Senior SOC Engineer
Hytech
Job Description
- Implement & manage the security tools that are currently used as required.
- Involve into POC for any new security products that will be used in the future.
- Write, review & enhance the cybersecurity SOP & playbook as required.
- Investigate the alerts from different security technologies (SIEM, XDR, Anti-Malware, Email Security etc) end-to-end, perform root cause analysis, and mitigate security threats.
- Analyse the emerging threat & provide actionable threat intelligence.
- Perform threat hunting periodically based on the latest threat intelligence.
- Create & review use cases based on the latest threat intelligence.
- Implement & perform Breach & Attack Simulation within the environment to identify & close the possible gaps between the latest threat & the current capabilities of security tools.
- Implement & manage honeypots to identify & analyse the potential threat that may be targeting the environment.
Requirements
- Passionate in Cybersecurity, interested in different aspects of technical expertise in Cybersecurity, which includes (but not limited to): Penetration Testing, Digital Forensic & Incident Response, Threat Intelligence, Threat Hunting, Active Directory Assessment, Configuration Assessment, Compromise Assessment etc.
- Willingness to solve the challenges in a practical/hands-on manner.
- Hands-on experience in different types of OS (Mainly Windows 10/11, Windows Server 2022/2025, Rocky Linux, Amazon Linux, Debian & their derivatives), experienced in macOS will be a plus.
- Understand (on a high level) how different technologies work, such as Active Directory, Databases, EDR/XDR, Anti-Malware, Firewall, WAF, IDS/IPS, VPN etc.
- Keep up to date with the latest technologies, threats & vulnerabilities.
- Understand different types of logs, and be able to analyse & correlate based on different types of logs.
- 7+ years of experience in security operations, detection engineering, incident response, threat hunting, Blue Team operations, or security monitoring platform development.
- Expert-level SOC detection capability, with the ability to design detection programs across attack paths, log sources, detection logic, false positive reduction, and response workflows.
Good to Have
- Ability to perform automation when required, with any programming language such as PowerShell, Bash, Python, Java, Go.
- Hands-on experience in setting up a home lab & configuring different technologies, including but not limited to: SIEM (Eg: OpenSearch, ElasticSearch, Wazuh, Splunk Free), Firewall (Eg: pfSense), Active Directory, VPN, vulnerable VMs etc.
- Familiar (at a high level) with different standards, guidelines & best practices, such as MITRE ATT&CK, ISO 27001, NIST, PCI DSS, CIS Benchmark etc.
- Pursue/Obtained Cybersecurity Certification, such as CompTIA, EC-Council, ISC2, ISACA, INE, OffSec etc.
- Experienced in multiple offerings in AWS, such as EC2, GuardDuty, ALB, S3 etc.
- Maintain a personal blog on the review/introduction of certain technologies/skills/certifications.
Skills
- AWS
- Bash
- Cybersecurity
- Derivatives
- Elasticsearch
- Java
- Linux
- Python
- Splunk
- Windows server


