Security Operations Center Analyst

TIME dotCom Berhad

Shah Alam

Hybrid

MYR 120,000 - 180,000

Full time

5 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Medical coverage
Wellness account
Employee assistance
Learning & growth opportunities
Certifications reimbursement

Job summary

TIME dotCom Berhad is seeking a SOC Analyst (Threat & Exposure) to drive exposure management, vulnerability validation, and security assessments across our multi-domain environment. You will coordinate scanning, validate controls, and support adversary simulations to strengthen cyber resilience.

Working with Cybersecurity and IT teams, you will analyze attack paths, prioritize remediation, and report on exposure trends to management.

Qualifications

  • Minimum 5 years in cybersecurity with focus on security operations and exposure management.
  • Experience performing security assessments, vulnerability analysis or validation.
  • Ability to analyze security findings and prioritize remediation effectively.

Responsibilities

  • Identify and assess security exposures across infrastructure, network, cloud and apps.
  • Perform attack surface reviews and analyze weaknesses, misconfigurations, and control gaps.
  • Validate remediation effectiveness and support adversary simulation exercises.
  • Coordinate vulnerability scanning and track remediation progress.
  • Prepare exposure dashboards and present findings to stakeholders.

Skills

Exposure management
Security validation
Vulnerability management
Threat modelling
Adversary thinking
Data analysis
Scripting (PowerShell/Python)

Tools

Tenable
Qualys
Rapid7
Microsoft Defender Vulnerability Management

Job description

The position reports to the Head of Group SOC.

Job Overview:

The SOC Analyst (Threat & Exposure) is responsible for proactively identifying, assessing, and reducing security exposures across the organization's technology landscape. As part of the Group Security Operations Center (GSOC), the role focuses on vulnerability management, attack surface analysis, security assessments, and security validation activities across multiple technology domains. The role helps ensure security weaknesses, misconfigurations, and control gaps are identified and addressed before they can be exploited by threat actors.

Working closely with Cybersecurity and IT teams, this role supports the continuous improvement of the organization's security posture through risk-based assessments, exposure management, and remediation validation. While expertise in every technology domain is not expected, the successful candidate should demonstrate strong analytical thinking, curiosity, adaptability, and a commitment to continuously expanding their cybersecurity knowledge and capabilities.

Exposure Management
  • Identify and assess security exposures across infrastructure, network, endpoint, identity, cloud, and application environments.
  • Perform attack surface reviews to identify attack paths, security weaknesses, misconfigurations, and control gaps.
  • Analyze attack paths and potential opportunities for privilege escalation, lateral movement, unauthorized access, credential compromise, and data exposure.
  • Assess exploitability and potential business impact of excessive privileges, insecure configurations, weak controls, technology vulnerabilities, and exposed services.
  • Recommend, track, and validate remediation activities to reduce organizational cyber exposure.
  • Support adversary simulation and purple team exercises to assess security control effectiveness.
Security Validation
  • Perform technical validation of security controls to verify they are operating effectively and providing the intended protection.
  • Assess the effectiveness of preventive, detective, and responsive controls across identity, endpoint, network, cloud, and application environments.
  • Validate remediation effectiveness through targeted testing and verification activities.
  • Conduct technical reviews and validation activities to identify deviations from approved security baselines, hardening standards, and security requirements.
  • Support adversary simulation, purple team exercises, and security validation initiatives.
  • Work closely with other team members to ensure critical exposures are adequately monitored, detectable, and responsive.
  • Identify control gaps and recommend improvements to strengthen cyber resilience.
Vulnerability Management
  • Manage the vulnerability management lifecycle from discovery through remediation validation.
  • Coordinate vulnerability scanning activities across servers, endpoints, network devices, cloud environments, and applications.
  • Assess vulnerability exploitability, business impact, and remediation priority.
  • Monitor remediation progress and validate closure of identified vulnerabilities.
  • Produce vulnerability metrics, trends, and management reports.
Penetration Test & Security Assessment Coordination
  • Coordinate internal and external penetration testing and security assessment activities where required.
  • Review findings and support risk prioritization.
  • Track remediation actions and verify closure of identified findings.
  • Maintain assessment records, trends, and exposure metrics.
Reporting & Stakeholder Engagement
  • Prepare exposure management dashboards, metrics, and reports.
  • Present findings and recommendations to technology teams and management.
  • Support risk discussions and remediation prioritization activities.
  • Maintain visibility of organizational attack surface, exposure trends, and remediation effectiveness.
  • Possess an attacker-minded approach when assessing systems, configurations, and security controls.
  • Strong analytical and problem-solving skills with the ability to identify meaningful risks from technical findings.
  • Curious and eager to learn across multiple technology domains and cybersecurity disciplines.
  • Able to balance technical risks with business priorities and practical remediation approaches.
  • Detail-oriented and methodical in assessing security weaknesses and validating control effectiveness.
  • Strong communication and stakeholder engagement skills, with the ability to influence remediation outcomes.
  • Self-motivated with a continuous improvement mindset and passion for cybersecurity.
Your Merits
Experience
  • Minimum 5 years of cybersecurity experience in security operations, vulnerability management, security assessments, infrastructure security, cloud security, application security, or related disciplines.
  • Experience identifying security weaknesses and working with technology teams to implement remediation.
  • Experience performing security assessments, vulnerability analysis, or security validation activities.
Technical Knowledge
  • Exposure Management & Security Validation: Attack surface management, exposure management, attack path analysis, security control validation, remediation validation, adversarial thinking, and risk-based prioritization of security weaknesses.
  • Vulnerability Management & Security Assessment: Vulnerability assessment and prioritization, vulnerability lifecycle management, security assessments, security configuration reviews, hardening validation, and exposure analysis using vulnerability management and assessment platforms (e.g., Tenable, Qualys, Rapid7, Microsoft Defender Vulnerability Management).
  • Identity, Infrastructure & Cloud Security: Identity and access management security (e.g., Active Directory, Microsoft Entra ID, Okta), authentication, authorization, privileged access security, cloud security posture assessment (e.g., Microsoft Azure, AWS, Google Cloud), network security fundamentals, Linux and Windows security, and infrastructure hardening principles.
  • Application & API Security: Web application and API security concepts, OWASP Top 10, authentication and authorization controls, API security, application attack surfaces, and application security testing tools (e.g., Burp Suite, OWASP ZAP, Acunetix).
  • Security Analysis & Investigation: Log analysis, attack path reconstruction, threat-informed security assessments, security findings validation, attack simulation techniques, and security control effectiveness reviews.
  • Data Analysis, Scripting & Automation: Basic scripting and automation (e.g., PowerShell, Python, Bash), security data analysis, vulnerability data interpretation, database fundamentals (e.g., Microsoft SQL Server, MySQL, PostgreSQL), and reporting automation.
Preferred Qualifications
  • Relevant cybersecurity certifications and practical experience in security operations, vulnerability management, exposure management, cloud security, identity security, security assessment, and penetration testing would be advantageous.
  • Certifications: SC-200, SC-300, AZ-500, Security+, CySA+, CEH, CISSP, and other industry-recognized cybersecurity certifications.
  • Frameworks and methodologies: MITRE ATT&CK, MITRE D3FEND, OWASP Top 10, Threat Modeling, STRIDE, Attack Trees, Zero Trust Architecture, and CIS Benchmarks.
Success in this role will be measured by:
  • Reduction in critical and high-risk vulnerabilities.
  • Reduction in exploitable attack paths and excessive privileges.
  • Improvement in vulnerability remediation SLA compliance and reduction of overdue findings.
  • Number of critical exposures identified and remediated before exploitation.
  • Number of security control weaknesses identified through security validation activities.
  • Reduction in repeat findings from vulnerability assessments, penetration tests, and security reviews.
  • Increased maturity of Threat & Exposure Management capabilities, processes, and reporting.
Our Commitment to You

