- Work model
- Office
- Experience
- 5+ years
- Employment
- Not specified
- Compensation
- Not disclosed
- Technology signal
- 6 tags
Technology context
6Parsed from the vacancy text; ordered by relevance to this role.
CloudCloud SecuritySoCThreat IntelligenceMicrosoft SentinelSecurity Incident Response
Full listing
Role description
We are seeking a Cyber Security Operations Lead . You will own detection and incident response in a regulated hedge fund environment, partnering with an outsourced SOC/MDR while tuning Microsoft Sentinel and Microsoft Defender. Based in Malaysia, you will support Singapore and regional offices with hands-on threat hunting, reporting and continuous control improvements.
Responsibilities
- Own and enhance Microsoft Sentinel detection content including analytics rules, workbooks, Kusto Query Language (KQL) and threat-hunting workflows
- Govern the outsourced SOC/MDR provider including onboarding, service reviews, escalation quality and service level agreement (SLA) performance
- Maintain security logging coverage across endpoint, identity, network and cloud environments
- Triage SOC escalations, assess severity, coordinate containment and drive incident communications
- Lead critical incident response through detection, containment, eradication, recovery and closure
- Oversee vulnerability scanning, remediation tracking, patch SLA compliance and cloud security posture improvements
- Deliver security operations reporting including key risk indicators (KRIs), key performance indicators (KPIs), mean time to detect (MTTD), mean time to respond (MTTR) and vendor performance
- Coach the Security Operations Analyst while maintaining runbooks, escalation paths, playbooks and audit-ready documentation
Requirements
- Proven experience in security operations, security operations center (SOC) leadership, detection engineering or incident response
- Hands-on expertise with Microsoft Sentinel including analytics rules, workbooks, Kusto Query Language (KQL), threat hunting and detection tuning
- Strong background with Microsoft Defender, especially Microsoft Defender for Endpoint and Microsoft Defender for Cloud
- Demonstrated ability to manage or partner with an outsourced SOC/MDR provider including SLA governance and escalation management
- Working knowledge of incident triage, response coordination, post-incident reviews and detection improvement
- Practical understanding of vulnerability management, patch governance, threat intelligence and cloud security posture management (CSPM)
- Ability to collaborate with security architecture, engineering and project delivery teams to improve detection and response outcomes
- Clear communication with confidence translating technical metrics into business-relevant reporting for senior leaders
Nice to have
- Experience working in regulated financial services such as asset management, investment management or hedge funds
- Microsoft certifications such as SC-200 or AZ-500 or industry certifications such as GCIA, GCIH or CISSP
- Experience integrating threat intelligence feeds and indicators of compromise (IOCs) into detection workflows