{"id":1246811,"url":"https://alion.io/job/altera-security-operations-center-lead-2","title":"Security Operations Center Lead","company":{"id":5328,"name":"Altera","domain":"altera.com","url":"https://alion.io/company/altera","size_band":"1001-5000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Workday","truth_index":{"grade":"A","score":95,"open_postings":19,"ghost_share":0,"stale_share":0,"repost_share":0,"time_to_fill_p50_days":84,"computed_at":"2026-09-26T05:45:00Z"}},"role":"Security","role_family":"Security","seniority":"lead","employment_type":"full_time","work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["George Town, Malaysia","Bengaluru, India"],"countries":["MY","IN"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":23000,"max_usd":60000,"period":"year","method":"global_role_cell_scaled_by_country","sample_n":330},"experience_years_min":5,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"ISO 27001","optional":false},{"name":"MITRE ATT&CK","optional":false},{"name":"NIST CSF","optional":false},{"name":"SIEM","optional":false},{"name":"SLI/SLO/SLA","optional":false},{"name":"AWS","optional":true},{"name":"Azure","optional":true},{"name":"Commander.js","optional":true},{"name":"GCP","optional":true},{"name":"JavaScript","optional":true},{"name":"Microsoft Defender","optional":true},{"name":"Microsoft Sentinel","optional":true},{"name":"Node JS","optional":true}],"status":"live","first_seen_at":"2026-09-15T00:00:00Z","employer_posted_date":"2026-09-15","last_verified_at":"2026-09-26T22:09:48Z","board_verified":true,"closed_at":null,"days_open":12,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":12},"description":"Job Details:\nJob Description:\nJob Description\nAltera is seeking an experienced and hands-on Security Operations Center Lead to lead and mature our global security monitoring, detection, incident response, and cyber defense capabilities. This role will be responsible for day-to-day SOC operations, alert triage, incident escalation, use case development, playbook execution, threat monitoring, and operational reporting across enterprise IT, cloud, identity, endpoint, network, and application environments.\nThis leader will partner closely with security engineering, infrastructure, identity, cloud, IT operations, legal, privacy, product security, and managed service providers to ensure security events are detected, investigated, contained, and remediated effectively. The ideal candidate combines strong technical security operations depth with leadership discipline, process ownership, and the ability to drive measurable improvements in detection coverage, response quality, automation, and operational resilience.\nKey Responsibilities\nLead daily SOC operations across monitoring, alert triage, investigation, escalation, incident response coordination, and operational handoff across global time zones.\nOwn and mature SOC operating procedures, including incident intake, severity classification, escalation paths, response playbooks, major incident communications, and post-incident reviews.\nManage and improve security monitoring across SIEM, SOAR, EDR/XDR, email security, cloud security, identity security, vulnerability signals, network telemetry, and threat intelligence sources.\nBuild, tune, and continuously improve detection use cases aligned to enterprise risks, MITRE ATT&CK techniques, threat intelligence, audit findings, and business-critical assets.\nPartner with security engineering teams to improve log onboarding, data quality, telemetry coverage, alert fidelity, automation, and response integrations.\nLead incident response coordination for security events involving endpoint compromise, identity misuse, phishing, malware, data loss indicators, cloud misconfigurations, suspicious network activity, and unauthorized access attempts.\nEstablish SOC performance metrics and reporting, including alert volumes, false-positive rates, SLA adherence, escalation quality, mean time to detect, mean time to acknowledge, mean time to contain, and incident trends.\nOversee SOC analyst workflows, shift handoffs, case documentation, evidence handling, and quality assurance reviews.\nCoordinate with managed security service providers, internal IT teams, and business stakeholders to ensure timely response and clear ownership of remediation actions.\nSupport implementation and operationalization of SOAR playbooks, automation workflows, enrichment logic, and incident response runbooks.\nDrive continuous improvement through tabletop exercises, incident retrospectives, purple-team findings, threat hunting outputs, and lessons learned.\nMaintain alignment with security governance, regulatory, privacy, and audit requirements by ensuring SOC processes are documented, repeatable, measurable, and evidence-ready.\nServe as a security operations lead for global SOC coverage and cross-functional collaboration.\nQualifications:\nQualifications\nMinimum Qualifications\nBachelor’s degree in Computer Science, Computer Engineering, Information Security, Cybersecurity, or a related field, or equivalent practical experience.\n5+ years of progressive cybersecurity experience, including significant hands-on experience in security operations, incident response, threat detection, or SOC leadership.\n3+ years of experience leading SOC analysts, incident response teams, managed security operations, or cross-functional cyber defense workflows.\nStrong working knowledge of SIEM, SOAR, EDR/XDR, cloud security monitoring, identity security, email security, network security, and incident response processes.\nDemonstrated experience building or improving detection use cases, alert triage workflows, response playbooks, escalation procedures, and SOC metrics.\nExperience coordinating investigations involving phishing, malware, endpoint compromise, suspicious authentication, privileged access misuse, data exposure, and cloud security events.\nFamiliarity with frameworks and standards such as MITRE ATT&CK, NIST CSF, NIST SP 800-61, ISO 27001, CIS Controls, or equivalent cyber defense frameworks.\nAbility to communicate clearly with technical teams, business stakeholders, senior leadership, and external partners during security incidents.\nStrong analytical, documentation, prioritization, and decision-making skills in high-pressure operational environments.\nCISSP, Security+, or equivalent industry certification.\nPreferred Qualifications\nExperience operating or transforming a global SOC in an enterprise environment.\nExperience working as an Incident Commander, leading IR execution for the company.\nExperience working with Microsoft Sentinel, Microsoft Defender XDR, KQLs, UEBA, or comparable security operations platforms.\nExperience with cloud security monitoring across Azure, AWS, GCP, or hybrid cloud environments.\nExperience with threat hunting, purple-team collaboration, adversary emulation, or detection engineering.\nExperience managing managed detection and response providers or outsourced SOC services.\nExperience in semiconductor, technology, manufacturing, or intellectual property-intensive environments.\nFamiliarity with GenAI-assisted SOC workflows, including alert enrichment, analyst productivity, incident summarization, and security automation.\nAdditional certifications such as CEH, or similar.\nJob Type:\nRegularShift:\nShift 1 (Malaysia)Primary Location:\nPenang 15, Penang, MalaysiaAdditional Locations:\nBengaluru, Karnataka, IndiaPosting Statement:\nAll qualified applicants will receive consideration for employment without regard to race, color, religion, religious creed, sex, national origin, ancestry, age, physical or mental disability, medical condition, genetic information, military and veteran status, marital status, pregnancy, gender, gender expression, gender identity, sexual orientation, or any other characteristic protected by local law, regulation, or ordinance.","description_format":"text","description_chars":6210,"description_truncated":false,"requirements":{"experience_years_min":5,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[{"name":"Malaysia","iso":"MY","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Security Operations","Processors, MCUs & AI Chips","Incident Response"],"lifecycle":[{"event":"open","at":"2026-09-25T17:50:31Z"}],"liveness":{"score":90,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.903,"p_room":1,"age_days":11,"expected_fill_days":84,"reasons":["conf:4","velocity","win:early","comp:brand"],"computed_at":"2026-09-26T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/altera-security-operations-center-lead-2","json_url":"https://alion.io/job/altera-security-operations-center-lead-2.json","meta":{"generated_at":"2026-09-27T02:37:50Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":2373,"day_limit":5000,"remaining_today":2627,"minute_limit":60,"resets_at":"2026-09-28T00:00:00Z"}}}