Managed Security Services Lead

PentagonPlus

Bangsar

On-site

PHP 3,385,000 - 4,615,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jora Malaysia is seeking an experienced Managed Security Services Analyst/Engineer to join our SOC team. You will manage real-time threat detection, incident response, and automated defense as part of our MSSP offerings.

You will work with Office 365, Azure, firewalls, and EDR, applying MITRE ATT&CK, tuning playbooks, and delivering rapid remediation. Collaboration across red/blue/purple teams is essential to improve detection and security posture.

Qualifications

  • 3+ years’ hands‑on experience in SOC, MSSP, or large enterprise security program
  • Bachelor’s degree in Information Security, Computer Science, or related field (or equivalent experience)
  • One or more of the following: CISSP, GIAC (e.g., GCIA/GCED), OSCP, CREST, CEH
  • Proven track record in threat detection, monitoring, and incident response
  • Familiarity with MITRE ATT&CK, NIST, and ISO/IEC 27001/27002
  • Demonstrated participation in red/blue/purple team operations and threat simulation
  • Experience with SOAR, SIEM (Splunk, QRadar, Sentinel, etc.), EDR, network security
  • Strong technical problem-solving, communication, stakeholder engagement skills

Responsibilities

  • Continuous Monitoring of live data streams, logs, events from EDR, firewalls, networks and cloud platforms
  • Incident Identification: detect and respond to threats with advanced analytics and high-fidelity alerting
  • Behavioral Analytics: monitor user/admin behaviors, privilege usage and policy violations for real-time detection
  • Automated Playbook Execution: deploy and fine-tune SOAR playbooks for rapid automated response
  • Triage and Escalation: automated triage using MITRE ATT&CK; escalate complex incidents
  • Remediation Guidance: provide actionable recommendations and coordinate with client IT teams
  • Ticketing/Workflow: log incidents in centralized systems with audit/compliance controls

Skills

Threat detection
Incident response
SOC operations
MITRE ATT&CK
Red/Blue/Purple team
SIEM

Education

Bachelor’s degree in Information Security, Computer Science, or related field

Tools

Splunk
QRadar
Sentinel
SOAR
EDR

Job description

Jora Malaysia will close on 9th September 2026. Thank you for being with us, we are cheering you on as you continue your career journey.

This position is working ina highly reliable IT vendor that provides IT Infrastructure Solutions, Cyber Security, Data Centre Design and Solutions.

We are seeking an experienced and highly motivated Managed Security Services Analyst/Engineer to join our Security Operations Center (SOC) team. As part of our Managed Security Service Provider (MSSP) offering, you will be responsible for end-to-end real-time threat detection, incident response, automated defense, and security posture improvement for our clients. This position requires the candidate to possess knowledge of Red Team (offensive testing), Blue Team (defensive operations), and Purple Team (collaborative security validation) practices.

Key Responsibilities:

  • Continuous Monitoring: Monitor live data streams, logs, events, and activities from EDR, firewalls, network devices, and cloud platforms (Office 365, Azure).
  • Incident Identification: Swiftly detect and respond to security threats using advanced analytics and high-fidelity alerting.
  • Behavioral Analytics: Actively monitor user/admin behaviors, privilege usage, and policy violations. Ensure real-time detection of unauthorized or abnormal activity.
  • Automated Playbook Execution: Deploy, manage, and fine-tune SOAR (Security Orchestration, Automation & Response) playbooks; ensure rapid, automated response to verified threats.
  • Triage and Escalation: Conduct automated triage using MITRE ATT&CK; elevate unresolved complex incidents for further analysis.
  • Remediation Guidance: Provide clear, actionable recommendations for risk mitigation and collaborate with client IT teams for formal incident handling, resolution, and review.
  • Ticketing/Workflow Systems: Log and track all incidents in centralized systems with proper audit/compliance controls; coordinate collaborative troubleshooting (e.g., Teams integration).

Security Use Case Tuning & Threat Intelligence Integration

  • Risk-Aligned Prioritization: Map and prioritize detection logic to client risk registers and threat models in alignment with frameworks such as MITRE ATT&CK.
  • Detection Logic Maintenance: Employ source validation, noise reduction, false positive optimization, and maintain documentation & version control of use cases.
  • Red/Purple Team Feedback: Incorporate threat simulation results (e.g., Atomic Red Team, CALDERA) and red/purple teaming feedback to improve efficiency and detection accuracy.
  • Metrics & KPIs: Measure and report detection outcomes, conversion rates, time to detect, and other quantitative security metrics.
  • Threat Intelligence: Integrate managed CTI feeds and conduct proactive threat hunting to inform control improvements and client recommendations.

