Security Operations Center Lead

Altera

Bayan Lepas

On-site

MYR 180,000 - 280,000

Full time

11 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Altera in Penang is seeking a senior Security Operations Center (SOC) Lead to oversee global SOC functions and incident response. You will drive incident management, develop playbooks, and coordinate with MSPs and internal teams to ensure timely remediation.

The role requires 5+ years in security operations, strong SIEM/SOAR/EDR/XDR experience, and hands-on leadership. You’ll align with MITRE ATT&CK and NIST CSF while delivering measurable security outcomes.

Qualifications

  • Bachelor’s degree in Computer Science, Computer Engineering, Information Security, or related field.
  • 5+ years of progressive cybersecurity experience in security operations, incident response, threat detection, or SOC leadership.
  • 3+ years leading SOC analysts, incident response teams, or cross-functional cyber defense workflows.
  • Strong working knowledge of SIEM, SOAR, EDR/XDR, cloud security monitoring, identity security, email security, network security, and incident response processes.
  • Demonstrated experience building or improving detection use cases, alert triage workflows, response playbooks, escalation procedures, and SOC metrics.
  • Experience coordinating investigations involving phishing, malware, endpoint compromise, suspicious authentication, privileged access misuse, data exposure, and cloud security events.
  • Familiarity with MITRE ATT&CK, NIST CSF, NIST SP 800-61, ISO 27001, CIS Controls, or equivalent cyber defense frameworks.
  • Ability to communicate clearly with technical teams, business stakeholders, senior leadership, and external partners during security incidents.
  • Strong analytical, documentation, prioritization, and decision-making skills in high-pressure operational environments.
  • CISSP, Security+, or equivalent industry certification.

Responsibilities

  • Lead daily SOC operations across monitoring, triage, investigation, escalation, and handoffs across global time zones.
  • Own and mature SOC procedures including incident intake, severity classification, escalation paths, playbooks, and post-incident reviews.
  • Manage and improve security monitoring across SIEM, SOAR, EDR/XDR, email, cloud, identity, and threat intelligence.
  • Build and tune detection use cases aligned to MITRE ATT&CK techniques, threat intelligence, audit findings, and business assets.
  • Lead incident response coordination for endpoint compromise, phishing, malware, data loss indicators, and cloud misconfigurations.
  • Establish SOC metrics and reporting including MTTD, MTTA, MTTC, and incident trends.
  • Coordinate with MSPs, IT teams, and stakeholders for remediation ownership.
  • Drive continuous improvement via tabletop exercises and purple-team findings.

Skills

Security operations
Incident response
SOC leadership
Threat detection
SIEM/SOAR/EDR/XDR
Communication with stakeholders
Governance/compliance

