Resident Engineer – Cybersecurity
Indexed description
Senior Threat Detection & SOAR Engineer
(Cybersecurity Resident Engineer)
Location: Malaysia
Employment Type: 12-month Renewable Employment Term
About the Role
We are seeking a hands-on Senior Threat Detection & SOAR Engineer to strengthen an enterprise customer’s threat-detection and automated-response capabilities.
The role will focus on developing and tuning SIEM detection rules, building SOAR playbooks, improving MITRE ATT&CK coverage and integrating security workflows with case-management and ticketing platforms.
The successful candidate should be technically hands-on and comfortable working directly with security operations, threat intelligence and incident-response teams.
Key Responsibilities
• Design, build, test and tune SIEM correlation rules, detection queries and alerts.
• Develop detection use cases across endpoint, network, identity, email and cloud telemetry.
• Translate threat intelligence, attacker behaviours and incident findings into actionable detection rules.
• Map detection content to the MITRE ATT&CK framework and identify coverage gaps by tactic and technique.
• Investigate false positives and improve alert accuracy, quality and operational effectiveness.
• Build and document SOAR playbooks for alert enrichment, incident creation, containment, escalation and response.
• Integrate security platforms with case-management and ticketing systems through APIs and automated workflows.
• Conduct telemetry coverage assessments to identify threats that cannot be detected because of missing, insufficient or degraded log sources.
• Maintain detection content using proper lifecycle management, documentation, quality review, version control and retirement processes.
• Work with the customer’s security team to define, prioritise and deliver the approved detection use-case backlog.
• Review existing automation and playbooks supporting the China environment and develop enhancements aligned with the organisation’s global security standards.
• Support the evaluation and development of AI-assisted security automation, including an AI agent capable of drafting detection rules from threat-intelligence inputs.
• Mentor the customer’s security team and transfer the knowledge required for independent operation after the engagement.
Required Experience and Skills
• At least five years of relevant cybersecurity experience, including hands-on exposure to SOC operations, detection engineering, threat hunting or incident response.
• Proven experience developing SIEM correlation rules, queries, dashboards or detection use cases.
• Hands-on experience with at least one enterprise SIEM platform, such as Microsoft Sentinel, Splunk, IBM QRadar, Google Security Operations, Elastic Security or a similar platform.
• Experience building SOAR playbooks, automated response workflows or security-platform integrations.
• Good understanding of MITRE ATT&CK, attacker techniques, threat intelligence and detection-use-case development.
• Experience analysing telemetry from endpoint, network, identity, email and cloud-security platforms.
• Scripting or automation experience using Python, PowerShell, REST APIs or similar technologies.
• Understanding of false-positive management, detection tuning, log quality and detection coverage gaps.
• Strong documentation, communication and stakeholder-management abilities.
Advantageous Experience
• Detection-as-code practices using Git, code review and automated testing.
• Integration with ServiceNow, Jira or other case-management and ticketing platforms.
• Experience supporting security operations within China or other complex regional environments.
• Experience with AI agents, large language models or AI-assisted cybersecurity automation.
• Relevant certifications in cybersecurity, SIEM, cloud security, incident response or threat detection.
Candidate Profile
This position is suitable for a detection engineer, SIEM engineer, SOAR engineer, threat hunter or senior SOC engineer who has progressed beyond alert monitoring and has hands-on experience building and improving detection and response capabilities.
Interested candidates may apply with an updated CV stating their current salary, expected salary, notice period and work-authorisation status.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search