Back to search
Millennium Technology Services Linkedin · Posted 8d ago

Resident Engineer – Cybersecurity

Federal Territory of Kuala Lumpur

Linkedin
Continue to application Add your email once, then Caio opens the original posting.

Indexed description

Senior Threat Detection & SOAR Engineer

(Cybersecurity Resident Engineer)

Location: Malaysia

Employment Type: 12-month Renewable Employment Term


About the Role

We are seeking a hands-on Senior Threat Detection & SOAR Engineer to strengthen an enterprise customer’s threat-detection and automated-response capabilities.

The role will focus on developing and tuning SIEM detection rules, building SOAR playbooks, improving MITRE ATT&CK coverage and integrating security workflows with case-management and ticketing platforms.

The successful candidate should be technically hands-on and comfortable working directly with security operations, threat intelligence and incident-response teams.


Key Responsibilities

• Design, build, test and tune SIEM correlation rules, detection queries and alerts.

• Develop detection use cases across endpoint, network, identity, email and cloud telemetry.

• Translate threat intelligence, attacker behaviours and incident findings into actionable detection rules.

• Map detection content to the MITRE ATT&CK framework and identify coverage gaps by tactic and technique.

• Investigate false positives and improve alert accuracy, quality and operational effectiveness.

• Build and document SOAR playbooks for alert enrichment, incident creation, containment, escalation and response.

• Integrate security platforms with case-management and ticketing systems through APIs and automated workflows.

• Conduct telemetry coverage assessments to identify threats that cannot be detected because of missing, insufficient or degraded log sources.

• Maintain detection content using proper lifecycle management, documentation, quality review, version control and retirement processes.

• Work with the customer’s security team to define, prioritise and deliver the approved detection use-case backlog.

• Review existing automation and playbooks supporting the China environment and develop enhancements aligned with the organisation’s global security standards.

• Support the evaluation and development of AI-assisted security automation, including an AI agent capable of drafting detection rules from threat-intelligence inputs.

• Mentor the customer’s security team and transfer the knowledge required for independent operation after the engagement.


Required Experience and Skills

• At least five years of relevant cybersecurity experience, including hands-on exposure to SOC operations, detection engineering, threat hunting or incident response.

• Proven experience developing SIEM correlation rules, queries, dashboards or detection use cases.

• Hands-on experience with at least one enterprise SIEM platform, such as Microsoft Sentinel, Splunk, IBM QRadar, Google Security Operations, Elastic Security or a similar platform.

• Experience building SOAR playbooks, automated response workflows or security-platform integrations.

• Good understanding of MITRE ATT&CK, attacker techniques, threat intelligence and detection-use-case development.

• Experience analysing telemetry from endpoint, network, identity, email and cloud-security platforms.

• Scripting or automation experience using Python, PowerShell, REST APIs or similar technologies.

• Understanding of false-positive management, detection tuning, log quality and detection coverage gaps.

• Strong documentation, communication and stakeholder-management abilities.


Advantageous Experience

• Detection-as-code practices using Git, code review and automated testing.

• Integration with ServiceNow, Jira or other case-management and ticketing platforms.

• Experience supporting security operations within China or other complex regional environments.

• Experience with AI agents, large language models or AI-assisted cybersecurity automation.

• Relevant certifications in cybersecurity, SIEM, cloud security, incident response or threat detection.


Candidate Profile

This position is suitable for a detection engineer, SIEM engineer, SOAR engineer, threat hunter or senior SOC engineer who has progressed beyond alert monitoring and has hands-on experience building and improving detection and response capabilities.

Interested candidates may apply with an updated CV stating their current salary, expected salary, notice period and work-authorisation status.

Free. 20 seconds. No password. See every match in this search.

Create a free Caio profile to unlock more results and save your role and location preferences.

Unlock free search
Want help applying to roles like this? Search Caio for free. If repetitive applications get heavy, Managed Job Search adds supervised execution for $99/month.
View Managed Job Search