Security Operations Center Lead

Altera Corporation

Kuala Lumpur

On-site

MYR 180,000 - 360,000

Full time

4 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Altera Corporation in Kuala Lumpur seeks an experienced Security Operations Center Lead to mature our global security monitoring, detection, incident response, and cyber defense capabilities. This role will guide day-to-day SOC operations, alert triage, and playbook execution across IT, cloud, identity, endpoint, network, and applications.

The ideal candidate combines hands-on security operations depth with leadership discipline and measurable improvements in detection coverage, response

Qualifications

  • Bachelor's degree or equivalent practical experience.
  • 5+ years of cybersecurity experience with hands-on security operations, incident response, threat detection, or SOC leadership.
  • 3+ years of experience leading SOC analysts, IR teams, or cross-functional cyber defense workflows.
  • Strong working knowledge of SIEM, SOAR, EDR/XDR, cloud security monitoring, identity security, email security, network security, and IR processes.
  • Familiarity with MITRE ATT&CK, NIST CSF, NIST SP 800-61, ISO 27001, CIS Controls.
  • Ability to communicate clearly with technical teams, leadership, and external partners during incidents.
  • Strong analytical, documentation, prioritization, and decision-making skills under pressure.
  • CISSP, Security+, or equivalent certification.

Responsibilities

  • Lead daily SOC operations across monitoring, triage, investigation, and incident response coordination.
  • Own and mature SOC operating procedures, including intake, escalation, and post-incident reviews.
  • Improve security monitoring across SIEM, SOAR, EDR/XDR, cloud, identity, and network telemetry.
  • Develop detection use cases aligned to MITRE ATT&CK and business assets.
  • Coordinate with engineering and MSPs to improve log onboarding and alert fidelity.
  • Lead IR coordination for phishing, endpoint compromise, cloud misconfigurations, and data loss events.
  • Establish SOC metrics and reporting on alert volume, MTTD, MTTA, containment time, and trends.
  • Oversee analyst workflows, evidence handling, and quality assurance.
  • Engage stakeholders to ensure timely remediation actions.

Skills

SOC leadership
Incident response
Threat detection
SIEM/SOAR/EDR/XDR
Cloud security monitoring
Identity security
Email security
Network security
Communication
Documentation
Decision-making

Education

Bachelor's degree in Computer Science / Information Security
CISSP / Security+ or equivalent

