413,278open jobs
14,581companies
74,184added this week
Browse all
Salary
$18k – $41k per year (Estimated)
Location
In office (Kuala Lumpur)
Seniority
Senior · 8+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Logicalis US is the American arm of a global IT solutions provider. It designs and manages networks, cloud, security and collaboration systems for enterprises. The company is part of the Datatec group.

About Us

At Logicalis Asia Pacific, this is where you belong, grow, and thrive - at one of APAC's leading AI-driven technology integrators.

As the Architects of Change™, we combine global expertise with local insight to help organisations accelerate their journey toward becoming AI-ready enterprises. With 7,000+ professionals across 30 territories and more than 10,000 clients worldwide, we deliver lifecycle services across cloud, connectivity, collaboration, cybersecurity, and managed services - providing real-time visibility and intelligence across our clients' digital ecosystems.

You'll belong as part of a collaborative regional team embedded within a global organisation. You'll grow through hands-on experience with the world's leading technology partners, supported by investment in certifications, consulting capability, and cross-border opportunity. And you'll thrive in a culture built on inclusion, trust, and continuous improvement.

Logicalis is proud to be a Great Place to Work® Certified™ organisation across multiple APAC markets - because the commitment we bring to our clients belongs equally to our people.

Join us and help shape the future of technology across APAC.

Detection Engineering

  • Design, develop, and deploy high-fidelity detection rules in SIEM (Splunk, Microsoft Sentinel, Devo, QRadar, EDR, etc.).
  • Create custom use cases to detect MITRE TTPs aligned with real-world threats and red team activities.
  • Conduct detection gap analysis, tune alerting mechanisms, and eliminate false positives at the MSS customer environment
  • Perform regular fine-tuning and optimization of detection rules, correlation logic, and alert thresholds across SIEM, EDR, and other security platforms to enhance detection accuracy and reduce false positives.
  • Continuously assess detection efficacy based on incident feedback and threat landscape evolution, implementing improvements accordingly.
  • Collaborate with red/purple teams to validate detection logic and build threat-informed defenses.
  • Regularly review, update, and enhance detection logic to ensure alignment with the latest threat intelligence, adversary TTPs, and evolving attack techniques.
  • Maintain relevancy and effectiveness of security detections by incorporating insights from threat hunts, incident response cases, red team exercises, and industry best practices.

Threat Hunting and Threat Intel:

  • Proactively hunt for advanced threats across on-prem and cloud environments using telemetry from SIEM, EDR, NDR, and threat intelligence.
  • Develop hypotheses based on TTPs, threat intelligence feeds, and incident trends.
  • Use frameworks like MITRE ATT&CK and Diamond Model to structure hunting campaigns.
  • Document hunt procedures and outcomes to support knowledge sharing and continuous improvement.
  • Map threat actor TTPs to frameworks such as MITRE ATT&CK to support proactive defense strategies and inform detection engineering efforts.
  • Provide actionable threat intelligence to SOC, detection engineering, and IR teams to inform custom detection rule development, prioritization of hunts, and incident scoping
  • Contribute to the threat intelligence lifecycle, including direction, collection, processing, analysis, dissemination, and feedback.
  • Ingest, analyze, and operationalize threat intelligence from internal sources, commercial feeds, and open-source intelligence (OSINT) to enrich detection logic, threat hunting hypotheses, and incident investigations
  • Collaborate with internal and commercial threat intelligence teams to contextualize IOCs and TTPs for targeted and industry-specific threats.
  • Maintain up-to-date threat intelligence repositories and contribute to the continuous improvement of threat intel processes and playbooks

Incident Response:

  • Lead incident response lifecycle (detection, triage, containment, eradication, recovery).
  • Handle security incidents tickets escalated by Level II team, and draft security incident report covering the root cause, forensic evidence, and recommended mitigation plans
  • Conduct/support forensic analysis of endpoints, logs, and network traffic to determine root cause and impact.
  • Coordinate with internal stakeholders and external partners during critical incidents.
  • Develop and maintain playbooks, runbooks, and incident reports.
  • Digital Forensics and Incident Response (DFIR) experience is a strong added advantage, enabling deeper investigations and root cause analysis.

Collaboration & Mentorship :

  • Mentor and support L1/L2 SOC analysts in investigations, tool usage, and processes.
  • Participate in tabletop exercises and red/purple team assessments.
  • Lead and conduct regular customer meetings to review SOC activities, including security posture, key metrics, and ongoing initiatives.
  • Prepare and deliver detailed briefings on priority incidents, RCA, ensuring timely communication of root cause, impact analysis, mitigation steps, and next actions.
  • Act as a primary point of contact for Incident escalations and maintain consistent, professional engagement with client stakeholders.
  • Coordinate with cross-functional teams including Engineering, Development, Red Team, and Risk/Compliance.
  • Identify gaps in existing SOC process and work with team members or other departments to create, modify standard operating procedures, to automate any mundane daily operational activities, ensuring Ops are run efficiently.

