Senior Security Analyst

Logicalis Asia Pacific

Kuala Lumpur

On-site

MYR 80,000 - 100,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Logicalis Asia Pacific in Kuala Lumpur seeks an experienced SOC Analyst to lead incident response and threat hunting initiatives. The role demands strong expertise in security technologies including Splunk, IBM QRadar, and Azure Sentinel, with a particular focus on collaboration and mentoring junior analysts. The preferred candidate will have 8-10 years of experience in SOC environments and relevant degree in Cyber Security or similar fields. This position offers opportunities for professional growth in a dynamic team environment.

Qualifications

  • At least 8–10 years of working experience in SOC and MSS environments.
  • Excellent hands-on experience in incident analysis using Splunk and other SIEM technologies.
  • Knowledge of current cyber threats and attack vectors.

Responsibilities

  • Lead incident response lifecycle including detection and recovery.
  • Conduct forensic analysis and generate incident reports.
  • Mentor junior SOC analysts in investigations and tool usage.

Skills

Incident analysis
Threat hunting
Security orchestration
Cyber threat knowledge
Team collaboration

Education

Bachelor's degree in Computer Engineering, Computer Science, Cyber Security, or equivalent

Tools

Splunk
IBM QRadar
Azure Sentinel
CrowdStrike
Microsoft Defender

Job description

About Logicalis

As Architects of Change, Logicalis' focus is to design, support and execute clients' digital transformation by uniting their vision with their technology expertise and industry insights. The company, through its deep understanding of key IT industry drivers such as security, cloud, data management and IoT, can address customer priorities such as revenue growth, business and operational efficiency, innovation, risk and compliance, data governance and sustainability.

Detection Engineering
  • Design, develop, and deploy high‑fidelity detection rules in SIEM (Splunk, Microsoft Sentinel, Devo, QRadar, EDR, etc.).
  • Create custom use cases to detect MITRE TTPs aligned with real‑world threats and red team activities.
  • Conduct detection gap analysis, tune alerting mechanisms, and eliminate false positives in the MSS customer environment.
  • Perform regular fine‑tuning and optimization of detection rules, correlation logic, and alert thresholds across SIEM, EDR, and other security platforms to enhance detection accuracy and reduce false positives.
  • Continuously assess detection efficacy based on incident feedback and threat landscape evolution, implementing improvements accordingly.
  • Collaborate with red/purple teams to validate detection logic and build threat‑informed defenses.
  • Regularly review, update, and enhance detection logic to ensure alignment with the latest threat intelligence, adversary TTPs, and evolving attack techniques.
  • Maintain relevancy and effectiveness of security detections by incorporating insights from threat hunts, incident response cases, red team exercises, and industry best practices.
Threat Hunting and Threat Intel
  • Proactively hunt for advanced threats across on‑prem and cloud environments using telemetry from SIEM, EDR, NDR, and threat intelligence.
  • Develop hypotheses based on TTPs, threat intelligence feeds, and incident trends.
  • Use frameworks like MITRE ATT&CK and the Diamond Model to structure hunting campaigns.
  • Document hunt procedures and outcomes to support knowledge sharing and continuous improvement.
  • Map threat actor TTPs to frameworks such as MITRE ATT&CK to support proactive defense strategies and inform detection engineering efforts.
  • Provide actionable threat intelligence to SOC, detection engineering, and IR teams to inform custom detection rule development, prioritization of hunts, and incident scoping.
  • Contribute to the threat intelligence lifecycle, including direction, collection, processing, analysis, dissemination, and feedback.
  • Ingest, analyze, and operationalize threat intelligence from internal sources, commercial feeds, and open‑source intelligence (OSINT) to enrich detection logic, threat hunting hypotheses, and incident investigations.
  • Collaborate with internal and commercial threat intelligence teams to contextualize IOCs and TTPs for targeted and industry‑specific threats.
  • Maintain up‑to‑date threat intelligence repositories and contribute to the continuous improvement of threat intel processes and playbooks.
Incident Response
  • Lead incident response lifecycle (detection, triage, containment, eradication, recovery).
  • Handle security incident tickets escalated by Level II team, and draft security incident reports covering the root cause, forensic evidence, and recommended mitigation plans.
  • Conduct/support forensic analysis of endpoints, logs, and network traffic to determine root cause and impact.
  • Coordinate with internal stakeholders and external partners during critical incidents.
  • Develop and maintain playbooks, runbooks, and incident reports.
  • Digital Forensics and Incident Response (DFIR) experience is a strong added advantage, enabling deeper investigations and root cause analysis.
Collaboration & Mentorship
  • Mentor and support L1/L2 SOC analysts in investigations, tool usage, and processes.
  • Participate in tabletop exercises and red/purple team assessments.
  • Lead and conduct regular customer meetings to review SOC activities, including security posture, key metrics and ongoing initiatives.
  • Prepare and deliver detailed briefings on priority incidents, RCA, ensuring timely communication of root cause, impact analysis, mitigation steps, and next actions.
  • Act as a primary point of contact for incident escalations and maintain consistent, professional engagement with client stakeholders.
  • Coordinate with cross‑functional teams including Engineering, Development, Red Team, and Risk/Compliance.
  • Identify gaps in existing SOC processes and work with team members or other departments to create, modify standard operating procedures, to automate any mundane daily operational activities, ensuring operations are run efficiently.
Requirements
  • At least 8–10 years of working experience in SOC and MSS environments.
  • Bachelor's degree in Computer Engineering, Computer Science, Cyber Security, Information Security, or equivalent.
  • Excellent hands‑on experience in implementing and analyzing incidents in Splunk, IBM QRadar, Azure Sentinel SIEM, and Devo technologies.
  • Hands‑on experience with Endpoint Protection (EPP) or Endpoint Detection Response (EDR) technologies; preferred if CrowdStrike or Microsoft Defender.
  • Hands‑on experience with SOAR (Security Orchestration, Automation and Response) technologies.
  • Experience in malware analysis for Windows, Linux and Mac.
  • Exposure to firewall technologies such as Cisco, Palo Alto, Checkpoint and Fortinet.
  • Good understanding of Windows and Linux environments and proficiency with basic Linux commands and troubleshooting, with proven Unix (Solaris, Linux, BSD) experience.
  • Knowledge of a shell scripting language and ability to apply it to automate routine operations tasks.
  • Knowledge of current cyber threats, attack vectors, vulnerabilities and threat intelligence feeds.
  • Ability to work effectively in a team environment, collaborate cross‑functionally, and mentor junior analysts.
  • At least one SANS certification; preferred if GCIH.
  • Good understanding of basic network concepts and exposure to cloud technologies.
  • Lateral thinking combined with excellent troubleshooting skills, preferably with experience following ITIL standards.
  • Experience leading a team of security analysts, developing SOC standard operating procedures and developing Threat Intel feeds such as MISP.

