about the company
Our client is a leading financial institution in Malaysia with a large-scale technology and cybersecurity environment. The organisation is strengthening its security monitoring capabilities and is looking for an experienced SIEM specialist to take ownership of enterprise SIEM engineering, security telemetry and detection capabilities.
...
about the job
We are looking for a Senior SIEM Engineer with strong hands-on experience in SIEM platform engineering, security monitoring and detection engineering.
This is a platform-focused cybersecurity engineering role, responsible for the architecture, performance, scalability, reliability and continuous optimisation of an enterprise SIEM environment.
You will work closely with SOC, Incident Response, Threat Intelligence, Cloud and Infrastructure teams to ensure security data is reliable, scalable and effective for threat detection and investigation.
Key Responsibilities
- Architect, build and operate large-scale SIEM platforms across on-premises, cloud or hybrid environments.
- Design and maintain SIEM infrastructure with strong availability, performance, scalability and cost efficiency.
- Perform SIEM performance tuning, capacity planning, EPS/TPS modelling and workload optimisation.
- Manage high-volume security log ingestion and onboard log sources across cloud, endpoint, network, identity, SaaS and applications.
- Automate SIEM deployment, configuration, upgrades and content management using IaC, CI/CD and scripting.
- Troubleshoot complex SIEM issues involving Linux/OS, networking, storage, query performance and data integrity.
- Act as a technical escalation point for SIEM incidents, outages and platform issues.
- Design, review and optimise security detection rules and use cases aligned with MITRE ATT&CK.
- Translate attacker behaviour and threat scenarios into scalable detection logic.
- Tune detections to improve alert quality, reduce false positives and optimise SOC workload.
- Support threat hunting, security monitoring and incident response through performant SIEM search and analytics.
- Work closely with SOC and security teams to improve alert triage, investigation and response workflows.
- Establish SIEM engineering standards, best practices and technical patterns.
- Mentor junior SIEM and detection engineers and provide technical guidance during major security incidents.
Key Requirements
- 8+ years of hands-on experience in SIEM engineering, security engineering or large-scale security monitoring platforms.
- Strong experience designing, implementing and operating enterprise SIEM platforms.
- Proven experience supporting 24x7 SOC environments and high-volume log ingestion.
- Strong knowledge of SIEM architecture, performance tuning, capacity planning and optimisation.
- Hands-on detection engineering experience and strong understanding of SOC operations.
- Good understanding of incident response, threat detection and MITRE ATT&CK.
- Strong foundation in Linux, networking and cloud platforms.
- Experience integrating security telemetry across hybrid environments.
- Proficiency in scripting, automation, IaC and CI/CD for security engineering.
- Strong troubleshooting and problem-solving skills across complex enterprise environments.
- Ability to act as a technical authority and collaborate across SOC, Cloud and Infrastructure teams.