SOC Lead

XL Axiata

Kuala Lumpur

On-site

MYR 240,000 - 360,000

Full time

10 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

XL Axiata is seeking a senior security lead in Kuala Lumpur to oversee security monitoring, IR, and platform engineering. The role blends hands-on investigations with leadership, coordinating IR responders, PE/SIEM engineers, and client onboarding to ensure robust detections and rapid response.

You will drive incident containment, root-cause analysis, and remediation while shaping detection lifecycles, playbooks, and threat intelligence integration across the team.

Qualifications

  • Hands-on SIEM and IR with leadership responsibility.
  • Experience in coordinating P1/P2 incidents and multi-team actions.
  • Strong knowledge of threats, detections and response playbooks.
  • Ability to onboard clients, manage data ingestion, and build detections.

Responsibilities

  • Lead high-severity incidents end-to-end and coordinate IR responders.
  • Act as senior escalation point for complex investigations.
  • Guide hands-on analysis across endpoints, network and telemetry.
  • Maintain IR SOPs and escalation workflows for improvements.
  • Lead platform engineering for SIEM onboarding and detections.

Skills

SIEM capability
Platform engineering
Automation/SOAR
Incident response
Digital forensics
Threat hunting
MITRE ATT&CK
Cloud security monitoring
Communication under pressure

Education

Degree/Diploma in IT or Cybersecurity
Certifications: GCIH/GCFA/GREM

Tools

Microsoft Defender XDR
Microsoft Sentinel
Splunk
QRadar
CrowdStrike

Job description

The Lead is the senior technical authority across security monitoring, incident response (IR) andplatform engineering, and leads a combined team on a day-to-day basis. Reporting to theOperations Manager, the Lead sets technical direction, uplifts the maturity of operations andacts as the final escalation point for complex investigations. Three groups report into this role:IR responders, SOC L1/L2 analysts, and Platform Engineering (PE) / SIEM engineers.

The role demands both a hands-on investigator who can independently drive incidents to rootcause and remediation, and a leader who can coordinate IR, direct a shift, and steer theplatform engineering function that onboards clients, answers their coverage questions andbuilds thedetections their environments require.

