Location
In office (Kuala Lumpur)
Seniority
Middle · 4+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Ensign InfoSecurity is one of Asia's largest pure play cybersecurity firms and is Singaporean owned. It provides consulting, managed security operations, threat intelligence and incident response. The company was formed by combining the security businesses of Singtel and Certis.
Ensign is hiring !
Key Responsibilities:
- Lead investigation and incident response activities for high-severity or complex security incidents across multiple clients.
- Act as final escalation point for incidents unresolved by Tier 1 and Tier 2 analysts.
- Conduct advanced forensic analysis of logs, network traffic, endpoints, and malware to identify root cause and scope.
- Perform proactive threat hunting based on current threat intelligence, TTPs (MITRE ATT&CK), IOCs, and anomalous behavior.
- Develop and refine detection logic, SIEM correlation rules, and EDR/NDR signatures to enhance SOC effectiveness.
- Support incident containment, eradication, and recovery efforts across diverse client environments.
- Collaborate with Threat Intelligence, Engineering, and IR teams to improve tools, data sources, and workflows.
- Identify gaps in an organization’s measurement metrics, telemetry, and logging capabilities and propose enhancement strategies to achieve the intended outcomes.
- Provide technical leadership and mentorship to junior analysts, supporting their skill development and analysis quality.
- Conduct post-incident reviews and create root cause analysis (RCA) and after-action reports for clients.
- Contribute to playbook creation, tuning, and automation efforts, particularly within SOAR platforms.
- Interface with client security teams, IT teams, and executives to communicate investigation findings, remediation guidance, and strategic improvements.
- Ensure SOC processes align with industry frameworks (e.g., NIST, ISO 27001) and client-specific regulatory requirements (e.g., HIPAA, PCI-DSS).
- Lead purple team exercises or internal red vs. blue simulations to test detection coverage and SOC readiness.
Requirements:
Education & Experience:
- Bachelor’s degree in Cybersecurity, Computer Science, or related discipline (or equivalent hands-on experience).
- 4+ years of experience in a SOC or cybersecurity operations role, including experience with incident response and threat hunting.
- Prior experience in an MSSP or multi-tenant SOC environment is strongly preferred.
Technical Skills:
- Deep expertise in security tools: SIEM (e.g., Splunk, MS Sentinel, QRadar, Google SecOps, Devo), EDR (e.g., CrowdStrike, SentinelOne), NDR, SOAR.
- Strong understanding of malware behavior, exploit techniques, persistence mechanisms, and attack chain.
- Advanced knowledge of operating systems (Windows/Linux), networking, firewalls, and cloud security (e.g., Azure, AWS).
- Familiarity with threat modeling, ATT&CK framework, cyber kill chain, and detection engineering.
- Experience with scripting and automation (e.g., Python, Bash, PowerShell) to improve SOC efficiency.
Certifications (preferred):
- GIAC certifications (e.g., GCIH, GCFA, GCIA, GDAT, GNFA)
- Offensive Security (OSCP) or equivalent
- CompTIA CASP+, CySA+
- Microsoft SC-200, Azure Defender certifications
Key Competencies:
- Strong investigative and analytical skills with attention to detail.
- Ability to manage multiple critical incidents and prioritize effectively under pressure.
- Excellent verbal and written communication, especially in client-facing contexts.
- Leadership and mentoring abilities to upskill junior staff and strengthen SOC maturity.
- Strategic thinking with a continuous improvement mindset.
- High degree of professionalism, discretion, and accountability.
Shift Expectations:
- Generally operates in a regular business-hour schedule, but must be available for escalation during critical incidents.
- May participate in on-call rotations or emergency response shifts depending on client SLAs.
Career Path:
Progression into roles such as SOC Team Lead, Incident Response Manager, Threat Intelligence Lead, or Security Architect, based on leadership, innovation, and impact.
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,634 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Free forever. No card. Under a minute.
Your match
How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.
