4 months ago
Kuala Lumpur, MalaysiaMid Level

Responsibilities

  • Develop, customize, and maintain SIEM monitoring content including rules, alerts, correlation searches, and dashboards.
  • Build SOAR automation playbooks for incident response.
  • Integrate data sources into SIEM platforms and manage parsing, normalization, and enrichment.
  • Create and maintain scripts and tools for threat detection, investigation, and reporting.
  • Collaborate with SOC Analysts and Threat Hunters to develop and improve detection use cases.
  • Develop detection logic based on threat intelligence and attack techniques such as MITRE ATT&CK.
  • Collaborate with infrastructure and application teams to improve logging and telemetry.
  • Maintain documentation for code, detection logic, use-case coverage, and automation workflows.

Requirements

  • Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or a related field.
  • Strong experience with SIEM technologies such as Splunk, QRadar, or ELK.
  • Experience with SOAR platforms such as Cortex XSOAR, Splunk Phantom, or IBM Resilient.
  • Proficiency in Python, JavaScript, or Bash.
  • Familiarity with REST APIs, JSON, and integration methods.
  • Understanding of cybersecurity concepts, attack techniques, and defensive strategies.
  • Familiarity with MITRE ATT&CK, cyber threat intelligence, and incident-handling workflows.
  • GIAC GMON, GCDA, GCIA, or equivalent certification is advantageous.

Tech Stack

Categories

Contact me