Technical Lead Security Operations

DKSH Management Ltd.

Kuala Lumpur

On-site

MYR 180,000 - 240,000

Full time

18 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

DKSH Management Ltd. in Kuala Lumpur is seeking a Technical Lead Security Operations to drive the SOC across regional environments, advancing detection and response aligned with business priorities.

You will mentor analysts, develop runbooks and playbooks, and coordinate cross-functional incident responses. Proficiency with Defender XDR, Sentinel, and MITRE ATT&CK is essential.

Qualifications

  • Bachelor's degree or equivalent practical experience in cybersecurity/IT/CS/engineering.

Responsibilities

  • Lead day-to-day SOC operations including alert triage, incident queue management, analyst workload balancing, quality review, escalation, and reporting.
  • Develop, maintain, and improve SOC processes, runbooks, incident response playbooks, escalation matrices, and evidence handling practices.
  • Drive proactive threat hunting using Defender XDR, Sentinel, EDR, SIEM, identity logs, and cloud/endpoi​nt telemetry.
  • Ensure monitoring use cases align with enterprise threats, critical assets, privileged activity, identity risks, and business priorities.
  • Own SOC reporting including alert volume, true positives, incident trends, and remediation follow-up.
  • Lead post-incident reviews and convert lessons learned into measurable control improvements.
  • Mentor SOC analysts during investigations and high-pressure escalations.
  • Coordinate cross-functional incident responses with infrastructure, application, network, cloud, and country IT teams.
  • Communicate incident status and containment plans to technical teams and senior management.

Skills

SOC operations
Incident response
Threat hunting
KQL
MITRE ATT&CK
Leadership

Education

Bachelor's degree in Cybersecurity/IT/CS/Engineering

Tools

Microsoft Sentinel
Microsoft Defender XDR
Defender for Endpoint
Kusto Query Language (KQL)

Job description

Select how often (in days) to receive an alert:

Title: Technical Lead Security Operations

Location: Kuala Lumpur, MY, MY

Global Business Unit: OTH

Job Function: Information Technology

Requisition Number: 246484

Description:

About the Role

As a Security Operations Center (SOC) Lead, you are at the forefront of DKSH's cyber defense operations, driving the detection, response, and continuous improvement of security monitoring across regional and enterprise environments. Your leadership ensures that threats are identified and contained swiftly, protecting DKSH's digital assets, operational continuity, and business reputation.

What You Will Deliver
  • Lead day-to-day SOC operations including alert triage, incident queue management, analyst workload balancing, quality review, escalation, and reporting to ensure consistent and high-quality cyber defense outcomes.
  • Develop, maintain, and continuously improve SOC processes, runbooks, incident response playbooks, escalation matrices, and evidence handling practices that strengthen the organization's detection and response capabilities.
  • Drive proactive threat hunting using Microsoft Defender XDR, Microsoft Sentinel, Endpoint Detection and Response (EDR), Security Information and Event Management (SIEM), identity logs, endpoint telemetry, network logs, email security telemetry, and cloud activity logs.
  • Ensure monitoring use cases are aligned to enterprise threats, critical assets, privileged activity, identity risks, application exposure, and business priorities to maximize detection coverage and relevance.
  • Own SOC reporting including alert volume, true positive rate, incident trends, recurring control gaps, service levels, and remediation follow-up to provide leadership with clear and timely visibility into security posture.
  • Lead post-incident reviews and ensure lessons learned are converted into sustainable, measurable control improvements.
  • Lead and mentor SOC analysts during investigations, major incidents, and high-pressure escalations, building a team capable of responding effectively under demanding conditions.
  • Coordinate cross-functional incident responses with infrastructure, application, network, cloud, database, and country IT teams to ensure containment and resolution are timely and well-organized.
  • Communicate incident status, evidence, containment plans, and business impact clearly to both technical teams and senior management.
  • Foster a resilience-focused SOC culture that enables business operations while systematically reducing cyber risk.
What You Bring
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or equivalent practical experience. Preferred certifications include Certified Information Systems Security Professional (CISSP), GIAC Certified Incident Handler (GCIH), GIAC Certified Intrusion Analyst (GCIA), GIAC Certified Forensic Analyst (GCFA), SC-200, AZ-500, or equivalent.
  • 7 or more years of cybersecurity experience, including strong exposure to SOC operations, incident response, threat hunting, detection engineering, or security operations leadership.
  • Deep expertise in SOC operations, incident response, threat hunting, detection engineering, and alert tuning.
  • Hands-on investigation capability using Kusto Query Language (KQL) within Microsoft Sentinel, Microsoft Defender XDR, and Defender for Endpoint.
  • Strong understanding of Windows, Linux, Active Directory, Microsoft Entra ID, endpoint telemetry, network security, web applications, malware behavior, lateral movement, and credential misuse.
  • Ability to develop incident timelines, evidence summaries, containment recommendations, executive updates, and corrective action trackers.
  • Solid knowledge of MITRE ATT&CK, common incident response frameworks, and SIEM/EDR/XDR operations and evidence handling practices.
Why Join DKSH

At DKSH, we help companies grow in Asia and enable people to perform at their best. You will be part of an organization that values accountability, collaboration, and long-term partnerships. We offer a dynamic environment where your contributions are visible and where you can build a meaningful career in Cybersecurity.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Technical Lead Security Operations
Technical Lead Security Operations

DKSH • Kuala Lumpur

On-site
MYR 180,000 - 300,000
Security Operations Lead: Threat Detection & Response
Security Operations Lead: Threat Detection & Response

DKSH • Kuala Lumpur

On-site
MYR 180,000 - 300,000
Security Operations Center Lead
Security Operations Center Lead

Altera • Bayan Lepas

On-site
MYR 180,000 - 280,000
Senior Specialist Application Security Engineer
Senior Specialist Application Security Engineer

DKSH Management Ltd. • Kuala Lumpur

On-site
MYR 150,000 - 210,000
Senior Cyber Security Consultant (SOC) Cyber security Kuala Lumpur
Senior Cyber Security Consultant (SOC) Cyber security Kuala Lumpur

S-RM Intelligence and Risk Consulting • Kuala Lumpur

Hybrid
MYR 120,000 - 180,000
Staff Cybersecurity & OT Security Engineer
Staff Cybersecurity & OT Security Engineer

Oxydata Software Sdn Bhd • Penang

On-site
MYR 180,000 - 240,000
Security Operations Center Lead
Security Operations Center Lead

Altera Corporation • Malaysia

On-site
MYR 180,000 - 300,000
SOC Team Lead
SOC Team Lead

Hytech • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Public transit access
Corporate insurance (dental, optical)
Gym and fitness claims
+2
SOC Team Lead
SOC Team Lead

Hytech Consulting Management Sdn Bhd • Kuala Lumpur

On-site
MYR 180,000 - 300,000
Public transportation access
Corporate insurance coverage (dental,光
Gym and fitness claims
+1
SOC Analyst
SOC Analyst

Oxydata Software Sdn Bhd • Kuala Lumpur

On-site
MYR 67,000 - 95,000
CompTIA Security+
CySA+
CEH
+2