SIEM/MDR Infra support (SOC Cybersecurity)

Atos

Cyberjaya

On-site

MYR 180,000 - 240,000

Full time

5 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Atos is seeking an experienced SIEM infra support specialist in Cyberjaya to lead day-to-day SIEM operations ensuring platform health, log-source availability, and high-quality detection. You will coordinate with SOC, infrastructure, cloud, network, and applications teams to resolve SIEM-related issues.

The role emphasizes tuning detection rules, reducing false positives, onboarding new log sources, and maintaining runbooks and documentation to support incident response and disaster recovery

Qualifications

  • 5–7+ years of experience in SIEM, SOC, or cybersecurity operations.
  • Strong hands-on experience with Microsoft Sentinel or another enterprise SIEM platform.
  • Good knowledge of KQL and log analysis.
  • Strong understanding of log ingestion, data connectors, analytics and detection rules.
  • Experience handling technical escalations and coordinating with multiple teams.
  • Knowledge of incident, change, and problem management.
  • Strong troubleshooting, leadership, and communication skills.

Responsibilities

  • Lead and manage the SIEM team, allocating daily operational activities and monitoring delivery.
  • Act as the primary technical escalation point for complex SIEM issues.
  • Monitor SIEM platform health, log ingestion, connectors, parsing, and data quality.
  • Ensure critical log sources are onboarded, available, and continuously monitored.
  • Review and manage detection and correlation rules, including tuning and false-positive reduction.
  • Coordinate with SOC, infrastructure, cloud, network, and application teams to resolve SIEM-related issues.
  • Track team activities, pending tasks, technical issues, and operational milestones.
  • Ensure incidents and service requests are resolved within agreed SLA and OLA timelines.
  • Review SIEM changes and ensure testing and implementation.
  • Support onboarding of new log sources, integrations, and security use cases.
  • Review technical incidents, identify root causes, and implement corrective actions.
  • Maintain SIEM SOPs, runbooks, and technical documentation.
  • Support SOC during major incidents and provide technical expertise.
  • Participate in disaster recovery and business continuity testing for SIEM monitoring continuity.
  • Provide regular operational updates and reports to management.

Skills

SIEM operations
Team leadership
Kusto Query Language (KQL)
Log ingestion & data quality
Incident/change/problem management
Technical escalation
Collaboration across teams

Tools

Microsoft Sentinel
Splunk
QRadar
ArcSight
Trellix

Job description

The SIEM infra support specialist is responsible for managing the day-to-day SIEM operations team, ensuring platform health, log-source availability, detection quality, timely resolution of technical issues, and effective support to Security Operations Center (SOC) operations.

Key Responsibilities

  • Lead and manage the SIEM team, allocating daily operational activities and monitoring delivery.
  • Act as the primary technical escalation point for complex SIEM issues.
  • Monitor SIEM platform health, log ingestion, connectors, parsing, and data quality.
  • Ensure critical log sources are onboarded, available, and continuously monitored.
  • Review and manage detection and correlation rules, including tuning and false-positive reduction.
  • Coordinate with SOC, infrastructure, cloud, network, and application teams to resolve SIEM-related issues.
  • Track team activities, pending tasks, technical issues, and operational milestones.
  • Ensure incidents and service requests are resolved within agreed SLA and OLA timelines.
  • Review SIEM changes and ensure appropriate testing and implementation.
  • Support the onboarding of new log sources, integrations, and security use cases.
  • Review technical incidents, identify root causes, and implement corrective actions.
  • Maintain SIEM standard operating procedures, runbooks, and technical documentation.
  • Support SOC teams during major incidents and provide technical expertise.
  • Participate in disaster recovery and business continuity testing to ensure SIEM monitoring continuity.
  • Provide regular operational updates and reports to management.

Required Qualifications and Skills

  • 5–7+ years of experience in SIEM, SOC, or cybersecurity operations.
  • Strong hands-on experience with Microsoft Sentinel or another enterprise SIEM platform.
  • Good knowledge of Kusto Query Language (KQL) and log analysis.
  • Strong understanding of log ingestion and data connectors, analytics and detection rules, alert tuning, false-positive reduction, data parsing and normalization, SIEM troubleshooting and health monitoring, and use-case development and testing.
  • Experience handling technical escalations and coordinating with multiple teams.
  • Good understanding of incident, change, and problem management.
  • Strong troubleshooting, leadership, and communication skills.

Preferred Qualifications

  • Experience with Microsoft Sentinel, Microsoft Defender XDR, Microsoft Entra ID, and Azure security.
  • Knowledge of SOAR, Automation Rules, Logic Apps, and Playbooks.
  • Experience with Splunk, QRadar, ArcSight, or Trellix.
  • Knowledge of MITRE ATT&CK, threat hunting, and threat intelligence.
  • Experience with SIEM migration or onboarding projects.
  • Knowledge of SIEM cost optimization and ingestion monitoring.

Preferred Certifications

  • Microsoft Certified: Security Operations Analyst Associate (SC-200)
  • GIAC Certified Incident Handler (GCIH) or GIAC Certified Intrusion Analyst (GCIA)
  • ITIL 4

Key Performance Indicators

  • SIEM platform and log-source availability.
  • Timely resolution of technical escalations.
  • SLA and OLA compliance.
  • Successful onboarding of log sources and integrations.
  • Improved detection quality and reduced false positives.
  • Timely delivery of SIEM use cases and operational tasks.
  • Reduction in recurring SIEM issues.
  • Effective team performance and operational reporting.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

SOC Specialist
SOC Specialist

Pride Global • Cyberjaya

On-site
MYR 120,000 - 180,000
SOC Specialist
SOC Specialist

Atos • Cyberjaya

On-site
MYR 120,000 - 180,000
Security Delivery Consultant
Security Delivery Consultant

ABP Group • Kuala Lumpur

On-site
MYR 120,000 - 170,000
Senior SIEM Engineer
Senior SIEM Engineer

Randstad Malaysia • Kuala Lumpur

On-site
MYR 180,000 - 240,000
SOC Senior analyst
SOC Senior analyst

Atos • Cyberjaya

On-site
MYR 60,000 - 120,000
Senior SIEM & MDR Infra Lead — SOC Operations
Senior SIEM & MDR Infra Lead — SOC Operations

Atos • Cyberjaya

On-site
MYR 180,000 - 240,000
Splunk Enterprise Security Engineer
Splunk Enterprise Security Engineer

NTT DATA Business Solutions • Cyberjaya

On-site
MYR 120,000 - 180,000
Medical Insurance
Health Insurance
Optical and Dental Benefits
Lead Analyst, Digital Security
Lead Analyst, Digital Security

AIA Digital+ • Kuala Lumpur

On-site
MYR 60,000 - 85,000
Senior Incident Response Specialist
Senior Incident Response Specialist

Starhub Ltd • Petaling Jaya

On-site
MYR 60,000 - 90,000
L2 SOC Analyst – SIEM
L2 SOC Analyst – SIEM

S SQUAD SDN. BHD. • Labuan

On-site
MYR 60,000 - 90,000