Assistant Manager, Cybersecurity Incident Response
cygnify · Kuala Lumpur
Job description
About the role
We are partnering with a leading technology‑driven telecommunications organization that is scaling rapidly to support new digital initiatives. The Assistant Manager, Cybersecurity Incident Response will manage end‑to‑end incident handling, optimise the Elastic SIEM platform, and collaborate across teams to protect large‑scale systems.
Key responsibilities
- End‑to‑end management of cybersecurity incidents, ensuring timely detection, triage, investigation and resolution.
- Achieve and maintain target MTTD and MTTR benchmarks.
- Administer and optimise the Elastic SIEM platform, including rule creation, tuning and integrations.
- Develop detection use cases aligned with evolving threat patterns.
- Monitor, triage and investigate alerts from multiple log sources (network, endpoint, cloud, application).
- Create, refine and manage SIEM detection rules to capture the latest attack patterns.
- Conduct log analysis and event correlation to identify potential intrusions.
- Lead integration efforts with EDR, firewalls, cloud platforms and ticketing systems.
- Collaborate with IT, Network and Cloud teams for incident containment and recovery.
- Document and enhance incident response playbooks and standard operating procedures.
Required profile
- 5‑8 years of experience in SOC, Incident Response or Detection Engineering.
- Proven success administering Elastic Stack (ELK) SIEM environments.
- Hands‑on expertise in incident triage, log analysis and detection rule engineering.
- Ability to design and operationalise MITRE ATT&CK‑aligned use cases.
- Experience collaborating across IT, security and business teams.
- Strong presentation and communication skills for stakeholder‑level incident discussions.
- Relevant certifications such as CISSP, GCIH, GCIA, CEH or Elastic Certified Engineer (preferred).
Required skills
- Elastic Stack (Elasticsearch, Logstash, Kibana, Beats)
- SIEM administration (Elastic SIEM)
- Detection rule engineering
- MITRE ATT&CK framework
- Log analysis and event correlation
- Integration with EDR, firewalls, cloud platforms and ticketing systems
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in Malaysia.
Salaries by job title
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
Published 1 day ago
Expires 1 month from now
3 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
cygnify
Kuala Lumpur