Tools

Microsoft Sentinel
Microsoft Defender XDR
KQLs
UEBA

Job description

# Job DescriptionAltera is seeking an experienced and hands-on Security Operations Center Lead to lead and mature our global security monitoring, detection, incident response, and cyber defense capabilities. This role will be responsible for day-to-day SOC operations, alert triage, incident escalation, use case development, playbook execution, threat monitoring, and operational reporting across enterprise IT, cloud, identity, endpoint, network, and application environments.This leader will partner closely with security engineering, infrastructure, identity, cloud, IT operations, legal, privacy, product security, and managed service providers to ensure security events are detected, investigated, contained, and remediated effectively. The ideal candidate combines strong technical security operations depth with leadership discipline, process ownership, and the ability to drive measurable improvements in detection coverage, response quality, automation, and operational resilience.# Key Responsibilities* Lead daily SOC operations across monitoring, alert triage, investigation, escalation, incident response coordination, and operational handoff across global time zones.* Own and mature SOC operating procedures, including incident intake, severity classification, escalation paths, response playbooks, major incident communications, and post-incident reviews.* Manage and improve security monitoring across SIEM, SOAR, EDR/XDR, email security, cloud security, identity security, vulnerability signals, network telemetry, and threat intelligence sources.* Build, tune, and continuously improve detection use cases aligned to enterprise risks, MITRE ATT&CK techniques, threat intelligence, audit findings, and business-critical assets.* Partner with security engineering teams to improve log onboarding, data quality, telemetry coverage, alert fidelity, automation, and response integrations.* Lead incident response coordination for security events involving endpoint compromise, identity misuse, phishing, malware, data loss indicators, cloud misconfigurations, suspicious network activity, and unauthorized access attempts.* Establish SOC performance metrics and reporting, including alert volumes, false-positive rates, SLA adherence, escalation quality, mean time to detect, mean time to acknowledge, mean time to contain, and incident trends.* Oversee SOC analyst workflows, shift handoffs, case documentation, evidence handling, and quality assurance reviews.* Coordinate with managed security service providers, internal IT teams, and business stakeholders to ensure timely response and clear ownership of remediation actions.* Support implementation and operationalization of SOAR playbooks, automation workflows, enrichment logic, and incident response runbooks.* Drive continuous improvement through tabletop exercises, incident retrospectives, purple-team findings, threat hunting outputs, and lessons learned.* Maintain alignment with security governance, regulatory, privacy, and audit requirements by ensuring SOC processes are documented, repeatable, measurable, and evidence-ready.* Serve as a security operations lead for global SOC coverage and cross-functional collaboration.### ## **Qualifications:**# Qualifications## Minimum Qualifications* Bachelor’s degree in Computer Science, Computer Engineering, Information Security, Cybersecurity, or a related field, or equivalent practical experience.* 5+ years of progressive cybersecurity experience, including significant hands-on experience in security operations, incident response, threat detection, or SOC leadership.* 3+ years of experience leading SOC analysts, incident response teams, managed security operations, or cross-functional cyber defense workflows.* Strong working knowledge of SIEM, SOAR, EDR/XDR, cloud security monitoring, identity security, email security, network security, and incident response processes.* Demonstrated experience building or improving detection use cases, alert triage workflows, response playbooks, escalation procedures, and SOC metrics.* Experience coordinating investigations involving phishing, malware, endpoint compromise, suspicious authentication, privileged access misuse, data exposure, and cloud security events.* Familiarity with frameworks and standards such as MITRE ATT&CK, NIST CSF, NIST SP 800-61, ISO 27001, CIS Controls, or equivalent cyber defense frameworks.* Ability to communicate clearly with technical teams, business stakeholders, senior leadership, and external partners during security incidents.* Strong analytical, documentation, prioritization, and decision-making skills in high-pressure operational environments.* CISSP, Security+, or equivalent industry certification.## Preferred Qualifications* Experience operating or transforming a global SOC in an enterprise environment.* Experience working as an Incident Commander, leading IR execution for the company.* Experience working with Microsoft Sentinel, Microsoft Defender XDR, KQLs, UEBA, or comparable security operations platforms.* Experience with cloud security monitoring across Azure, AWS, GCP, or hybrid cloud environments.* Experience with threat hunting, purple-team collaboration, adversary emulation, or detection engineering.* Experience managing managed detection and response providers or outsourced SOC services.* Experience in semiconductor, technology, manufacturing, or intellectual property-intensive environments.* Familiarity with GenAI-assisted SOC workflows, including alert enrichment, analyst productivity, incident summarization, and security automation.* Additional certifications such as CEH, or similar.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Operations Center Lead
Security Operations Center Lead

Altera Corporation • Malaysia

On-site
MYR 180,000 - 300,000
Principal Network Security Engineer
Principal Network Security Engineer

Altera Corporation • Kuala Lumpur

On-site
MYR 240,000 - 420,000
Security Operations Center Lead
Security Operations Center Lead

Altera • Bayan Lepas

On-site
MYR 180,000 - 280,000
SOC Lead
SOC Lead

Axonect • Kuala Lumpur

On-site
MYR 180,000 - 240,000
Senior SOC Analyst
Senior SOC Analyst

Pride Global • Selangor

On-site
MYR 120,000 - 180,000
Security Delivery Consultant
Security Delivery Consultant

ABP Group • Kuala Lumpur

On-site
MYR 120,000 - 170,000
Security Analyst (Intelligence & Operations)
Security Analyst (Intelligence & Operations)

GXS Bank • Petaling Jaya

On-site
MYR 90,000 - 150,000
SOC Specialist
SOC Specialist

Pride Global • Cyberjaya

On-site
MYR 120,000 - 180,000
SOC Specialist
SOC Specialist

Pride Global • Selangor

On-site
MYR 140,000 - 230,000
Service Manager SIEM/SOC
Service Manager SIEM/SOC

Pride Global • Selangor

On-site
MYR 180,000 - 300,000