Performance Reporting & Client Engagement

  • Monthly and Quarterly Reporting: Prepare and present technical and executive security reports, aligning content with NIST and ISO 27002 frameworks, client templates, and evolving needs.
  • Review Sessions: Lead quarterly review sessions with client IT teams to discuss findings, answer questions, and align on next steps.
  • Continuous Improvement: Proactively update and improve reporting and engagement processes as client requirements evolve.

Advanced Detection, Automation & Vendor Support

  • Firewall/Endpoint/Server Monitoring: Design and tune use cases for port scans, DDoS, malware, privilege escalation, process injection, etc.
  • Automation: Enrich, block, isolate, and disable malicious activity or accounts through automated workflows.
  • Remote Support: Provide incident response and troubleshooting, including after-hours/onsite escalation as necessary.
  • Patching & Updates: Coordinate remote firmware/software updates for managed firewall and security devices.

Red, Blue, and Purple Teaming

  • Red Team Participation: Perform or support offensive security engagements such as penetration testing, social engineering, and vulnerability assessments.
  • Blue Team Operations: Lead or assist with defensive operations including live monitoring, log analysis, SIEM/SOAR rule tuning, and incident remediation.
  • Purple Team Collaboration: Work cross-functionally to bridge detection engineering and adversary simulation, integrating red/blue teaming outcomes to continuously improve use case effectiveness and security posture.

Requirements:

  • 3+ years’ hands‑on experience in SOC, MSSP, or large enterprise security program
  • Bachelor’s degree in Information Security, Computer Science, or related field (or equivalent experience)
  • One or more of the following: CISSP, GIAC (e.g., GCIA/GCED), OSCP, CREST, CEH
  • Proven track record in threat detection, monitoring, and incident response
  • Familiarity with MITRE ATT&CK, NIST, and ISO/IEC 27001/27002
  • Demonstrated participation in red/blue/purple team operations and threat simulation
  • Experience with SOAR, SIEM (Splunk, QRadar, Sentinel, etc.), EDR, network security
  • Strong technical problem-solving, communication, stakeholder engagement skills

Preferred Attributes

  • Knowledge of network security, endpoint security, firewall platforms, and cloud (Azure, Office 365).
  • Familiarity with automated detection logic, purple/red team pipelines, and hands‑on threat hunting.
  • Ability to customize detection rules, playbooks, and handle evolving sector‑specific IOCs and threats.
  • Commitment to continuous improvement, learning, and team‑based innovation.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior MSSP Security Operations Engineer – Threat & Response
Senior MSSP Security Operations Engineer – Threat & Response

PentagonPlus • Bangsar

On-site
PHP 3,385,000 - 4,615,000
IT Security Specialist
IT Security Specialist

ibex • Mandaluyong

On-site
PHP 420,000 - 640,000
Security Analyst (Remote)
Security Analyst (Remote)

Prime System Solutions • Philippines

On-site
PHP 1,200,000 - 1,600,000
HMO coverage
Paid time off
Career development and certification
+2
IT Security Specialist
IT Security Specialist

Ibex Limited • Manila

On-site
PHP 600,000 - 900,000
Senior Security Consultant
Senior Security Consultant

Hunter's Hub Inc. • Taguig

On-site
Application Security Manager
Application Security Manager

PwC • Makati

On-site
PHP 1,200,000 - 1,600,000
SOC Manager
SOC Manager

SM Investments • Philippines

On-site
PHP 1,200,000 - 2,000,000
Senior Red Team Operator
Senior Red Team Operator

sunlife • Philippines

On-site
PHP 1,800,000 - 3,000,000
Security Operations Center (SOC) - Head
Security Operations Center (SOC) - Head

SMITS, Inc. - IT Company of San Miguel Corporation • Mandaluyong

On-site
PHP 900,000 - 1,600,000
Junior SOC Analyst
Junior SOC Analyst

Kinettix Inc. • Manila

On-site