Apply now »

Title:  Technical Lead Security Operations

Location: 

Kuala Lumpur, MY, MY

Global Business Unit:  OTH
Job Function:  Information Technology
Requisition Number:  246484
Description: 

About the Role

 

As a Security Operations Center (SOC) Lead, you are at the forefront of DKSH's cyber defense operations, driving the detection, response, and continuous improvement of security monitoring across regional and enterprise environments. Your leadership ensures that threats are identified and contained swiftly, protecting DKSH's digital assets, operational continuity, and business reputation.

 

What You Will Deliver

 

  • Lead day-to-day SOC operations including alert triage, incident queue management, analyst workload balancing, quality review, escalation, and reporting to ensure consistent and high-quality cyber defense outcomes.
  • Develop, maintain, and continuously improve SOC processes, runbooks, incident response playbooks, escalation matrices, and evidence handling practices that strengthen the organization's detection and response capabilities.
  • Drive proactive threat hunting using Microsoft Defender XDR, Microsoft Sentinel, Endpoint Detection and Response (EDR), Security Information and Event Management (SIEM), identity logs, endpoint telemetry, network logs, email security telemetry, and cloud activity logs.
  • Ensure monitoring use cases are aligned to enterprise threats, critical assets, privileged activity, identity risks, application exposure, and business priorities to maximize detection coverage and relevance.
  • Own SOC reporting including alert volume, true positive rate, incident trends, recurring control gaps, service levels, and remediation follow-up to provide leadership with clear and timely visibility into security posture.
  • Lead post-incident reviews and ensure lessons learned are converted into sustainable, measurable control improvements.
  • Lead and mentor SOC analysts during investigations, major incidents, and high-pressure escalations, building a team capable of responding effectively under demanding conditions.
  • Coordinate cross-functional incident responses with infrastructure, application, network, cloud, database, and country IT teams to ensure containment and resolution are timely and well-organized.
  • Communicate incident status, evidence, containment plans, and business impact clearly to both technical teams and senior management.
  • Foster a resilience-focused SOC culture that enables business operations while systematically reducing cyber risk.

 

What You Bring

 

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or equivalent practical experience. Preferred certifications include Certified Information Systems Security Professional (CISSP), GIAC Certified Incident Handler (GCIH), GIAC Certified Intrusion Analyst (GCIA), GIAC Certified Forensic Analyst (GCFA), SC-200, AZ-500, or equivalent.
  • 7 or more years of cybersecurity experience, including strong exposure to SOC operations, incident response, threat hunting, detection engineering, or security operations leadership.
  • Deep expertise in SOC operations, incident response, threat hunting, detection engineering, and alert tuning.
  • Hands-on investigation capability using Kusto Query Language (KQL) within Microsoft Sentinel, Microsoft Defender XDR, and Defender for Endpoint.
  • Strong understanding of Windows, Linux, Active Directory, Microsoft Entra ID, endpoint telemetry, network security, web applications, malware behavior, lateral movement, and credential misuse.
  • Ability to develop incident timelines, evidence summaries, containment recommendations, executive updates, and corrective action trackers.
  • Solid knowledge of MITRE ATT&CK, common incident response frameworks, and SIEM/EDR/XDR operations and evidence handling practices.

 

Why Join DKSH

At DKSH, we help companies grow in Asia and enable people to perform at their best. You will be part of an organization that values accountability, collaboration, and long-term partnerships. We offer a dynamic environment where your contributions are visible and where you can build a meaningful career in Cybersecurity.

 

 

Requisition Number:  246484
Job Function:  Information Technology

Apply now »