Requirements:

  • Candidate should have at least 8-10 years of working experience in SOC and MSS environments,
  • Bachelor's degree in computer engineering, Computer Science, Cyber Security, Information Security, or other equivalents.
  • Excellent hands-on experience in implementations, incident analysis of Splunk, IBM QRadar, Azure Sentinel SIEM (Security Information and Event Management) & Devo technologies.
  • Hands on experience on any Endpoint Protection (EPP) or Endpoint Detection Response (EDR) technologies. Preferred if CrowdStrike, Microsoft Defender.
  • Hands on experience on SOAR (Security Orchestration, Automation, and Response) technologies.
  • Experience in malware analysis for Windows and Linux/Mac.
  • Exposure to firewall technologies such as Cisco, Palo Alto, Checkpoint, Fortinet.
  • Good understanding of WIN, LINUX environments and well versed with basic LINUX commands and troubleshooting, with proven Unix (Solaris, Linux, BSD (Bumi Serpong Damai)) experience.
  • Knowledge of any shell scripting language and applying it to automate mundane operations tasks
  • Knowledge of current cyber threats, attack vectors, vulnerabilities, and threat intelligence feeds.
  • Ability to work effectively in a team environment, collaborate cross-functionally, and mentor junior analysts
  • Candidate should have at least one SANS certification. Preferred if that is GCIH
  • Good understanding of basic network concepts and advantages of exposure to cloud technologies.
  • Lateral thinking combined with excellent troubleshooting skills, preferably with experience following ITIL (Information Technology Infrastructure Library) standards
  • Lead team of security analysts, develop SOC standard operating procedures and develop Threat Intel feeds such as MISP.

Interested applicants please submit your application with your expected salary and notice period to be considered for the role.

We regret that only shortlisted candidates will be notified.

As part of any recruitment process, we collect and processes personal data relating to job applicants. We are committed to being transparent about how we collect and use that data and to meeting our data protection obligations.

By applying to this post and sending us your resume, you agree to the collection, use and/or disclosure of your personal data in the manner as set out in our Data Protection Notice for Job Applicants.

Click below to view the data protection notice.

https://ap.logicalis.com/sites/default/files/2022-10/PIMS-A7.3-01%20Attachment%20I%20DP%20Notice%20for%20Job%20Applicants_updated9sept22.pdf.

Interested applicants are invited to apply via our careers portal. Only shortlisted candidates will be notified.

As part of our recruitment process, we collect and process personal data relating to job applicants. By submitting your application, you consent to the collection, use, and/or disclosure of your personal data in accordance with our Data Protection Notice for Job Applicants.

At Logicalis, we are committed to creating a diverse and inclusive workplace where everyone can thrive.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
413,278 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Kuala Lumpur
Deployment Lead 1 hour ago
$28k – $58k per year (Estimated) • In office • Full-Time • 10+ years exp • Bachelor's Degree • Mumbai
JavaScript
DevOps
Azure
Incident Management
Management
Jira
Microsoft Teams
ServiceNow
Apply
Remote/Hybrid • Full-Time • 5+ years exp • Helsinki
Databases
Databricks
Microsoft Fabric
Snowflake
AI/ML
Agentic Workflows
AI Agents
LLM
DevOps
AWS
Azure
Platform Engineering
Apply
In office • Full-Time • 6+ years exp • Riyadh
AI/ML
AI Agents
Fine-tuning
Function Calling
Knowledge Graph
LLM
LLM Guardrails
Model Context Protocol
Multi-Agent Systems
NLP
Tool Use
DevOps
FinOps
IAM
Vector
Cybersecurity
Defense in Depth
Apply
QA Engineer 1 hour ago
$13k – $39k per year (Estimated) • In office • 3+ years exp • Bengaluru
JavaScript
Python
SQL
DevOps
Azure
CI/CD
Dynatrace
New Relic
Management
Jira
QA
Cypress
Playwright
Postman
Rest-Assured
Selenium
Apply
$94k – $222k per year (Estimated) • In office • Full-Time • 5+ years exp • Singapore
Python
SQL
Databases
PostGIS
PostgreSQL
DevOps
AWS
Azure
IAM
Rest API
Apply
$67k – $165k per year (Estimated) • Remote • Full-Time • 5+ years exp • Frankfurt am Main
Python
AI/ML
LangChain
LangGraph
LLM
Apply
$63k – $122k per year (Estimated) • In office • Full-Time • Frankfurt am Main • Munich • Cologne
Python
DevOps
Ansible
ArgoCD
AWS
Azure
CI/CD
Datadog
Docker
FluxCD
GCP
Git
GitLab
GitLab CI
GitOps
Grafana
Jenkins
Kubernetes
OpenShift
Prometheus
Red Hat
Terraform
VMWare
Apply
UC Engineer 4 days ago
In office • Full-Time • Singapore
Apply
$68k – $92k per year • Remote/Hybrid • Full-Time • 5+ years exp • Frankfurt am Main
Java
SQL
Apex
Apex
MuleSoft
AI/ML
Model Context Protocol
Apply
$16k – $36k per year (Estimated) • In office • Full-Time • 5+ years exp • Kuala Lumpur
Apply
$9.5k – $22k per year (Estimated) • In office • Full-Time • 2+ years exp • Kuala Lumpur
Apply
In office • Full-Time • Kuala Lumpur
SQL
Apply
In office • Full-Time • Kuala Lumpur
Apply
PTP Specialist 3 days ago
$12k – $16k per year • Remote/Hybrid • Full-Time • Kuala Lumpur
Apply
$27k – $36k per year • Remote/Hybrid • Full-Time • Kuala Lumpur
Apply
See all jobs
This is one of many
413,278 more open roles from verified company boards, updated every day.