SOC Specialist

Pride Global

Kuala Lumpur

On-site

MYR 55,000 - 110,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jora Malaysia is seeking an experienced SOC Specialist to provide expert-level security monitoring, incident investigation, threat hunting, and escalation guidance. You will support major incident response, improve detection capabilities, and mentor SOC analysts across diverse environments.

Qualifications include 5–7+ years in SOC/Cybersecurity, strong SIEM experience (Microsoft Sentinel) and Defender XDR, and hands-on skills in KQL, PowerShell, and threat intelligence.

Qualifications

  • 5–7+ years of hands-on SOC/Cybersecurity experience.
  • Proven L2/L3 experience in security monitoring and incident investigation.
  • Experience handling critical/high-severity incidents and technical escalations.
  • Experience in an enterprise SOC/MDR/MSSP environment.
  • Strong hands-on experience with Microsoft Sentinel or equivalent SIEM.
  • Strong Defender XDR/Defender for Endpoint or equivalent EDR/XDR.
  • Strong KQL knowledge and ability to independently query and correlate security data.
  • Knowledge of endpoint and network investigation, email/phishing, PowerShell, lateral movement, privilege escalation, persistence, data exfiltration.
  • Strong technical documentation and communication skills.
  • Ability to mentor junior analysts and provide technical recommendations.

Responsibilities

  • Perform advanced investigation of complex, high-risk, and escalated security incidents.
  • Analyze events across SIEM, EDR/XDR, identity, network, email, cloud, firewall, proxy, and application logs.
  • Correlate multiple data sources to establish attack timelines, entry points, affected assets, and scope.
  • Investigate suspicious processes, PowerShell, persistence, credential abuse, lateral movement, privilege escalation, and data exfiltration.
  • Conduct proactive threat hunting using IOCs, TTPs, behavioral indicators, threat intelligence, and MITRE ATT&CK.
  • Validate threat intelligence indicators and assess their relevance to the environment.
  • Review and tune SIEM analytics rules, detection logic, correlation rules, and alert thresholds.
  • Identify detection gaps and recommend new security use cases.
  • Support major incident response, containment, eradication, and recovery activities.
  • Perform RCA and recommend corrective/preventive actions.
  • Provide technical guidance and mentoring to L1/L2 SOC analysts.
  • Coordinate with infrastructure, endpoint, network, identity, cloud, and application teams for remediation.
  • Prepare detailed technical investigation reports and maintain SOC playbooks and documentation.
  • Participate in tabletop exercises, threat simulations, and incident-response testing.

Skills

SOC/Cybersecurity experience
L2/L3 escalation
Microsoft Sentinel
Defender XDR
KQL
Threat hunting
Incident investigation
PowerShell

Tools

Microsoft Defender XDR
EDR/XDR tooling
Splunk
QRadar
ArcSight
Trellix

Job description

Jora Malaysia will close on 9th September 2026. Thank you for being with us, we are cheering you on as you continue your career journey.

We are seeking an experienced SOC Specialist to provide specialist-level expertise in advanced security monitoring, complex incident investigation, threat hunting, detection engineering support, and technical escalation. The role will support major incident response, improve SOC detection capabilities, and provide technical guidance to SOC analysts.

Key Responsibilities

  • Perform advanced investigation of complex, high-risk, and escalated security incidents.
  • Analyze events across SIEM, EDR/XDR, identity, network, email, cloud, firewall, proxy, and application logs.
  • Correlate multiple data sources to establish attack timelines, entry points, affected assets, and scope.
  • Investigate suspicious processes, PowerShell, persistence, credential abuse, lateral movement, privilege escalation, and data exfiltration.
  • Conduct proactive threat hunting using IOCs, TTPs, behavioral indicators, threat intelligence, and MITRE ATT&CK.
  • Validate threat intelligence indicators and assess their relevance to the environment.
  • Review and tune SIEM analytics rules, detection logic, correlation rules, and alert thresholds.
  • Identify detection gaps and recommend new security use cases.
  • Support major incident response, containment, eradication, and recovery activities.
  • Perform RCA and recommend corrective/preventive actions.
  • Provide technical guidance and mentoring to L1/L2 SOC analysts.
  • Coordinate with infrastructure, endpoint, network, identity, cloud, and application teams for remediation.
  • Prepare detailed technical investigation reports and maintain SOC playbooks and documentation.
  • Participate in tabletop exercises, threat simulations, and incident-response testing.

