Senior Incident Response Specialist, Cyber Security-Malaysia

Posted One Month Ago
Be an Early Applicant
Kuala Lumpur, Wilayah Persekutuan Kuala Lumpur, MYS
In-Office
Senior level
Artificial Intelligence • HR Tech • Information Technology • Professional Services
The Role
Serve as L2 incident responder in the SOC: triage, investigate, contain, and close security incidents. Tune detections in Elastic Stack SIEM, perform log correlation, threat hunting, malware/phishing/cloud investigations, onboard log sources, document incidents, collaborate with MSSP/CSIRT/IT, and support automation and post-incident improvements.
Summary Generated by Built In

Role Mission

The Senior Analyst - Cyber Security Incident Response is responsible for monitoring, detecting, and analyzing cybersecurity incidents through the Security Operations Centre (SOC) platform. The role supports the end-to-end incident lifecycle — including triage, investigation, containment, and closure — ensuring timely response to security events and maintaining cyber resilience. This role acts as the Level 2 (L2) Incident Responder, bridging SOC analysts and Incident Response management by performing deep technical analysis and coordinating with internal teams for resolution.

Accountabilities:

  • Perform end-to-end incident triage and investigation of security alerts escalated from L1 SOC analysts.

  • Ensure timely incident analysis, containment, and escalation aligned with MTTD and MTTR goals.

  • Support the SIEM platform (Elastic Stack) by fine-tuning existing rules and suggesting new detections.

  • Conduct log analysis and correlation across multiple data sources (network, endpoint, and cloud).

  • Create and maintain incident documentation, reports, and lessons learned.

  • Support incident response playbook execution during containment and recovery phases.

  • Collaborate with IT, network, and application teams for incident remediation and root cause analysis.

  • Provide insights for use case improvements and participate in use case validation and testing.

  • Escalate confirmed incidents to CSIRT / Assistant Manager - Incident Response for further action.

  • Participate in post-incident reviews, contributing to process and detection improvements.

  • Monitor alerts generated from the SOC/SIEM and perform initial to intermediate-level investigations.

  • Review and validate security events from multiple log sources and identify legitimate threats.

  • Perform deep-dive investigations for incidents involving malware, phishing, insider threats, and cloud breaches.

  • Assist in detection rule creation and tuning under the guidance of senior incident responders.

  • Use frameworks like MITRE ATT&CK for mapping and improving detection quality.

  • Conduct threat hunting using Elastic Stack and related tools.

  • Collaborate with MSSP, CSIRT, and IT infrastructure teams to ensure timely incident handling.

  • Support incident response reporting, evidence collection, and documentation for compliance and audit.

  • Contribute to automation opportunities in detection and response workflows.

  • Participate in training sessions, simulations, and tabletop exercises to enhance readiness.

  • Responsible for the log source onboarding and managing the continuous logs availability on the SIEM platform.

Requirements

  • Monitor alerts generated from the SOC/SIEM and perform initial to intermediate-level investigations.

  • Review and validate security events from multiple log sources and identify legitimate threats.

  • Perform deep-dive investigations for incidents involving malware, phishing, insider threats, and cloud breaches.

  • Assist in detection rule creation and tuning under the guidance of senior incident responders.

  • Use frameworks like MITRE ATT&CK for mapping and improving detection quality.

  • Conduct threat hunting using Elastic Stack and related tools.

  • Collaborate with MSSP, CSIRT, and IT infrastructure teams to ensure timely incident handling.

  • Support incident response reporting, evidence collection, and documentation for compliance and audit.

  • Contribute to automation opportunities in detection and response workflows.

  • Participate in training sessions, simulations, and tabletop exercises to enhance readiness.

  • Responsible for the log source onboarding and managing the continuous logs availability on the SIEM platform.
    #LI-KI1

Skills Required

  • Monitor SOC/SIEM alerts and perform initial to intermediate-level investigations
  • Review and validate security events from multiple log sources and identify legitimate threats
  • Perform deep-dive investigations for incidents involving malware, phishing, insider threats, and cloud breaches
  • Assist in detection rule creation and tuning under guidance of senior responders
  • Use frameworks like MITRE ATT&CK for mapping and improving detection quality
  • Conduct threat hunting using Elastic Stack and related tools
  • Collaborate with MSSP, CSIRT, and IT infrastructure teams for incident handling and remediation
  • Support incident response reporting, evidence collection, and documentation for compliance and audit
  • Contribute to automation opportunities in detection and response workflows
  • Participate in training sessions, simulations, and tabletop exercises to enhance readiness
  • Responsible for log source onboarding and managing continuous log availability on the SIEM platform
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Singapore
31 Employees
Year Founded: 2023

What We Do

Cygnify offers Talent Acquisition as a Service (TAaaS), providing a fully-managed team of experts, AI tools, and a candidate database on a flexible, month-to-month subscription model.

Similar Jobs

Wise Logo Wise

FinCrime Operations Senior Lead - AML Investigations

Fintech • Mobile • Payments • Software • Financial Services
Hybrid
Kuala Lumpur, Wilayah Persekutuan Kuala Lumpur, MYS
9000 Employees

Hewlett Packard Enterprise Logo Hewlett Packard Enterprise

Tech Arch - Storage Channel Presales

Artificial Intelligence • Cloud • Information Technology • Consulting
Hybrid
Kuala Lumpur, Wilayah Persekutuan Kuala Lumpur, MYS
85422 Employees

Pfizer Logo Pfizer

Brand Manager

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
In-Office
Kuala Lumpur, Wilayah Persekutuan Kuala Lumpur, MYS
121990 Employees
In-Office or Remote
2 Locations
121228 Employees

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees
Vega Thumbnail
Artificial Intelligence • Automotive • Insurance • Transportation
US
43 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account