SOC Specialist

Atos

Cyberjaya

On-site

MYR 140,000 - 210,000

Full time

4 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Atos in Cyberjaya, Malaysia seeks an experienced SOC Specialist to lead advanced investigations, threat hunting, and detection engineering. You will mentor junior analysts, tune detection rules, and coordinate incident response across security teams.

The role requires hands-on expertise with SIEM/EDR, MITRE ATT&CK, and threat intelligence, delivering detailed reports and improving SOC capabilities within a demanding enterprise environment.

Qualifications

  • 5–7+ years in SOC or cybersecurity
  • Experience in L2/L3 monitoring and escalation
  • Experience handling high-severity incidents in enterprise SOC
  • Strong hands-on with Microsoft Sentinel or equivalent SIEM
  • Strong XDR/EDR platform experience (Defender, etc.)
  • Strong KQL knowledge for data correlation
  • Excellent incident documentation and reporting
  • Able to communicate complex findings to stakeholders

Responsibilities

  • Perform advanced investigations of complex security incidents.
  • Analyze events across SIEM, EDR/XDR, identity, network, cloud, and logs.
  • Correlate data to establish attack timeline and scope.
  • Investigate malicious PowerShell activity, persistence, and data exfiltration.
  • Conduct proactive threat hunting using indicators and intel.
  • Map activities to MITRE ATT&CK techniques.
  • Validate threat-indicators and relevance to environment.
  • Review and tune SIEM analytics and alert thresholds.
  • Identify detection gaps and improve use cases.
  • Support major incident response and root-cause analyses.
  • Mentor L1/L2 SOC analysts and provide guidance.
  • Coordinate remediation with cross-functional teams.
  • Prepare detailed investigation reports for management and customers.
  • Maintain playbooks and knowledge articles.

Skills

Threat hunting
Incident investigation
MITRE ATT&CK
KQL
Threat intelligence

Education

GCFA or GCIA
Microsoft SC-200
CISSP
CompTIA Security+ or CEH

Tools

Microsoft Sentinel
Defender for Endpoint/XDR
Splunk
QRadar
Palo Alto

Job description

The SOC Specialist is a technical security resource responsible for advanced monitoring, complex incident investigation, threat detection, threat hunting, detection-engineering support, and technical escalation. The role provides specialist-level expertise to SOC analysts and supports the continuous improvement of SOC detection and response capabilities.

