Manager – IT (Security Operations Centre & Incident Response)

MINDTECK SOFTWARE MALAYSIA SDN BHD

Sepang

On-site

MYR 180,000 - 280,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Mindteck Software Malaysia Sdn Bhd is seeking an experienced Manager – IT (Security Operations Centre & Incident Response) to lead and enhance enterprise cybersecurity monitoring, detection, and incident response capabilities. The role oversees SOC operations, incident response programs, MSSP relationships, and security monitoring platforms, guiding threat detection and maturity initiatives.

The successful candidate will provide operational leadership during major security incidents and drive

Qualifications

  • Bachelor’s Degree in Cybersecurity, Computer Science, Information Technology, or a related discipline.
  • 7–10 years of experience in SOC operations, incident response, cybersecurity operations, or information security.
  • Proven experience leading SOC and/or cybersecurity operations teams.
  • Strong hands-on and management experience with SIEM, SOAR, EDR/XDR, Security Monitoring, Threat Intelligence, Log Management, and Incident Response.

Responsibilities

  • Lead, govern, and continuously improve Security Operations Centre (SOC) functions, processes, and operating models.
  • Develop and maintain effective cybersecurity incident response and major incident management processes.
  • Lead and coordinate response activities for high‑severity and major cybersecurity incidents.
  • Manage relationships with Managed Security Service Providers (MSSPs), cybersecurity vendors, and external security partners.
  • Oversee the operation and optimization of SIEM, SOAR, Log Management, EDR/XDR, Threat Intelligence Platforms and related technologies.
  • Develop and enhance security monitoring, detection rules, alerting, and use cases.
  • Lead threat hunting, detection engineering, and security automation initiatives.
  • Leverage MITRE ATT&CK and threat intelligence to improve detection and response capabilities.
  • Coordinate security incident investigations, root‑cause analysis, containment, eradication, and recovery activities.
  • Conduct and oversee post‑incident reviews and drive corrective and preventive actions.
  • Establish and monitor SOC and incident response KPIs, KRIs, SLAs, and operational metrics.
  • Continuously assess and improve the maturity of cybersecurity operations, processes, technologies, and capabilities.
  • Ensure SOC and incident response activities comply with applicable cybersecurity standards, policies, regulatory requirements, and industry best practices.
  • Prepare and present executive‑level reports covering security posture, major incidents, operational performance, threat trends, and response effectiveness.
  • Support cybersecurity assessments, audits, regulatory reviews, and compliance activities.
  • Develop and maintain incident response playbooks, procedures, escalation matrices, and operational documentation.
  • Lead, mentor, and develop SOC, incident response, and cybersecurity operations personnel.
  • Promote a strong culture of security awareness, continuous improvement, collaboration, and operational excellence.

Skills

SOC operations
Incident response
Security monitoring
MSSP management
SIEM
SOAR
EDR/XDR
Threat intelligence
MITRE ATT&CK
Leadership

Education

Bachelor’s Degree in Cybersecurity, Computer Science, Information Technology, or related

Tools

SIEM platforms
SOAR platforms
EDR/XDR tooling
Threat intelligence platforms
Log management tools

Job description

Manager – IT (Security Operations Centre & Incident Response)

We are seeking an experienced Manager – IT (Security Operations Centre & Incident Response) to lead and enhance the organization's enterprise cybersecurity monitoring, detection, and incident response capabilities.

The role will be responsible for overseeing SOC operations, incident response programs, MSSP relationships, security monitoring platforms, threat detection, and cybersecurity operations maturity initiatives. The successful candidate will provide operational leadership during major security incidents and drive continuous improvements in the organization's ability to detect, investigate, respond to, and recover from cyber threats.

Job Overview

We are seeking an experienced Manager – IT (Security Operations Centre & Incident Response) to lead and enhance the organization's enterprise cybersecurity monitoring, detection, and incident response capabilities.

The role will be responsible for overseeing SOC operations, incident response programs, MSSP relationships, security monitoring platforms, threat detection, and cybersecurity operations maturity initiatives. The successful candidate will provide operational leadership during major security incidents and drive continuous improvements in the organization's ability to detect, investigate, respond to, and recover from cyber threats.

Key Responsibilities
  • Lead, govern, and continuously improve Security Operations Centre (SOC) functions, processes, and operating models.

  • Develop and maintain effective cybersecurity incident response and major incident management processes.

  • Lead and coordinate response activities for high‑severity and major cybersecurity incidents.

  • Manage relationships with Managed Security Service Providers (MSSPs), cybersecurity vendors, and external security partners.

  • Oversee the operation and optimization of:

    • SIEM

    • SOAR

    • Log Management

    • EDR/XDR

    • Threat Intelligence Platforms

    • Security monitoring and detection technologies

  • Develop and enhance security monitoring, detection rules, alerting, and use cases.

  • Lead threat hunting, detection engineering, and security automation initiatives.

  • Leverage MITRE ATT&CK and threat intelligence to improve detection and response capabilities.

  • Coordinate security incident investigations, root‑cause analysis, containment, eradication, and recovery activities.

  • Conduct and oversee post‑incident reviews and drive corrective and preventive actions.

  • Establish and monitor SOC and incident response KPIs, KRIs, SLAs, and operational metrics.

  • Continuously assess and improve the maturity of cybersecurity operations, processes, technologies, and capabilities.

  • Ensure SOC and incident response activities comply with applicable cybersecurity standards, policies, regulatory requirements, and industry best practices.

