CareerPlanSign in

Security Operations Center Lead

Penang 15, Penang, Malaysia💼 Full-time🗓 2026-08-11 → 2026-09-26

Core

Lead global SOC operations including monitoring, alert triage, incident response coordination, and process maturity across multiple time zones.

Role type

Senior IC Security Operations Center Lead

Builds

Production security monitoring, detection use cases, incident response playbooks, and SOC performance metrics

Domain

Cybersecurity / Security Operations

Deliverable

production ML models | product features | dashboards & analysis | client delivery | infrastructure

Required skills

SOC operations leadership, incident response coordination, SIEM/SOAR/EDR/XDR management, detection engineering, threat intelligence integration, security metrics analysis, regulatory compliance alignment

Preferred skills

Global SOC transformation, Incident Commander experience, Microsoft Sentinel/Defender XDR/KQL/UEBA, cloud security monitoring (Azure/AWS/GCP), threat hunting, purple-team collaboration, managed security provider management, GenAI-assisted SOC workflows

Technologies

SIEM, SOAR, EDR/XDR, Microsoft Sentinel, Microsoft Defender XDR, KQL, UEBA, Azure, AWS, GCP

Responsibilities

Lead daily SOC operations across monitoring, alert triage, investigation, escalation, and incident response coordination; Own and mature SOC operating procedures including incident intake, severity classification, escalation paths, response playbooks, and post-incident reviews; Build, tune, and continuously improve detection use cases aligned to enterprise risks and MITRE ATT&CK techniques; Partner with security engineering teams to improve log onboarding, data quality, telemetry coverage, alert fidelity, automation, and response integrations; Lead incident response coordination for security events involving endpoint compromise, identity misuse, phishing, malware, data loss indicators, cloud misconfigurations, and unauthorized access attempts; Establish SOC performance metrics and reporting including alert volumes, false-positive rates, SLA adherence, mean time to detect/acknowledge/contain, and incident trends; Oversee SOC analyst workflows, shift handoffs, case documentation, evidence handling, and quality assurance reviews; Coordinate with managed security service providers, internal IT teams, and business stakeholders to ensure timely response and clear ownership of remediation actions; Support implementation and operationalization of SOAR playbooks, automation workflows, enrichment logic, and incident response runbooks; Drive continuous improvement through tabletop exercises, incident retrospectives, purple-team findings, threat hunting outputs, and lessons learned; Maintain alignment with security governance, regulatory, privacy, and audit requirements by ensuring SOC processes are documented, repeatable, measurable, and evidence-ready

Seniority

Senior, hands-on IC with leadership responsibilities

Sourced via workday · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.