Recommended for you based on this role
Similar stack
Same company
Kuala Lumpur
Applied - AI Engineer
12 hours ago
≈ $25k – $69k per year (Estimated) • In office • Full-Time • 3+ years exp • Bachelor's Degree • Bengaluru • Pune
Java
Python
AI/ML
AI Agents
AWS Bedrock
Fine-tuning
Google ADK
LangGraph
LLM
LoRA
RAG
Semantic Search
LangChain
PEFT
A2A
Amazon SageMaker
AWS Strands Agents
NIST AI RMF
Semantic Search
Model Context Protocol
DevOps
Amazon EC2
Amazon EKS
AWS
Azure
CI/CD
CloudFormation
Docker
GCP
Git
GitOps
gRPC
Kubernetes
OpenTelemetry
Rest API
Terraform
Vector
Amazon S3
IAM
GitLab
Apply
Senior Java Software Engineer -VP
12 hours ago
≈ $25k – $68k per year (Estimated) • In office • Full-Time • Pune
Java
Java
Spring Boot
Frontend
GraphQL
DevOps
AWS
Azure
Azure DevOps
CI/CD
CloudFormation
Docker
GCP
Jenkins
Kubernetes
Shift-Left
Terraform
GitLab
Cybersecurity
Shift-Left Security
Zero Trust
Apply
Software Engineer (Core)
12 hours ago
≈ $20k – $84k per year (Estimated) • In office • Full-Time • Pune
Java
SQL
Kotlin
Java
Gradle
Maven
Spring Boot
Spring MVC
Kotlin
Mockito
Databases
PostgreSQL
AI/ML
Model Context Protocol
Tokenization
Mobile
JUnit
DevOps
AWS
Azure
CI/CD
Docker
Git
Kubernetes
Web3
Smart Contracts
Apply
Lead Full Stack Engineer
12 hours ago
≈ $27k – $70k per year (Estimated) • In office • Full-Time • Pune
JavaScript
SQL
TypeScript
Java
Java
Gradle
Hibernate
Maven
Spring Boot
Spring Framework
Databases
Apache Kafka
Oracle
Frontend
Angular
React.js
DevOps
AWS
CI/CD
Docker
Git
Jenkins
Kubernetes
OpenShift
Cybersecurity
SonarQube
Veracode
QA
Selenium
Swagger
Apply
Lead Engineer - AI Platform
12 hours ago
≈ $34k – $82k per year (Estimated) • In office • Full-Time • 3+ years exp • Bengaluru • Pune
Java
Python
Python
Asyncio
FastAPI
Databases
Amazon Aurora
AI/ML
AWS Bedrock
Google ADK
LangChain
LangGraph
LLM
RAG
A2A
LLM Guardrails
AI Agents
Model Context Protocol
DevOps
Amazon EKS
AWS
Envoy
Kubernetes
API Gateway
IAM
Cybersecurity
Zero Trust
Apply
Security Engineer- Day 1
1 day ago
In office • Full-Time • 3+ years exp • Indonesia
DevOps
AWS
Azure
GCP
IAM
Apply
Associate Software Engineer
1 day ago
≈ $47k – $165k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Singapore
JavaScript
Node JS
Databases
PostgreSQL
AI/ML
AI Agents
Frontend
D3.js
Next.js
React.js
DevOps
CI/CD
Git
Apply
In office • Internship • Indonesia
PowerShell
Python
AI/ML
Red Teaming
DevOps
Kubernetes
Cybersecurity
Burp Suite
Frida
MITRE ATT&CK
Nessus
OWASP Top 10
Apply
L2 Security Analyst
6 days ago
In office • Full-Time • 2+ years exp • Bachelor's Degree • Kuala Lumpur
PowerShell
Python
DevOps
Cortex
SLI/SLO/SLA
Splunk
Prometheus
Cybersecurity
Corelight
Cortex XSOAR
Crowdstrike
Darktrace
IBM QRadar
Microsoft Defender
MITRE ATT&CK
SentinelOne
TheHive
Management
Jira
ServiceNow
Apply
L2 - Security Analyst
12 days ago
In office • Full-Time • 2+ years exp • Bachelor's Degree • Kuala Lumpur
PowerShell
Python
DevOps
Cortex
SLI/SLO/SLA
Splunk
Prometheus
Cybersecurity
Corelight
Cortex XSOAR
Crowdstrike
Darktrace
IBM QRadar
Microsoft Defender
MITRE ATT&CK
SentinelOne
TheHive
Management
Jira
ServiceNow
Apply
Remote/Hybrid • Full-Time • 1+ year exp • Kuala Lumpur
Apply
Apply
Senior Manager, Technology Centre
1 day ago
In office • Full-Time • 10+ years exp • Kuala Lumpur
COBOL
SQL
Apply
In office • Full-Time • 5+ years exp • Bachelor's Degree • Kuala Lumpur
ABAP
ABAP
ABAP Objects
DevOps
Rest API
SLI/SLO/SLA
Apply
Assistant Manager, Reporting
1 day ago
In office • Full-Time • 8+ years exp • Bachelor's Degree • Kuala Lumpur
ABAP
DevOps
SLI/SLO/SLA
Apply
This is one of many
368,634 more open roles from verified company boards, updated every day.