Interested applicants please submit your application with your expected salary and notice period to be considered for the role. We regret that only shortlisted candidates will be notified.

As part of any recruitment process, we collect and process personal data relating to job applicants. We are committed to being transparent about how we collect and use that data and to meeting our data protection obligations. By applying to this post and sending us your resume, you agree to the collection, use and/or disclosure of your personal data in the manner as set out in our Data Protection Notice for Job Applicants. Click below to view the data protection notice.

https://ap.logicalis.com/sites/default/files/2022-10/PIMS-A7.3-01%20Attachment%20I%20DP%20Notice%20for%20Job%20Applicants_updated9sept22.pdf

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Analyst
Senior Security Analyst

All jobs • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Senior Security Analyst
Senior Security Analyst

Logicalis • Kuala Lumpur

On-site
MYR 180,000 - 300,000
Senior Security Analyst
Senior Security Analyst

Logicalis GmbH • Kuala Lumpur

On-site
MYR 80,000 - 120,000
SOC Intern
SOC Intern

All jobs • Kuala Lumpur

On-site
SOC Intern
SOC Intern

Logicalis Asia Pacific • Kuala Lumpur

On-site
Security Analyst (Intelligence & Operations)
Security Analyst (Intelligence & Operations)

GXS Bank • Petaling Jaya

On-site
MYR 90,000 - 150,000
Security Analyst (Intelligence - Operations)
Security Analyst (Intelligence - Operations)

GXS Bank • Selangor

On-site
MYR 90,000 - 130,000
Senior Threat Hunter & Detection Engineer Lead
Senior Threat Hunter & Detection Engineer Lead

Logicalis • Kuala Lumpur

On-site
MYR 180,000 - 300,000
SOC Lead
SOC Lead

Axonect • Kuala Lumpur

Hybrid
MYR 140,000 - 180,000
SOC Intern
SOC Intern

Logicalis GmbH • Kuala Lumpur

On-site