Technical Lead Security Operations

DKSH

Kuala Lumpur

On-site

MYR 180,000 - 300,000

Full time

25 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

DKSH in Kuala Lumpur is seeking a Security Operations Center (SOC) Lead to drive detection, response, and continuous improvement of security monitoring across regional environments. You will lead alert triage, incident handling, and reporting to protect DKSH's digital assets and operations.

You will oversee incident response playbooks, coordinate with IT teams, and mentor analysts. Proficiency with Microsoft Defender XDR, Sentinel, and KQL is essential, as is strong leadership and communication.

Qualifications

  • Bachelor's degree in Cybersecurity, IT, CS or engineering; professional certifications preferred.
  • 7+ years of cybersecurity experience with exposure to SOC operations, incident response, threat hunting, or leadership.
  • Deep expertise in SOC operations, incident response, threat hunting, and alert tuning.
  • Hands-on investigation using KQL within Microsoft Sentinel, Defender XDR, and Defender for Endpoint.
  • Strong understanding of Windows, Linux, Active Directory, Entra ID, endpoint telemetry, network security, and malware behavior.
  • Ability to develop incident timelines, evidence summaries, containment recommendations, and executive updates.
  • Knowledge of MITRE ATT&CK and SIEM/EDR/XDR workflows.

Responsibilities

  • Lead day-to-day SOC operations including alert triage, incident queue management, analyst workload balancing, quality review, escalation, and reporting.
  • Develop and maintain SOC processes, runbooks, incident response playbooks, escalation matrices, and evidence handling practices.
  • Drive proactive threat hunting using Defender XDR, Sentinel, EDR, SIEM, identity logs, endpoint telemetry, network logs, cloud activity logs.
  • Ensure monitoring use cases align to enterprise threats, critical assets, privileged activity, identity risks, application exposure, and business priorities.
  • Own SOC reporting including alert volume, true positive rate, incident trends, remediation follow-up.
  • Lead post-incident reviews and ensure lessons learned are converted into improvements.
  • Mentor SOC analysts during investigations, major incidents, and escalations.
  • Coordinate cross-functional incident responses with IT teams to ensure containment and resolution.
  • Communicate incident status and business impact to technical teams and senior management.
  • Foster a resilience-focused SOC culture.

Skills

SOC operations
Incident response
Threat hunting
Detection engineering
Security leadership
Executive communication
Incident timelines

Education

Bachelor's degree in Cybersecurity/IT/CS/Engineering
CISSP
GIAC GCIH
GIAC GCIA
GIAC GCFA
SC-200
AZ-500

Tools

KQL
Microsoft Sentinel
Microsoft Defender XDR
Defender for Endpoint
SIEM
Endpoint telemetry

Job description

About The Role

As a Security Operations Center (SOC) Lead, you are at the forefront of DKSH's cyber defense operations, driving the detection, response, and continuous improvement of security monitoring across regional and enterprise environments. Your leadership ensures that threats are identified and contained swiftly, protecting DKSH's digital assets, operational continuity, and business reputation.


What You Will Deliver


  • Lead day-to-day SOC operations including alert triage, incident queue management, analyst workload balancing, quality review, escalation, and reporting to ensure consistent and high-quality cyber defense outcomes.

  • Develop, maintain, and continuously improve SOC processes, runbooks, incident response playbooks, escalation matrices, and evidence handling practices that strengthen the organization's detection and response capabilities.

  • Drive proactive threat hunting using Microsoft Defender XDR, Microsoft Sentinel, Endpoint Detection and Response (EDR), Security Information and Event Management (SIEM), identity logs, endpoint telemetry, network logs, email security telemetry, and cloud activity logs.

  • Ensure monitoring use cases are aligned to enterprise threats, critical assets, privileged activity, identity risks, application exposure, and business priorities to maximize detection coverage and relevance.

  • Own SOC reporting including alert volume, true positive rate, incident trends, recurring control gaps, service levels, and remediation follow-up to provide leadership with clear and timely visibility into security posture.

  • Lead post-incident reviews and ensure lessons learned are converted into sustainable, measurable control improvements.

  • Lead and mentor SOC analysts during investigations, major incidents, and high-pressure escalations, building a team capable of responding effectively under demanding conditions.

  • Coordinate cross-functional incident responses with infrastructure, application, network, cloud, database, and country IT teams to ensure containment and resolution are timely and well-organized.

  • Communicate incident status, evidence, containment plans, and business impact clearly to both technical teams and senior management.

  • Foster a resilience-focused SOC culture that enables business operations while systematically reducing cyber risk.


What You Bring


  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or equivalent practical experience. Preferred certifications include Certified Information Systems Security Professional (CISSP), GIAC Certified Incident Handler (GCIH), GIAC Certified Intrusion Analyst (GCIA), GIAC Certified Forensic Analyst (GCFA), SC-200, AZ-500, or equivalent.

  • 7 or more years of cybersecurity experience, including strong exposure to SOC operations, incident response, threat hunting, detection engineering, or security operations leadership.

  • Deep expertise in SOC operations, incident response, threat hunting, detection engineering, and alert tuning.

  • Hands-on investigation capability using Kusto Query Language (KQL) within Microsoft Sentinel, Microsoft Defender XDR, and Defender for Endpoint.

  • Strong understanding of Windows, Linux, Active Directory, Microsoft Entra ID, endpoint telemetry, network security, web applications, malware behavior, lateral movement, and credential misuse.

  • Ability to develop incident timelines, evidence summaries, containment recommendations, executive updates, and corrective action trackers.

  • Solid knowledge of MITRE ATT&CK, common incident response frameworks, and SIEM/EDR/XDR operations and evidence handling practices.


Why Join DKSH

At DKSH, we help companies grow in Asia and enable people to perform at their best. You will be part of an organization that values accountability, collaboration, and long-term partnerships. We offer a dynamic environment where your contributions are visible and where you can build a meaningful career in Cybersecurity.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Technical Lead Security Operations
Technical Lead Security Operations

DKSH Group • Kuala Lumpur

On-site
MYR 180,000 - 240,000
Security Operations Lead: Threat Detection & Response
Security Operations Lead: Threat Detection & Response

DKSH • Kuala Lumpur

On-site
MYR 180,000 - 300,000
Senior SOC Lead: Threat Hunting & Incident Response
Senior SOC Lead: Threat Hunting & Incident Response

DKSH Group • Kuala Lumpur

On-site
MYR 180,000 - 240,000
Senior Specialist Application Security Engineer
Senior Specialist Application Security Engineer

DKSH • Kuala Lumpur

On-site
MYR 140,000 - 240,000
Security Operations Center Lead
Security Operations Center Lead

Altera • Bayan Lepas

On-site
MYR 180,000 - 280,000
Security Operations Center Lead
Security Operations Center Lead

Altera Corporation • Malaysia

On-site
MYR 180,000 - 300,000
Security Analyst (Intelligence - Operations)
Security Analyst (Intelligence - Operations)

GXS Bank • Selangor

On-site
MYR 90,000 - 130,000
Senior SOC Analyst
Senior SOC Analyst

Pride Global • Selangor

On-site
MYR 120,000 - 180,000
Senior Security Analyst
Senior Security Analyst

Logicalis • Kuala Lumpur

On-site
MYR 180,000 - 300,000
Senior Specialist Application Security Engineer
Senior Specialist Application Security Engineer

DKSH Group • Kuala Lumpur

On-site
MYR 120,000 - 160,000