SOC Specialist

Atos

Cyberjaya

On-site

MYR 120,000 - 180,000

Full time

2 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Atos in Cyberjaya is seeking a SOC Specialist to lead advanced monitoring, investigations, and threat hunting across SIEM, EDR/XDR, identity, network, and cloud environments. The role requires hands-on expertise with incident response, detection engineering, and cross-team collaboration.

You will mentor L1/L2 analysts, refine detection logic, and drive improvements to reduce alerts and false positives while delivering thorough technical reports and escalation guidance.

Qualifications

  • 5–7+ years of hands-on SOC or cybersecurity experience.
  • Expertise in L2/L3 security monitoring, incident investigation, and escalation.
  • Experience handling high-severity incidents in enterprise environments.
  • Strong knowledge of MITRE ATT&CK and threat intelligence.

Responsibilities

  • Perform advanced investigations of complex, high-risk incidents.
  • Analyze events across SIEM, EDR/XDR, identity, network, cloud, and logs.
  • Correlate data to establish attack timelines and scope.
  • Investigate persistence, privilege escalation, lateral movement, and data exfiltration.
  • Threat hunt using indicators, hypotheses, and intelligence.
  • Map activities to MITRE ATT&CK techniques and assess relevance.
  • Review and tune SIEM analytics, rules, and thresholds.
  • Identify detection gaps and reduce false positives.
  • Support major incident response and root-cause analysis.
  • Mentor L1/L2 SOC analysts and conduct drills and simulations.
  • Coordinate remediation with security and infrastructure teams.
  • Prepare technical reports and present findings to stakeholders.

Skills

KQL
Threat hunting
Incident escalation
Technical documentation

Tools

Microsoft Sentinel
Microsoft Defender XDR
EDR/XDR
SOAR
Logic Apps
Splunk
QRadar
Azure/AWS/GCP security

Job description

The SOC Specialist is a technical security resource responsible for advanced monitoring, complex incident investigation, threat detection, threat hunting, detection-engineering support, and technical escalation. The role provides specialist-level expertise to SOC analysts and supports the continuous improvement of SOC detection and response capabilities.