Requirements

  • 5–7+ years of hands-on SOC/Cybersecurity experience.
  • Proven L2/L3 experience in security monitoring and incident investigation.
  • Experience handling critical/high-severity incidents and technical escalations.
  • Experience in an enterprise SOC/MDR/MSSP environment.
  • Strong hands-on experience with Microsoft Sentinel or equivalent SIEM.
  • Strong experience with Microsoft Defender XDR/Defender for Endpoint or equivalent EDR/XDR.
  • Strong KQL knowledge and ability to independently query and correlate security data.
  • Strong knowledge of:
  • Endpoint and Network Investigation
  • Email/Phishing Investigation
  • PowerShell & Command-Line Analysis
  • Lateral Movement & Privilege Escalation
  • Persistence & Data Exfiltration
  • Ability to build end-to-end attack timelines, determine scope and impact, identify true/false positives, and recommend containment/remediation actions.
  • Strong technical documentation and communication skills.
  • Ability to mentor junior analysts and provide technical recommendations.

Preferred

  • Experience with Defender for Identity, Defender for Cloud, Entra ID, Purview, and Intune.
  • Experience with SOAR, Logic Apps, Playbooks, and security automation.
  • Experience with Trellix, Palo Alto, Splunk, QRadar, or ArcSight.
  • Knowledge of UEBA, behavioral analytics, malware analysis, and digital forensics.
  • Experience developing Sentinel analytics rules and advanced hunting queries.
  • Knowledge of Azure/AWS/GCP security.
  • Experience with SIEM/EDR migration or SOC transformation projects.
  • Familiarity with Threat Intelligence Platforms (TIP).

Preferred Certifications

  • GCFA / GCIA
  • Microsoft SC-200
  • CISSP
  • Security+ / CEH
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior SOC Analyst
Senior SOC Analyst

Pride Global • Kuala Lumpur

On-site
MYR 120,000 - 180,000
L2 SOC Analyst
L2 SOC Analyst

Pride Global • Kuala Lumpur

On-site
MYR 67,000 - 100,000
L1 - SOC Analyst
L1 - SOC Analyst

Dwell Technologies Sdn. Bhd. • Kuala Lumpur

On-site
MYR 54,000 - 90,000
Service Manager SIEM-SOC
Service Manager SIEM-SOC

Pride Global • Kuala Lumpur

On-site
MYR 180,000 - 300,000
SENIOR SOC ANALYST L2
SENIOR SOC ANALYST L2

TechLab Security • Shah Alam

On-site
MYR 120,000 - 180,000
SOC Manager
SOC Manager

Quess • Shah Alam

On-site
MYR 120,000 - 180,000
Senior SOC Analyst / SOC Engineer (L3)
Senior SOC Analyst / SOC Engineer (L3)

Jobstreet Malaysia • Klang City

On-site
MYR 120,000 - 180,000
SOC Analyst L2
SOC Analyst L2

PERSOL • Kuala Lumpur

On-site
MYR 60,000 - 90,000
Health insurance
L2 SOC Analyst / Engineer
L2 SOC Analyst / Engineer

Insyghts Security • Iskandar Puteri

On-site
MYR 120,000 - 180,000
Transfer opportunity to Singapore
Cyber Security Analyst/Support (SOC)
Cyber Security Analyst/Support (SOC)

MSP Systems • Kuala Lumpur

On-site
MYR 60,000 - 90,000