Key Responsibilities
  • Perform advanced investigations of complex, high-risk, and escalated security incidents.
  • Analyze events across SIEM, EDR/XDR, identity, network, email, cloud, firewall, proxy, application, and related security logs.
  • Correlate multiple data sources to establish the attack timeline, entry point, affected assets, user impact, and overall scope.
  • Investigate suspicious processes, PowerShell activity, scripts, persistence, credential abuse, lateral movement, privilege escalation, and data exfiltration.
  • Conduct proactive threat hunting using indicators of compromise, tactics, techniques and procedures, behavioral indicators, hypotheses, and threat intelligence.
  • Map observed activities to MITRE ATT&CK techniques and identify attack progression.
  • Validate threat-intelligence indicators and assess their relevance to the environment.
  • Review and tune SIEM analytics, detection logic, correlation rules, and alert thresholds.
  • Identify detection gaps, recommend new security use cases, and reduce recurring alerts and false positives.
  • Support major incident response, containment, eradication, recovery, and root-cause analysis activities.
  • Provide technical guidance and mentoring to L1 and L2 SOC analysts.
  • Support alert drills, tabletop exercises, threat simulations, and incident-response testing.
  • Coordinate remediation with infrastructure, endpoint, network, identity, cloud, application, and security teams.
  • Prepare detailed technical investigation reports and present findings to SOC management and customers.
  • Maintain investigation procedures, playbooks, hunting documentation, and technical knowledge articles.
Required Experience and Qualifications
  • 5–7+ years of hands-on SOC or cybersecurity experience.
  • Proven experience in L2/L3 security monitoring, incident investigation, and technical escalation.
  • Experience handling critical and high-severity incidents in an enterprise SOC, MDR, or MSSP environment.
  • Strong hands-on experience with Microsoft Sentinel or an equivalent enterprise SIEM.
  • Strong hands-on experience with Microsoft Defender XDR, Defender for Endpoint, or an equivalent EDR/XDR platform.
  • Strong KQL knowledge, with the ability to independently query and correlate security data.
  • Strong knowledge of incident response, threat hunting, threat intelligence, MITRE ATT&CK, IOC/TTP analysis, endpoint investigation, identity and authentication attacks, network security analysis, email and phishing investigation, malware and ransomware investigation, PowerShell and command-line analysis, lateral movement, privilege escalation, persistence mechanisms, and data exfiltration.
  • Strong technical documentation and report-writing skills.
  • Ability to communicate complex security findings to technical and non-technical stakeholders.
  • Ability to challenge investigation findings, provide technical recommendations, mentor junior analysts, and improve investigation quality.
Independent Investigation Capabilities
  • Build an end-to-end attack timeline.
  • Identify the initial access vector and affected entities.
  • Determine whether an alert is a true positive or false positive.
  • Identify related users, devices, IP addresses, domains, hashes, processes, and accounts.
  • Determine the incident scope and potential business impact.
  • Recommend containment and remediation actions.
  • Identify detection gaps following an incident.
Preferred Experience and Knowledge
  • Experience with Defender for Identity, Defender for Cloud, Microsoft Entra ID, Microsoft Purview, and Intune.
  • Experience with SOAR, Logic Apps, playbooks, and security automation.
  • Experience with Trellix, Palo Alto, Splunk, QRadar, or ArcSight.
  • Knowledge of UEBA and behavioral analytics.
  • Experience with Google Threat Intelligence or other threat-intelligence platforms.
  • Knowledge of malware analysis and digital forensics.
  • Experience developing Microsoft Sentinel analytics rules and advanced hunting queries.
  • Knowledge of Azure, AWS, or Google Cloud security.
  • Experience in SIEM/EDR migration or SOC transformation projects.
Preferred Certifications
  • GCFA or GCIA
  • Microsoft Certified: Security Operations Analyst Associate (SC-200)
  • CISSP
  • CompTIA Security+ or CEH
Key Performance Indicators
  • Accurate and timely resolution of complex security incidents.
  • Quality of advanced investigations and incident documentation.
  • Effective threat hunting and identification of previously unknown threats.
  • Reduction in missed detections and false positives.
  • Improvement in detection and use-case coverage.Timely technical escalation and remediation.
  • Quality of root-cause analyses and corrective-action recommendations.
  • Effective technical mentoring of SOC analysts.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SOC Specialist
SOC Specialist

Pride Global • Selangor

On-site
MYR 140,000 - 230,000
SOC Specialist
SOC Specialist

Pride Global • Cyberjaya

On-site
MYR 120,000 - 180,000
Senior SOC Analyst
Senior SOC Analyst

Pride Global • Selangor

On-site
MYR 120,000 - 180,000
Security Analyst (Intelligence & Operations)
Security Analyst (Intelligence & Operations)

GXS Bank • Petaling Jaya

On-site
MYR 90,000 - 150,000
Service Manager SIEM/SOC
Service Manager SIEM/SOC

Pride Global • Selangor

On-site
MYR 180,000 - 300,000
L2 SOC Analyst
L2 SOC Analyst

Pride Global • Selangor

On-site
MYR 60,000 - 110,000
SOC Lead
SOC Lead

Axonect • Kuala Lumpur

On-site
MYR 180,000 - 240,000
Security Delivery Consultant
Security Delivery Consultant

ABP Group • Kuala Lumpur

On-site
MYR 120,000 - 170,000
SOC Analyst L2
SOC Analyst L2

PERSOL Workforce Solutions Malaysia Sdn Bhd • Kuala Lumpur

On-site
MYR 60,000 - 100,000
L2 SOC Analyst / Engineer
L2 SOC Analyst / Engineer

Insyghts Security Sdn Bhd • Iskandar Puteri

On-site
MYR 60,000 - 100,000