Key Responsibilities
  • Perform advanced investigations of complex, high-risk, and escalated security incidents.
  • Analyze events across SIEM, EDR/XDR, identity, network, email, cloud, firewall, proxy, application, and related security logs.
  • Correlate multiple data sources to establish the attack timeline, entry point, affected assets, user impact, and overall scope.
  • Investigate suspicious processes, PowerShell activity, scripts, persistence, credential abuse, lateral movement, privilege escalation, and data exfiltration.
  • Conduct proactive threat hunting using indicators of compromise, tactics, techniques and procedures, behavioral indicators, hypotheses, and threat intelligence.
  • Map observed activities to MITRE ATT&CK techniques and identify attack progression.
  • Validate threat-intelligence indicators and assess their relevance to the environment.
  • Review and tune SIEM analytics, detection logic, correlation rules, and alert thresholds.
  • Identify detection gaps, recommend new security use cases, and reduce recurring alerts and false positives.
  • Support major incident response, containment, eradication, recovery, and root-cause analysis activities.
  • Provide technical guidance and mentoring to L1 and L2 SOC analysts.
  • Support alert drills, tabletop exercises, threat simulations, and incident-response testing.
  • Coordinate remediation with infrastructure, endpoint, network, identity, cloud, application, and security teams.
  • Prepare detailed technical investigation reports and present findings to SOC management and customers.
  • Maintain investigation procedures, playbooks, hunting documentation, and technical knowledge articles.
Required Experience and Qualifications
  • 5–7+ years of hands-on SOC or cybersecurity experience.
  • Proven experience in L2/L3 security monitoring, incident investigation, and technical escalation.
  • Experience handling critical and high-severity incidents in an enterprise SOC, MDR, or MSSP environment.
  • Strong hands-on experience with Microsoft Sentinel or an equivalent enterprise SIEM.
  • Strong hands-on experience with Microsoft Defender XDR, Defender for Endpoint, or an equivalent EDR/XDR platform.
  • Strong KQL knowledge, with the ability to independently query and correlate security data.
  • Strong knowledge of incident response, threat hunting, threat intelligence, MITRE ATT&CK, IOC/TTP analysis, endpoint investigation, identity and authentication attacks, network security analysis, email and phishing investigation, malware and ransomware investigation, PowerShell and command-line analysis, lateral movement, privilege escalation, persistence mechanisms, and data exfiltration.
  • Strong technical documentation and report-writing skills.
  • Ability to communicate complex security findings to technical and non-technical stakeholders.
  • Ability to challenge investigation findings, provide technical recommendations, mentor junior analysts, and improve investigation quality.
Independent Investigation Capabilities
  • Build an end-to-end attack timeline.
  • Identify the initial access vector and affected entities.
  • Determine whether an alert is a true positive or false positive.
  • Identify related users, devices, IP addresses, domains, hashes, processes, and accounts.
  • Determine the incident scope and potential business impact.
  • Recommend containment and remediation actions.
  • Identify detection gaps following an incident.
Preferred Experience and Knowledge
  • Experience with Defender for Identity, Defender for Cloud, Microsoft Entra ID, Microsoft Purview, and Intune.
  • Experience with SOAR, Logic Apps, playbooks, and security automation.
  • Experience with Trellix, Palo Alto, Splunk, QRadar, or ArcSight.
  • Knowledge of UEBA and behavioral analytics.
  • Experience with Google Threat Intelligence or other threat-intelligence platforms.
  • Knowledge of malware analysis and digital forensics.
  • Experience developing Microsoft Sentinel analytics rules and advanced hunting queries.
  • Knowledge of Azure, AWS, or Google Cloud security.
  • Experience in SIEM/EDR migration or SOC transformation projects.
Preferred Certifications
  • GCFA or GCIA
  • Microsoft Certified: Security Operations Analyst Associate (SC-200)
  • CISSP
  • CompTIA Security+ or CEH
Key Performance Indicators
  • Accurate and timely resolution of complex security incidents.
  • Quality of advanced investigations and incident documentation.
  • Effective threat hunting and identification of previously unknown threats.
  • Reduction in missed detections and false positives.
  • Improvement in detection and use-case coverage.
  • Timely technical escalation and remediation.
  • Quality of root-cause analyses and corrective-action recommendations.
  • Effective technical mentoring of SOC analysts.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

SOC Specialist
SOC Specialist

Pride Global • Selangor

On-site
MYR 140,000 - 230,000
SOC Specialist
SOC Specialist

Pride Global • Cyberjaya

On-site
MYR 120,000 - 180,000
SOC Senior analyst
SOC Senior analyst

Atos • Cyberjaya

On-site
MYR 60,000 - 120,000
Senior SOC Analyst
Senior SOC Analyst

Pride Global • Selangor

On-site
MYR 120,000 - 180,000
Service Manager SIEM/SOC
Service Manager SIEM/SOC

Pride Global • Selangor

On-site
MYR 180,000 - 300,000
L2 SOC Analyst
L2 SOC Analyst

Pride Global • Selangor

On-site
MYR 60,000 - 110,000
SOC Lead
SOC Lead

Axonect • Kuala Lumpur

On-site
MYR 180,000 - 240,000
SOC Lead
SOC Lead

XL Axiata • Kuala Lumpur

On-site
MYR 240,000 - 360,000
Security Delivery Consultant
Security Delivery Consultant

ABP Group • Kuala Lumpur

On-site
MYR 120,000 - 170,000
SOC Analyst L2
SOC Analyst L2

PERSOL Workforce Solutions Malaysia Sdn Bhd • Kuala Lumpur

On-site
MYR 60,000 - 100,000