Senior Security Analyst (SOC Level 3)

Ensign Services

Kuala Lumpur

On-site

MYR 70,000 - 130,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Ensign Services is seeking a skilled SOC Analyst to lead incident response, perform forensic analysis, and develop detection capabilities. You will work with cross-functional teams to identify root causes and improve defense effectiveness.

The role requires hands-on experience with SIEM/EDR/IDS and a strong understanding of TTPs, MITRE ATT&CK, and cloud security monitoring. Strong communication and mentoring skills are essential for success.

Qualifications

  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field.
  • Strongly preferred certifications.
  • Experience in SOC operations, incident response, or threat detection is desirable.
  • Applicants should demonstrate solid analytical and communication skills.

Responsibilities

  • Lead high-severity incident response and containment activities across IT and business units.
  • Conduct forensic analysis on endpoints, networks, and logs to determine root cause.
  • Develop detection use cases and correlation rules from threat intel and MITRE ATT&CK.
  • Perform proactive threat hunting using SIEM, EDR, and intel feeds.
  • Fine-tune alerts and playbooks to reduce false positives and improve SOC efficiency.
  • Mentor L1/L2 analysts and provide guidance and quality review of investigations.
  • Serve as escalation point for complex security issues and investigations.
  • Contribute to post-mortems and propose security posture improvements.
  • Collaborate with red/purple teams and engineering to validate defenses.

Skills

Analytical thinking
Problem-solving
Communication skills
Leadership of investigations
Cross-functional collaboration

Education

Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or related field

Tools

SIEM
EDR
IDS/IPS
SOAR
Threat intel feeds
Python
PowerShell
Bash
Windows
Linux
AWS/Azure security monitoring

Job description

Key Responsibilities:
  • Lead high-severity incident response and containment activities, coordinating with stakeholders across IT and business units.

  • Conduct in-depth forensic analysis on endpoints, networks, and logs to determine the root cause and impact of security incidents.

  • Develop advanced detection use cases and correlation rules based on threat intelligence and TTPs (MITRE ATT&CK, etc.).

  • Perform proactive threat hunting using SIEM, EDR, and threat intel feeds to uncover undetected threats.

  • Review and fine-tune alerts, playbooks, and automation workflows to reduce false positives and improve SOC efficiency.

  • Mentor L1 and L2 analysts, providing guidance, training, and quality review of investigations.

  • Serve as a technical escalation point for complex security issues and investigations.

  • Contribute to incident post-mortems and provide recommendations to improve security posture and processes.

  • Collaborate with red/purple teams and engineering to simulate attacks and validate defense effectiveness.

Requirements:
Education & Certification:
  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field.

  • Strongly preferred certifications:

Technical Skills:
  • Deep understanding of security monitoring and detection tools (SIEM, EDR, IDS/IPS, SOAR).

  • Strong hands-on experience in forensic tools, log analysis, malware analysis, and packet inspection.

  • Solid grasp of attacker tactics, techniques, and procedures (TTPs), threat modeling, and behavior analytics.

  • Familiarity with scripting or automation (Python, PowerShell, Bash) is an advantage.

  • Experience with Windows, Linux, and cloud environments (AWS/Azure security monitoring).

Soft Skills:
  • Excellent analytical and problem-solving skills.

  • Strong written and verbal communication, including report writing.

  • Ability to lead investigations and influence cross-functional teams under pressure.

Preferred Experience:
  • 4–6+ years of experience in SOC operations, incident response, or threat detection.

  • Experience working in or leading incident response within a 24x7 SOC or MSSP environment.

  • Prior involvement in threat hunting or red/purple team collaboration is a strong plus.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Analyst (Intelligence & Operations)
Security Analyst (Intelligence & Operations)

GXS Bank • Petaling Jaya

On-site
MYR 90,000 - 150,000
Senior SOC Analyst
Senior SOC Analyst

Pride Global • Selangor

On-site
MYR 120,000 - 180,000
Security Analyst (Intelligence & Operations)
Security Analyst (Intelligence & Operations)

GXBank • Petaling Jaya

On-site
MYR 120,000 - 180,000
Security Analyst L3
Security Analyst L3

Ensign Services • Rawang

On-site
MYR 120,000 - 180,000
SOC Specialist
SOC Specialist

Pride Global • Cyberjaya

On-site
MYR 120,000 - 180,000
L2 SOC Analyst
L2 SOC Analyst

Pride Global • Selangor

On-site
MYR 60,000 - 110,000
SOC Analyst L2
SOC Analyst L2

PERSOL Workforce Solutions Malaysia Sdn Bhd • Kuala Lumpur

On-site
MYR 60,000 - 100,000
SOC Lead
SOC Lead

Axonect • Kuala Lumpur

On-site
MYR 180,000 - 240,000
Senior Security Analyst
Senior Security Analyst

Logicalis • Kuala Lumpur

On-site
MYR 180,000 - 300,000
Cyber Security Engineer
Cyber Security Engineer

RHB Banking Group • Selangor

On-site
MYR 80,000 - 120,000