM Annexe 2, Telekom Malaysia Berhad, Jalan Pantai Baharu, Kuala Lumpur.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

EDR - Cloud Security Support Specialist
EDR - Cloud Security Support Specialist

Pride Global • Cyberjaya

On-site
MYR 90,000 - 150,000
EDR & Cloud Security Support Specialist
EDR & Cloud Security Support Specialist

Pride Global • Selangor

On-site
MYR 70,000 - 120,000
Senior XDR & Endpoint Security Lead
Senior XDR & Endpoint Security Lead

Telekom Malaysia • Kuala Lumpur

On-site
MYR 180,000 - 320,000
Senior IT Security Engineer
Senior IT Security Engineer

GXBank • Petaling Jaya

On-site
MYR 120,000 - 180,000
Security Operations Center Lead
Security Operations Center Lead

Altera • Bayan Lepas

On-site
MYR 180,000 - 280,000
Senior SOC Analyst
Senior SOC Analyst

Pride Global • Cyberjaya

On-site
MYR 120,000 - 180,000
Incident Response Lead
Incident Response Lead

Axonect • Kuala Lumpur

On-site
MYR 180,000 - 360,000
Information Security Operations Lead (Penang / Johor)
Information Security Operations Lead (Penang / Johor)

Randstad Malaysia • Kuala Lumpur

On-site
MYR 180,000 - 240,000
Senior Manager, Digital Security
Senior Manager, Digital Security

AIA Digital+ • Kuala Lumpur

On-site
MYR 180,000 - 360,000
Senior Security Analyst
Senior Security Analyst

Logicalis Asia Pacific • Kuala Lumpur

On-site
MYR 80,000 - 100,000