Senior Incident Response Specialist

StarHub

Petaling Jaya

On-site

MYR 90,000 - 130,000

Full time

5 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

StarHub is seeking a Senior Analyst – Cyber Security Incident Response to monitor, detect, and analyse cybersecurity incidents within the SOC. You will handle end-to-end incident lifecycle from triage to closure, acting as L2 responder and coordinating with internal teams for resolution.

You will perform detailed log correlation across networks, endpoints, and cloud, fine-tune Elastic Stack detections, and contribute to incident documentation and playbooks.

Qualifications

  • 2–3 years of experience in a SOC or Incident Response (L2)
  • Intermediate hands-on experience with SIEM platforms (Elastic Stack preferred)
  • Exposure to incident triage, malware analysis, phishing response, and log correlation
  • Strong understanding of use case creation and MITRE ATT&CK framework mapping
  • Demonstrated ability to analyze complex alerts and distinguish false positives from true incidents
  • Familiarity with security tools such as EDR, NDR, Cyber security tools and threat intelligence platforms
  • Good communication and documentation skills for stakeholder updates
  • Certifications such as CEH, CompTIA Security+, GCIA, or Elastic Certified Analyst preferred

Responsibilities

  • Perform end-to-end incident triage and investigation of security alerts escalated from L1 SOC analysts
  • Ensure timely incident analysis, containment, and escalation aligned with MTTD and MTTR goals
  • Support the SIEM platform by fine-tuning existing rules and suggesting new detections
  • Conduct log analysis and correlation across multiple data sources (network, endpoint, and cloud)
  • Create and maintain incident documentation, reports, and lessons learned
  • Support incident response playbook execution during containment and recovery phases
  • Collaborate with IT, network, and application teams for incident remediation and root cause analysis
  • Provide insights for use case improvements and participate in use case validation and testing
  • Escalate confirmed incidents to CSIRT / Assistant Manager – Incident Response for further action
  • Participate in post-incident reviews, contributing to process and detection improvements

Skills

SOC experience
IR L2
SIEM
MITRE ATT&CK
Log analysis

Tools

Elastic Stack

Job description

The Senior Analyst – Cyber Security Incident Response is responsible for monitoring, detecting, and analysing cybersecurity incidents through the Security Operations Centre (SOC) platform. The role supports the end-to-end incident lifecycle — including triage, investigation, containment, and closure — ensuring timely response to security events and maintaining StarHub's cyber resilience. This role acts as the Level 2 (L2) Incident Responder, bridging SOC analysts and Incident Response management by performing deep technical analysis and coordinating with internal teams for resolution.

Key responsibilities

Perform end-to-end incident triage and investigation of security alerts escalated from L1 SOC analysts

Ensure timely incident analysis, containment, and escalation aligned with MTTD and MTTR goals

Support the SIEM platform (Elastic Stack) by fine-tuning existing rules and suggesting new detections

Conduct log analysis and correlation across multiple data sources (network, endpoint, and cloud)

Create and maintain incident documentation, reports, and lessons learned

Support incident response playbook execution during containment and recovery phases

Collaborate with IT, network, and application teams for incident remediation and root cause analysis

Provide insights for use case improvements and participate in use case validation and testing

Escalate confirmed incidents to CSIRT / Assistant Manager – Incident Response for further action

Participate in post-incident reviews, contributing to process and detection improvements

About you

2–3 years of experience in a SOC or Incident Response (L2) environment

Intermediate hands-on experience with SIEM platforms (Elastic Stack preferred)

Exposure to incident triage, malware analysis, phishing response, and log correlation

Strong understanding of use case creation and MITRE ATT&CK framework mapping

Demonstrated ability to analyze complex alerts and distinguish false positives from true incidents

Familiarity with security tools such as EDR, NDR, Cyber security tools and threat intelligence platforms

Good communication and documentation skills for stakeholder updates

Certifications such as CEH, CompTIA Security+, GCIA, or Elastic Certified Analyst preferred

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Incident Response Lead — SOC & IR
Senior Incident Response Lead — SOC & IR

StarHub • Petaling Jaya

On-site
MYR 90,000 - 130,000
Senior SOC Analyst
Senior SOC Analyst

Pride Global • Selangor

On-site
MYR 120,000 - 180,000
L2 SOC Analyst
L2 SOC Analyst

Pride Global • Selangor

On-site
MYR 60,000 - 110,000
JUNIOR CYBER SECURITY ANALYST
JUNIOR CYBER SECURITY ANALYST

Private Advertiser • Petaling Jaya

On-site
MYR 60,000 - 100,000
Security Delivery Consultant
Security Delivery Consultant

ABP Group • Kuala Lumpur

On-site
MYR 120,000 - 170,000
L2 SOC Analyst – SIEM
L2 SOC Analyst – SIEM

S SQUAD SDN. BHD. • Labuan

On-site
MYR 60,000 - 90,000
SOC Senior analyst
SOC Senior analyst

Atos • Cyberjaya

On-site
MYR 60,000 - 120,000
Cybersecurity Analyst L2/L3
Cybersecurity Analyst L2/L3

Tech Staffing • Kuala Lumpur

On-site
MYR 90,000 - 150,000
SOC L2 IT Security Analyst – Incident Response
SOC L2 IT Security Analyst – Incident Response

RHB Banking Group • Selangor

On-site
MYR 60,000 - 110,000
SOC Specialist
SOC Specialist

Pride Global • Cyberjaya

On-site
MYR 120,000 - 180,000