openqareer

L2 SOC Engineer -

Neuron Solutions · Sentul

# L2 SOC Engineer - **Neuron Solutions** · Sentul · `On-site` 🕒 **Статус:** *Опубликовано: сегодня* · *Источник: Indeed* --- ### About the Role Key Responsibilities - Serve as the primary Point of Contact (SPOC) for the MSSP's Tier 1 SOC team, managing SIEM (Microsoft Sentinel), CrowdStrike Falcon EDR alerts, and ITSM tickets across Malaysia and UK properties. - Investigate and respond to security incidents in line with the Cyber Incident Response (CIR) plan, ensuring timely threat containment and remediation within defined SLAs. - Lead Root Cause Analysis (RCA), prepare incident reports, and deliver weekly and monthly security updates to technical teams, stakeholders, and executives. - Monitor Entra ID and on-premises Active Directory for suspicious account activity, privilege abuse, MFA gaps, and risky sign-ins. - Coordinate vulnerability scanning, High and Critical CVE patch reviews, firewall configuration audits, and Joiner/Mover/Leaver access reviews. - Develop and maintain security policies, incident response playbooks, Disaster Recovery and Business Continuity Plans, risk registers, and risk management frameworks. - Create and fine-tune Sentinel detection rules, KQL queries, automation scripts, and threat hunting use cases. - Conduct Third Party Risk Management (TPRM) assessments and represent YTL Hotels on the Cyber Security Task Force. - Deliver cyber security awareness training, phishing simulations, and threat intelligence briefings to IT teams and users across Malaysia and the UK. Requirements - Bachelor's degree in Cyber Security, Information Technology, or a related field. - 7–9 years of experience in cyber security operations, including 3–4 years in a Tier 2 SOC, incident response, or security engineering role. Experience working with an MSSP-managed Tier 1 SOC is preferred. - Hands-on experience with Microsoft Sentinel, including KQL queries, analytics rules, log source onboarding, and detection tuning. - Strong knowledge of Microsoft 365 and Entra ID security monitoring, including MFA, Conditional Access, PIM, and risky sign-ins. - Experience with CrowdStrike Falcon EDR or comparable platforms, covering alert triage, IOC management, detection rules, and endpoint protection. - Working knowledge of Fortinet FortiGate firewalls and network security monitoring across multi-site environments. - Proven experience in incident response, threat containment, RCA, and executive-level incident reporting. - Good understanding of NIST CSF, ISO 27001, vulnerability management, compliance audits, and user access reviews. - Strong communication and stakeholder management skills, with the ability to liaise with technical teams and executive stakeholders across Malaysia and the UK. Pay: RM5,500.00 - RM7,000.00 per month Application Question(s): - Expected Salary - Notice Period Experience: - L2 SOC: 5 years (Required) - SIEM: 5 years (Required) Work Location: In person

Наблюдалась 2026-10-07, впервые 2026-10-06, источник — Indeed.

Открыть у работодателя