SIEM Team Lead

Atos

Cyberjaya

On-site

MYR 120,000 - 180,000

Full time

7 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Jora Malaysia is seeking an experienced SIEM Team Lead to oversee day-to-day operations, ensure platform health, and support SOC activities across on-prem and cloud log sources.

You will mentor a technical team, manage detections, tuning, and incident response coordination, and drive improvements in alerting quality and SLAs, in a fast-paced security environment.

Qualifications

  • 5–7+ years of experience in SIEM/SOC or cybersecurity operations.
  • Hands-on experience with Microsoft Sentinel or another enterprise SIEM.
  • Strong knowledge of Kusto Query Language (KQL) and log analysis.
  • Experience with log ingestion, data connectors, parsing, and normalization.
  • Experience handling technical escalations and coordinating with multiple teams.
  • Familiarity with incident, change, and problem management.

Responsibilities

  • Lead and manage the SIEM team, allocating daily operational activities and monitoring delivery.
  • Act as the primary technical escalation point for complex SIEM issues.
  • Monitor SIEM platform health, log ingestion, connectors, parsing, and data quality.
  • Ensure critical log sources are onboarded, available, and continuously monitored.
  • Review and manage detection and correlation rules, including tuning and false-positive reduction.
  • Coordinate with SOC, infrastructure, cloud, network, and application teams to resolve SIEM-related issues.
  • Track team activities, pending tasks, technical issues, and operational milestones.
  • Ensure incidents and service requests are resolved within agreed SLA and OLA timelines.
  • Review SIEM changes and ensure appropriate testing and implementation.
  • Support the onboarding of new log sources, integrations, and security use cases.
  • Review technical incidents, identify root causes, and implement corrective actions.
  • Maintain SIEM standard operating procedures, runbooks, and technical documentation.
  • Support SOC teams during major incidents and provide technical expertise.
  • Participate in disaster recovery and business continuity testing to ensure SIEM monitoring continuity.
  • Provide regular operational updates and reports to management.

Skills

SIEM leadership
SOC operations
KQL / log analysis
Log ingestion & parsing
Incident escalation
Cross-team coordination
SLA / OLA management

Education

Bachelor's degree in Computer Science, Cybersecurity, or related field

Tools

Microsoft Sentinel
Splunk
QRadar
Trellix
Azure security tooling

Job description

Jora Malaysia will close on 9th September 2026. Thank you for being with us, we are cheering you on as you continue your career journey.

The SIEM Team Lead is responsible for managing the day-to-day SIEM operations team, ensuring platform health, log-source availability, detection quality, timely resolution of technical issues, and effective support to Security Operations Center (SOC) operations.

Key Responsibilities

  • Lead and manage the SIEM team, allocating daily operational activities and monitoring delivery.
  • Act as the primary technical escalation point for complex SIEM issues.
  • Monitor SIEM platform health, log ingestion, connectors, parsing, and data quality.
  • Ensure critical log sources are onboarded, available, and continuously monitored.
  • Review and manage detection and correlation rules, including tuning and false-positive reduction.
  • Coordinate with SOC, infrastructure, cloud, network, and application teams to resolve SIEM-related issues.
  • Track team activities, pending tasks, technical issues, and operational milestones.
  • Ensure incidents and service requests are resolved within agreed SLA and OLA timelines.
  • Review SIEM changes and ensure appropriate testing and implementation.
  • Support the onboarding of new log sources, integrations, and security use cases.
  • Review technical incidents, identify root causes, and implement corrective actions.
  • Maintain SIEM standard operating procedures, runbooks, and technical documentation.
  • Support SOC teams during major incidents and provide technical expertise.
  • Participate in disaster recovery and business continuity testing to ensure SIEM monitoring continuity.
  • Provide regular operational updates and reports to management.

Required Qualifications and Skills

  • 5–7+ years of experience in SIEM, SOC, or cybersecurity operations.
  • Strong hands‑on experience with Microsoft Sentinel or another enterprise SIEM platform.
  • Good knowledge of Kusto Query Language (KQL) and log analysis.
  • Strong understanding of log ingestion and data connectors, analytics and detection rules, alert tuning, false-positive reduction, data parsing and normalization, SIEM troubleshooting and health monitoring, and use‑case development and testing.
  • Experience handling technical escalations and coordinating with multiple teams.
  • Good understanding of incident, change, and problem management.
  • Strong troubleshooting, leadership, and communication skills.

Preferred Qualifications

  • Experience with Microsoft Sentinel, Microsoft Defender XDR, Microsoft Entra ID, and Azure security.
  • Knowledge of SOAR, Automation Rules, Logic Apps, and Playbooks.
  • Experience with Splunk, QRadar, ArcSight, or Trellix.
  • Knowledge of MITRE ATT&CK, threat hunting, and threat intelligence.
  • Experience with SIEM migration or onboarding projects.
  • Knowledge of SIEM cost optimization and ingestion monitoring.

Preferred Certifications

  • Microsoft Certified: Security Operations Analyst Associate (SC-200)
  • GIAC Certified Incident Handler (GCIH) or GIAC Certified Intrusion Analyst (GCIA)
  • ITIL 4

Key Performance Indicators

  • SIEM platform and log-source availability.
  • Timely resolution of technical escalations.
  • SLA and OLA compliance.
  • Successful onboarding of log sources and integrations.
  • Improved detection quality and reduced false positives.
  • Timely delivery of SIEM use cases and operational tasks.
  • Reduction in recurring SIEM issues.
  • Effective team performance and operational reporting.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SIEM Team Lead (SOC-02)
SIEM Team Lead (SOC-02)

Tentacle Technologies • Sepang

On-site
MYR 180,000 - 280,000
Mentorship and professional growth
Career progression pathway
Collaborative team culture
+1
Service Manager SIEM-SOC
Service Manager SIEM-SOC

Pride Global • Cyberjaya

On-site
MYR 180,000 - 240,000
SIEM Team Lead
SIEM Team Lead

TENTACLE SSO SDN BHD • Cyberjaya

On-site
MYR 150,000 - 210,000
Career progression
Professional development support
Collaborative team culture
+1
Senior SOC Analyst
Senior SOC Analyst

Pride Global • Cyberjaya

On-site
MYR 120,000 - 180,000
Senior SOC Analyst
Senior SOC Analyst

Pride Global • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Immediate Opening for SOC Service Manager
Immediate Opening for SOC Service Manager

Pan Asia Group • Cyberjaya

On-site
MYR 180,000 - 240,000
SENIOR SOC ANALYST L2
SENIOR SOC ANALYST L2

TechLab Security • Shah Alam

On-site
MYR 120,000 - 180,000
SIEM Team Lead (SOC-02)
SIEM Team Lead (SOC-02)

Tentacle Tech • Cyberjaya

On-site
MYR 120,000 - 180,000
Mentorship and professional growth
Career progression pathway
Supportive team culture
+1
SOC Service Manager
SOC Service Manager

Tentacle Technologies • Sepang

On-site
MYR 180,000 - 300,000
Mentorship
Career progression
Collaborative culture
Service Manager SIEM/SOC
Service Manager SIEM/SOC

Pride Global • Selangor

On-site
MYR 180,000 - 300,000