Technical Lead Security Operations

DKSH Group

Kuala Lumpur

On-site

MYR 180,000 - 240,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

DKSH is seeking a Technical Lead Security Operations in Kuala Lumpur to drive security monitoring, threat detection, and incident response across regional environments. You will lead SOC operations, develop runbooks, and mentor analysts while coordinating cross-functional responses to incidents.

The role requires strong expertise in SOC, incident response, threat hunting, and evidence handling, plus hands-on use of KQL with Microsoft Sentinel and Defender XDR.

Qualifications

  • Bachelor's degree in Cybersecurity, IT, CS, or Engineering or equivalent experience.
  • 7+ years in cybersecurity with SOC, IR, threat hunting, or leadership.
  • Hands-on with KQL in Sentinel and XDR environments.

Responsibilities

  • Lead day-to-day SOC operations, triage alerts, manage incidents, and report outcomes.
  • Develop and improve SOC runbooks, playbooks, and evidence handling.
  • Drive proactive threat hunting across MS Defender XDR, Sentinel, and SIEM.
  • Coordinate cross-functional incident response with IT, network, and cloud teams.

Skills

SOC leadership
Incident response
Threat hunting
Detection engineering
Alert tuning
KQL
MITRE ATT&CK

Education

Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or equivalent practical experience

Tools

Microsoft Defender XDR
Microsoft Sentinel
Defender for Endpoint

Job description

Title: Technical Lead Security Operations

Location: Kuala Lumpur, MY, MY

Global Business Unit: OTH

Job Function: Information Technology

Requisition Number: 246484

About the Role

As a Security Operations Center (SOC) Lead, you are at the forefront of DKSH's cyber defense operations, driving the detection, response, and continuous improvement of security monitoring across regional and enterprise environments. Your leadership ensures that threats are identified and contained swiftly, protecting DKSH's digital assets, operational continuity, and business reputation.

What You Will Deliver
  • Lead day-to-day SOC operations including alert triage, incident queue management, analyst workload balancing, quality review, escalation, and reporting to ensure consistent and high-quality cyber defense outcomes.
  • Develop, maintain, and continuously improve SOC processes, runbooks, incident response playbooks, escalation matrices, and evidence handling practices that strengthen the organization's detection and response capabilities.
  • Drive proactive threat hunting using Microsoft Defender XDR, Microsoft Sentinel, Endpoint Detection and Response (EDR), Security Information and Event Management (SIEM), identity logs, endpoint telemetry, network logs, email security telemetry, and cloud activity logs.
  • Ensure monitoring use cases are aligned to enterprise threats, critical assets, privileged activity, identity risks, application exposure, and business priorities to maximize detection coverage and relevance.
  • Own SOC reporting including alert volume, true positive rate, incident trends, recurring control gaps, service levels, and remediation follow-up to provide leadership with clear and timely visibility into security posture.
  • Lead post-incident reviews and ensure lessons learned are converted into sustainable, measurable control improvements.
  • Lead and mentor SOC analysts during investigations, major incidents, and high-pressure escalations, building a team capable of responding effectively under demanding conditions.
  • Coordinate cross-functional incident responses with infrastructure, application, network, cloud, database, and country IT teams to ensure containment and resolution are timely and well-organized.
  • Communicate incident status, evidence, containment plans, and business impact clearly to both technical teams and senior management.
  • Foster a resilience-focused SOC culture that enables business operations while systematically reducing cyber risk.
What You Bring
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or equivalent practical experience. Preferred certifications include Certified Information Systems Security Professional (CISSP), GIAC Certified Incident Handler (GCIH), GIAC Certified Intrusion Analyst (GCIA), GIAC Certified Forensic Analyst (GCFA), SC-200, AZ-500, or equivalent.
  • 7 or more years of cybersecurity experience, including strong exposure to SOC operations, incident response, threat hunting, detection engineering, or security operations leadership.
  • Deep expertise in SOC operations, incident response, threat hunting, detection engineering, and alert tuning.
  • Hands-on investigation capability using Kusto Query Language (KQL) within Microsoft Sentinel, Microsoft Defender XDR, and Defender for Endpoint.
  • Strong understanding of Windows, Linux, Active Directory, Microsoft Entra ID, endpoint telemetry, network security, web applications, malware behavior, lateral movement, and credential misuse.
  • Ability to develop incident timelines, evidence summaries, containment recommendations, executive updates, and corrective action trackers.
  • Solid knowledge of MITRE ATT&CK, common incident response frameworks, and SIEM/EDR/XDR operations and evidence handling practices.
Why Join DKSH

At DKSH, we help companies grow in Asia and enable people to perform at their best. You will be part of an organization that values accountability, collaboration, and long-term partnerships. We offer a dynamic environment where your contributions are visible and where you can build a meaningful career in Cybersecurity.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Technical Lead Security Operations
Technical Lead Security Operations

DKSH • Kuala Lumpur

On-site
MYR 180,000 - 300,000
Security Operations Lead: Threat Detection & Response
Security Operations Lead: Threat Detection & Response

DKSH • Kuala Lumpur

On-site
MYR 180,000 - 300,000
Senior SOC Lead: Threat Hunting & Incident Response
Senior SOC Lead: Threat Hunting & Incident Response

DKSH Group • Kuala Lumpur

On-site
MYR 180,000 - 240,000
Security Operations Center Lead
Security Operations Center Lead

Altera • Bayan Lepas

On-site
MYR 180,000 - 280,000
Security Operations Center Lead
Security Operations Center Lead

Altera Corporation • Malaysia

On-site
MYR 180,000 - 300,000
Senior Specialist Application Security Engineer
Senior Specialist Application Security Engineer

DKSH Group • Kuala Lumpur

On-site
MYR 120,000 - 160,000
Senior Specialist Application Security Engineer
Senior Specialist Application Security Engineer

DKSH • Kuala Lumpur

On-site
MYR 140,000 - 240,000
Senior Cyber Security Consultant (SOC) Cyber security Kuala Lumpur
Senior Cyber Security Consultant (SOC) Cyber security Kuala Lumpur

S-RM Intelligence and Risk Consulting • Kuala Lumpur

Hybrid
MYR 120,000 - 180,000
Cyber Security Analyst/Support (SOC)
Cyber Security Analyst/Support (SOC)

MSP Systems • Kuala Lumpur

On-site
MYR 60,000 - 90,000
Senior SOC Consultant
Senior SOC Consultant

S-RM • Kuala Lumpur

Hybrid
MYR 180,000 - 240,000
Hybrid work model
Global collaboration