  • Prepare and present executive‑level reports covering security posture, major incidents, operational performance, threat trends, and response effectiveness.

  • Support cybersecurity assessments, audits, regulatory reviews, and compliance activities.

  • Develop and maintain incident response playbooks, procedures, escalation matrices, and operational documentation.

  • Lead, mentor, and develop SOC, incident response, and cybersecurity operations personnel.

  • Promote a strong culture of security awareness, continuous improvement, collaboration, and operational excellence.

Required Qualifications & Experience
  • Bachelor’s Degree in Cybersecurity, Computer Science, Information Technology, or a related discipline.

  • 7–10 years of experience in SOC operations, incident response, cybersecurity operations, or information security.

  • Proven experience leading SOC and/or cybersecurity operations teams.

  • Strong hands‑on and management experience with:

    • SIEM

    • SOAR

    • EDR/XDR

    • Security Monitoring

    • Threat Intelligence

    • Log Management

    • Incident Response

  • Strong experience managing MSSPs and cybersecurity technology vendors.

  • Proven experience developing and optimizing security detection use cases and monitoring capabilities.

  • Strong knowledge of MITRE ATT&CK, threat hunting, incident response methodologies, and security operations best practices.

  • Experience handling and coordinating major cybersecurity incidents.

  • Strong understanding of cybersecurity risks, vulnerabilities, attack techniques, and enterprise security environments.

  • Excellent leadership, communication, analytical, and stakeholder management skills.

Preferred Certifications

Relevant professional certifications such as:

  • CISSP – Certified Information Systems Security Professional

  • CISM – Certified Information Security Manager

  • GIAC / GCIH / GCIA / GCFA

  • CompTIA CySA+

  • Certified SOC Analyst (CSA) or equivalent

  • Other recognized cybersecurity operations or incident response certifications

Mindteck is a global software services company, offering a wide range of information technology solutions that helps our customers enhance their overall business performance. We offer a broad spectrum of IT services including Custom Application development, Application Management, Reengineering and Independent testing services in Embedded & System programming, Business Application Consulting, Storage and Infrastructure & SAP services.

We span a global presence with offices in USA, UK, Germany, Singapore, Malaysia, Middle East and India. Mindteck's customers include Fortune 500 companies, multinationals, small and medium enterprises across several industries. Our customer's business focus is diverse as well. A representative list of our customer industries include Capital Markets, High-tech Manufacturing, Insurance, Medical Equipments, Telecom, Semiconductor Manufacturing, Shipping, Smart Cards, Storage / Server, Software Products, Retail, Wireless Devices. Mindteck's flexibility allows us to work successfully with customers from numerous industries with diverse business focus, on projects of all sizes.

Please visit our website www.mindteck.com for more information

Mindteck is a global software services company, offering a wide range of information technology solutions that helps our customers enhance their overall business performance. We offer a broad spectrum of IT services including Custom Application development, Application Management, Reengineering and Independent testing services in Embedded & System programming, Business Application Consulting, Storage and Infrastructure & SAP services.

We span a global presence with offices in USA, UK, Germany, Singapore, Malaysia, Middle East and India. Mindteck's customers include Fortune 500 companies, multinationals, small and medium enterprises across several industries. Our customer's business focus is diverse as well. A representative list of our customer industries include Capital Markets, High-tech Manufacturing, Insurance, Medical Equipments, Telecom, Semiconductor Manufacturing, Shipping, Smart Cards, Storage / Server, Software Products, Retail, Wireless Devices. Mindteck's flexibility allows us to work successfully with customers from numerous industries with diverse business focus, on projects of all sizes.

Please visit our website www.mindteck.com for more information

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

SOC & Incident Response Manager – Cybersecurity Operations
SOC & Incident Response Manager – Cybersecurity Operations

MINDTECK SOFTWARE MALAYSIA SDN BHD • Sepang

On-site
MYR 180,000 - 280,000
Manager IT (Cybersecurity Risk & Policy)
Manager IT (Cybersecurity Risk & Policy)

MINDTECK SOFTWARE MALAYSIA SDN BHD • Sepang

On-site
MYR 180,000 - 340,000
Security Operations Center Lead
Security Operations Center Lead

Altera • Bayan Lepas

On-site
MYR 180,000 - 280,000
Senior Security Analyst
Senior Security Analyst

Logicalis Asia Pacific • Kuala Lumpur

On-site
MYR 80,000 - 100,000
SOC Team Lead
SOC Team Lead

Pacific Comnet (M) Sdn Bhd • Kuala Lumpur

On-site
MYR 120,000 - 180,000
SOC Team Lead
SOC Team Lead

Hytech Consulting Management Sdn Bhd • Kuala Lumpur

On-site
MYR 180,000 - 300,000
Public transportation access
Corporate insurance coverage (dental,光
Gym and fitness claims
+1
Senior Cyber Threat Engineer & SOC Mentor
Senior Cyber Threat Engineer & SOC Mentor

RHB Banking Group • Selangor

On-site
MYR 80,000 - 120,000
SOC Team Lead
SOC Team Lead

Hytech • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Public transit access
Corporate insurance (dental, optical)
Gym and fitness claims
+2
Incident Response Lead
Incident Response Lead

Axonect • Kuala Lumpur

On-site
MYR 240,000 - 360,000
Senior Cyber Security Consultant (SOC) Cyber security Kuala Lumpur
Senior Cyber Security Consultant (SOC) Cyber security Kuala Lumpur

S-RM Intelligence and Risk Consulting • Kuala Lumpur

On-site
MYR 120,000 - 180,000