Job Search and Career Advice Platform

Enable job alerts via email!

Manager, Threat Detection & Engineering

Awantec

Cyberjaya

On-site

MYR 80,000 - 120,000

Full time

Yesterday
Be an early applicant

Generate a tailored resume in minutes

Land an interview and earn more. Learn more

Job summary

A cybersecurity solutions provider in Cyberjaya is seeking a skilled cybersecurity engineer to lead the deployment and optimization of SIEM and EDR platforms. Responsibilities include overseeing threat monitoring, providing technical advisory, and managing incident response. The ideal candidate should possess a Bachelor's Degree in Information Security or a related field, with 5-6 years of relevant experience. Familiarity with cloud environments and proficiency in security tools are essential for this role, offering opportunity for significant impact on SOC operations.

Qualifications

  • 5–6 years of hands-on experience in cybersecurity engineering or SOC operations.
  • Professional certifications in EDR/XDR or SIEM are preferred.
  • Familiarity with cloud security and log integration workflows.

Responsibilities

  • Lead deployment and management of SIEM, EDR, and XDR platforms.
  • Conduct threat monitoring activities and incident analysis.
  • Support technical advisory on detection engineering and SOC optimization.

Skills

Cybersecurity engineering
Incident response support
Threat detection logic
Cloud security
Log correlation

Education

Bachelor’s Degree in Information Security, Computer Science, or related technical field

Tools

SIEM tools (e.g., Splunk)
EDR/XDR platforms (e.g., Trend Micro, CrowdStrike)
Firewalls
VPN technologies
Job description
Key Accountabilities
  1. Lead deployment, optimization, and lifecycle management of SIEM, EDR, and XDR platforms, ensuring effective detection coverage and alignment with MITRE ATT&CK
  2. Oversee threat monitoring activities, including L2 incident analysis, threat hunting, and purple-team validation to strengthen SOC detection maturity
  3. Provide technical oversight for endpoint, network, and cloud security implementations (EDR, firewalls, WAF, IDS/IPS), ensuring secure configurations and operational readiness.
  4. Support client-facing engagements by delivering technical advisory on detection engineering, SOC optimization, and incident readiness, including playbook development.
  5. Collaborate with the Principal Consultant to align detection controls with ISO 27001, NIST CSF, PDPA, and RMiT requirements, contributing to posture assessments and Phase 1–2 roadmap execution
  6. Lead and deliver technical POCs, solution designs, and workshops together with the sales teams, including presenting architectures and detection approaches to senior stakeholders
  7. Guide SOC analysts and junior engineers, develop internal detection engineering content for the Cyber Academy, and enhance engineering playbooks and deployment templates
Job Summary
  1. Deploy and configure cybersecurity technologies across endpoint, network, and cloud environments
  2. Conduct threat hunting, detection development, and analysis of suspicious behavior
  3. Perform incident support, including evidence gathering, timeline reconstruction, and recovery advisory
  4. Lead SIEM/SOC engineering tasks such as onboarding data sources, parser development, and log quality assurance
  5. Assist in security assessments and gap analyses aligned to ISO 27001, NIST CSF, and RMiT
  6. Coordinate with Principal Security Consultant to develop security controls that support governance and compliance outcomes
  7. Drive continuous improvement of MTTD, MTTR, and overall SOC maturity
Job Requirements
  1. Bachelor’s Degree in Information Security, Computer Science, or related technical field
  2. 5–6 years of hands‑on experience in cybersecurity engineering, SOC operations, detection engineering, or IR support
  3. Professional certifications are preferred but not mandatory. For example:
  4. EDR/XDR certifications (Trend Micro, CrowdStrike, SentinelOne)
  5. SIEM/XDR certifications (Splunk Power User / SIEM certifications)
  6. Relevant offensive security certifications (e.g., CEH, eJPT; OSCP is an advantage)
  7. Cloud security certifications (e.g., Google Cloud Security, AWS Security Specialty, or Azure Security) are an added advantage
  8. Network/security certifications (e.g Fortinet NSE4/5, CCNP Security, HCIP Security)
  9. Familiarity with cloud environments (e.g Google Cloud, AWS, Azure) and log integration workflows
Desired Experience/Exposure
  1. Experience deploying SIEM/XDR platforms in production environments
  2. Deep understanding of threat detection logic, log correlation, and alert tuning
  3. Exposure to VAPT workflows, basic offensive testing, or purple-team validation
  4. Experience with network defense technologies (firewalls, IPS/IDS, VPN, SWG)
  5. Good understanding of regulatory requirements (RMiT, PDPA, ISO 27001 controls)
  6. Ability to translate technical detections into risk‑based reporting for CXO audiences
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.