At Time, we believe great work deserves great support. Here’s what you can look forward to when you join us:

  • Comprehensive medical coverage for you and your immediate family, including outpatient care, hospitalisation, dental and optical benefits.
  • Wellness support with an annual spending account for health-related needs, alternative treatments, or even paid-up premiums for personal insurance.
  • Employee assistance during life’s big moments, from celebrations to times of bereavement.
  • Learning & growth opportunities through dedicated time for learning, access to LinkedIn Learning and rewards for upskilling.
  • Cash rewards for recognised certifications and full reimbursement for up to two approved professional memberships each year.

*Only shortlisted candidates will be notified.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cybersecurity Analyst
Cybersecurity Analyst

Tune Protect Group Berhad • Kuala Lumpur

On-site
MYR 36,000 - 72,000
Medical
Dental
Education support
+2
CYBER SECURITY SPECIALIST
CYBER SECURITY SPECIALIST

Commerce Dot Com Sdn Bhd • Cyberjaya

On-site
MYR 60,000 - 120,000
Comprehensive medical benefits
Group term life coverage
Meal allowances
+1
Cybersecurity Analyst
Cybersecurity Analyst

Tune Protect Group • Kuala Lumpur

On-site
MYR 60,000 - 90,000
Senior Offensive Security Consultant Cyber security Kuala Lumpur
Senior Offensive Security Consultant Cyber security Kuala Lumpur

S-RM Intelligence and Risk Consulting • Kuala Lumpur

On-site
MYR 240,000 - 360,000
20 days holiday
Hybrid working
Private medical insurance
+5
Senior SOC Engineer
Senior SOC Engineer

Hytech Consulting Management Sdn Bhd • Kuala Lumpur

On-site
MYR 180,000 - 240,000
Public transport access
Corporate insurance (dental, optical,–
Gym and fitness claims
+1
Security Operations Center Lead
Security Operations Center Lead

Altera • Bayan Lepas

On-site
MYR 180,000 - 280,000
Cyber Security Consultant
Cyber Security Consultant

ABeam Consulting Malaysia • Petaling Jaya

On-site
MYR 90,000 - 150,000
Vulnerability Response Specialist
Vulnerability Response Specialist

Two95 International Inc. • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Senior SOC Engineer
Senior SOC Engineer

Hytech • Kuala Lumpur

On-site
MYR 180,000 - 300,000
Public transport access
Corporate insurance (dental, optical,
Gym and fitness claims
+2
Information Security Analyst
Information Security Analyst

Air Liquide • Petaling Jaya

On-site
MYR 120,000 - 180,000