Key Responsibilities
  • Lead and coordinate high-severity incidents (P1/P2) end-to-end, running bridge calls anddirecting the IR responders through detection, containment, eradication and recovery
  • Serve as the senior escalation and decision point for complex investigations, providingtechnical validation and clear direction under pressure
  • Investigate hands-on to find solutions — deep-dive analysis of endpoint, network andidentity telemetry, malware behaviour and adversary TTPs to establish root cause andremediation, not just triage
  • Guide forensic examination (endpoints, servers, logs, memory, network traffic) to supportinvestigative outcomes and attribution
  • Maintain IR SOPs, forensic playbooks and escalation workflows, feeding lessons learnedback into detections and process
  • Lead technical coordination for cyber drills and tabletop exercises, translating outcomesinto concrete improvements
Platform Engineering (PE) & Detection
  • Lead the PE / SIEM engineering function, directing onboarding of new clients, log sourcesand assets onto the monitoring platform and ensuring healthy, complete data ingestion
  • Act as the senior technical contact for client queries — advising on asset coverage,answering questions about their monitored estate, and translating their needs intomonitoring outcomes
  • Own the detection lifecycle — design, build, test and tune SIEM use cases and correlationrules, including new detections requested by clients or driven by their specific markets andthreat landscape
  • Build and mature automation across monitoring, IR and platform engineering —orchestration and SOAR playbooks that cut manual effort and accelerate response
  • Continuously evaluate best-in-market approaches and tooling (SIEM, SOAR, EDR/XDR,threat intel, AI-assisted triage) and drive adoption where they add clear value
  • Operationalize threat intelligence into detections and run threat hunting / hypothesis-driveninvestigations to close coverage gaps
  • Lead the combined team — IR responders, SOC L1/L2 analysts and PE / SIEM engineers— allocating work, managing shift coverage and ensuring the team consistently follows theright process
  • Uplift the team and set direction — mentor and coach across IR, monitoring and platformengineering, raise technical standards and build a clear path for capability improvement
  • Provide quality assurance over the team's output (triage accuracy, escalation quality,onboarding, detection changes, documentation) and hold the team accountable to SLAsand standards
  • Act as the day-to-day technical face of the team to the Operations Manager, surfacingrisks, gaps and improvement opportunities
Key Performance Indicators (KPIs)
  • Incident handling: number of incidents contained/resolved within SLA; MTTD and MTTR trendimprovements, particularly for P1/P2
  • Detection quality: number of use cases tuned with measurable falsepositive reduction;increase in high-fidelity true-positive alerts
  • Onboarding & platform delivery: client/asset onboarding delivered on schedule; newclient detection requests actioned within agreed timelines; monitoring coveragecompleteness
  • Automation & maturity: number of automated/SOAR workflows implemented; number ofincidents leveraging automation; number of playbooks reviewed and validated on cadence
  • Team performance: adherence to process/SLA; QA scores across IR, SOC and PE;measurable uplift in team capability and feedback on guidance
Person Specifications
Qualifications & Experience
  • 8+ years hands-on experience across security monitoring, incident response and digitalforensics, including senior/escalation responsibility
  • Demonstrable experience leading P1/P2 incidents and coordinating multiple teams underpressure
  • Experience leading or supervising a SOC / IR / engineering team, including shift coverage
  • Experience in SIEM platform engineering — client/log-source onboarding and buildingdetections to meet client requirements
  • Degree/Diploma in Information Technology, Cybersecurity or a related discipline
  • Certifications — preferred: GCIH, GCFA, GREM, CHFI. Good to have: GCIA, GCDA,GMON, Microsoft SC-200, AZ-500, SC-100, CISSP
Knowledge & Technical Skills
Required Skills
  • Deep, hands-on SIEM capability — building, tuning and maintaining use cases, correlation rules and dashboards; strong grounding in detection engineering as a discipline
  • Proven platform engineering experience — onboarding log sources/assets, data ingestion and coverage, and building detections tailored to client environments
  • Proven automation/SOAR experience — designing and implementing orchestration and playbooks to improve SOC and IR efficiency
  • Strong operational IR and digital forensics capability, including malware analysis and threat hunting
  • Solid knowledge of APTs, adversary tools/techniques and MITRE ATT&CK TTPs
  • Strong networking / TCP-IP knowledge and exposure to firewall, IPS, EPP/EDR, DLP, proxy and email security controls
  • Ability to review and integrate PT / vulnerability findings into monitoring and IR workflows
  • Cloud security monitoring across Azure, AWS and GCP
  • Excellent written/verbal communication with the ability to work with clients and lead under pressure during major incidents
Desired Skills
  • Microsoft security stack (strong plus — aligned to our current environment):Microsoft Sentinel (SIEM/SOAR), Microsoft Defender XDR, KQL, Logic Apps automationand Security Copilot
  • Experience with other market-leading platforms (e.g. Splunk, QRadar) and EDR solutions(CrowdStrike, Carbon Black)
  • Scripting/programming for automation (e.g. PowerShell, Python, KQL)
  • Threat intelligence platform experience and the ability to operationalize intel feeds
  • Familiarity with regulatory/compliance-driven incident handling (e.g. NIST, ISO 27035, PDPA/GDPR)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SOC Lead
SOC Lead

Axonect • Kuala Lumpur

On-site
MYR 180,000 - 240,000
SOC Specialist
SOC Specialist

Atos • Cyberjaya

On-site
MYR 120,000 - 180,000
SOC Specialist
SOC Specialist

Pride Global • Selangor

On-site
MYR 140,000 - 230,000
SOC Specialist
SOC Specialist

Pride Global • Cyberjaya

On-site
MYR 120,000 - 180,000
SOC Senior analyst
SOC Senior analyst

Atos • Cyberjaya

On-site
MYR 60,000 - 120,000
Senior SOC Analyst
Senior SOC Analyst

Pride Global • Selangor

On-site
MYR 120,000 - 180,000
Service Manager SIEM/SOC
Service Manager SIEM/SOC

Pride Global • Selangor

On-site
MYR 180,000 - 300,000
Security Delivery Consultant
Security Delivery Consultant

ABP Group • Kuala Lumpur

On-site
MYR 120,000 - 170,000
Senior Security Analyst
Senior Security Analyst

Logicalis Asia Pacific • Kuala Lumpur

On-site
MYR 80,000 - 100,000
Security Operations Center Lead
Security Operations Center Lead

Altera • Bayan Lepas

On-site
MYR 180,000 - 280,000