Education

Bachelor’s degree in Computer Science / related field
CISSP or equivalent

Tools

Microsoft Sentinel
Microsoft Defender XDR
KQLs

Job description

  • Lead daily SOC operations across monitoring, alert triage, investigation, escalation, incident response coordination, and operational handoff across global time zones.
  • Own and mature SOC operating procedures, including incident intake, severity classification, escalation paths, response playbooks, major incident communications, and post-incident reviews.
  • Manage and improve security monitoring across SIEM, SOAR, EDR/XDR, email security, cloud security, identity security, vulnerability signals, network telemetry, and threat intelligence sources.
  • Build, tune, and continuously improve detection use cases aligned to enterprise risks, MITRE ATT&CK techniques, threat intelligence, audit findings, and business-critical assets.
  • Partner with security engineering teams to improve log onboarding, data quality, telemetry coverage, alert fidelity, automation, and response integrations.
  • Lead incident response coordination for security events involving endpoint compromise, identity misuse, phishing, malware, data loss indicators, cloud misconfigurations, suspicious network activity, and unauthorized access attempts.
  • Establish SOC performance metrics and reporting, including alert volumes, false-positive rates, SLA adherence, escalation quality, mean time to detect, mean time to acknowledge, mean time to contain, and incident trends.
  • Oversee SOC analyst workflows, shift handoffs, case documentation, evidence handling, and quality assurance reviews.
  • Coordinate with managed security service providers, internal IT teams, and business stakeholders to ensure timely response and clear ownership of remediation actions.
  • Support implementation and operationalization of SOAR playbooks, automation workflows, enrichment logic, and incident response runbooks.
  • Drive continuous improvement through tabletop exercises, incident retrospectives, purple-team findings, threat hunting outputs, and lessons learned.
  • Maintain alignment with security governance, regulatory, privacy, and audit requirements by ensuring SOC processes are documented, repeatable, measurable, and evidence-ready.
  • Serve as a security operations lead for global SOC coverage and cross-functional collaboration.
Job Details
Job Description
  • Lead daily SOC operations across monitoring, alert triage, investigation, escalation, incident response coordination, and operational handoff across global time zones.
  • Own and mature SOC operating procedures, including incident intake, severity classification, escalation paths, response playbooks, major incident communications, and post-incident reviews.
  • Manage and improve security monitoring across SIEM, SOAR, EDR/XDR, email security, cloud security, identity security, vulnerability signals, network telemetry, and threat intelligence sources.
  • Build, tune, and continuously improve detection use cases aligned to enterprise risks, MITRE ATT&CK techniques, threat intelligence, audit findings, and business-critical assets.
  • Partner with security engineering teams to improve log onboarding, data quality, telemetry coverage, alert fidelity, automation, and response integrations.
  • Lead incident response coordination for security events involving endpoint compromise, identity misuse, phishing, malware, data loss indicators, cloud misconfigurations, suspicious network activity, and unauthorized access attempts.
  • Establish SOC performance metrics and reporting, including alert volumes, false-positive rates, SLA adherence, escalation quality, mean time to detect, mean time to acknowledge, mean time to contain, and incident trends.
  • Oversee SOC analyst workflows, shift handoffs, case documentation, evidence handling, and quality assurance reviews.
  • Coordinate with managed security service providers, internal IT teams, and business stakeholders to ensure timely response and clear ownership of remediation actions.
  • Support implementation and operationalization of SOAR playbooks, automation workflows, enrichment logic, and incident response runbooks.
  • Drive continuous improvement through tabletop exercises, incident retrospectives, purple-team findings, threat hunting outputs, and lessons learned.
  • Maintain alignment with security governance, regulatory, privacy, and audit requirements by ensuring SOC processes are documented, repeatable, measurable, and evidence-ready.
  • Serve as a security operations lead for global SOC coverage and cross-functional collaboration.
Qualifications
Minimum Qualifications
  • Bachelor’s degree in Computer Science, Computer Engineering, Information Security, Cybersecurity, or a related field, or equivalent practical experience.
  • 5+ years of progressive cybersecurity experience, including significant hands‑on experience in security operations, incident response, threat detection, or SOC leadership.
  • 3+ years of experience leading SOC analysts, incident response teams, managed security operations, or cross‑functional cyber defense workflows.
  • Strong working knowledge of SIEM, SOAR, EDR/XDR, cloud security monitoring, identity security, email security, network security, and incident response processes.
  • Demonstrated experience building or improving detection use cases, alert triage workflows, response playbooks, escalation procedures, and SOC metrics.
  • Experience coordinating investigations involving phishing, malware, endpoint compromise, suspicious authentication, privileged access misuse, data exposure, and cloud security events.
  • Familiarity with frameworks and standards such as MITRE ATT&CK, NIST CSF, NIST SP 800-61, ISO 27001, CIS Controls, or equivalent cyber defense frameworks.
  • Ability to communicate clearly with technical teams, business stakeholders, senior leadership, and external partners during security incidents.
  • Strong analytical, documentation, prioritization, and decision‑making skills in high‑pressure operational environments.
  • CISSP, Security+, or equivalent industry certification.
Preferred Qualifications
  • Experience operating or transforming a global SOC in an enterprise environment.
  • Experience working as an Incident Commander, leading IR execution for the company.
  • Experience working with Microsoft Sentinel, Microsoft Defender XDR, KQLs, UEBA, or comparable security operations platforms.
  • Experience with cloud security monitoring across Azure, AWS, GCP, or hybrid cloud environments.
  • Experience with threat hunting, purple‑team collaboration, adversary emulation, or detection engineering.
  • Experience managing managed detection and response providers or outsourced SOC services.
  • Experience in semiconductor, technology, manufacturing, or intellectual property‑intensive environments.
  • Familiarity with GenAI‑assisted SOC workflows, including alert enrichment, analyst productivity, incident summarization, and security automation.
  • Additional certifications such as CEH, or similar.
Job Type

Regular

Shift

Shift 1 (Malaysia)

Primary Location

Penang 15, Penang, Malaysia

Additional Locations

Bengaluru, Karnataka, India

Posting Statement

All qualified applicants will receive consideration for employment without regard to race, color, religion, religious creed, sex, national origin, ancestry, age, physical or mental disability, medical condition, genetic information, military and veteran status, marital status, pregnancy, gender, gender expression, gender identity, sexual orientation, or any other characteristic protected by local law, regulation, or ordinance.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Operations Center Lead
Security Operations Center Lead

Altera Corporation • Malaysia

On-site
MYR 180,000 - 300,000
Senior Cyber Security Consultant (SOC) Cyber security Kuala Lumpur
Senior Cyber Security Consultant (SOC) Cyber security Kuala Lumpur

S-RM Intelligence and Risk Consulting • Kuala Lumpur

Hybrid
MYR 120,000 - 180,000
Senior SOC Consultant
Senior SOC Consultant

S-RM • Kuala Lumpur

Hybrid
MYR 180,000 - 240,000
Hybrid work model
Global collaboration
Soc Manager
Soc Manager

EC-Council Global Services • Kuala Lumpur

On-site
MYR 180,000 - 300,000
Senior SOC Analyst / SOC Engineer (L3)
Senior SOC Analyst / SOC Engineer (L3)

Jobstreet Malaysia • Klang City

On-site
MYR 120,000 - 180,000
Security Analyst (Intelligence - Operations)
Security Analyst (Intelligence - Operations)

GXS Bank • Selangor

On-site
MYR 90,000 - 130,000
SOC Engineer, Kuala Lumpur Cyber security Kuala Lumpur
SOC Engineer, Kuala Lumpur Cyber security Kuala Lumpur

S-RM Intelligence and Risk Consulting • Kuala Lumpur

Hybrid
MYR 60,000 - 90,000
20 days paid holiday plus additional leave
Flexible working hours
Pension scheme
+2
SOC & Cyber Incident Response Lead
SOC & Cyber Incident Response Lead

Epergne Solutions • Kuala Lumpur

On-site
MYR 100,000 - 140,000
Manager Security Operation Centre
Manager Security Operation Centre

GoKardz Technologies • Kuala Lumpur

On-site
MYR 120,000 - 150,000
Cyber Security Operations Lead
Cyber Security Operations Lead

EPAM Systems • Malaysia

On-site
MYR 180,000 - 280,000