jobs in Millennium Technology Services

Kerja Sepenuh Masa, Resident Engineer – Cybersecurity di Millennium Technology Services Federal Territory - Maukerja

Undisclosed

KL City, Federal Territory

Kongsi
Simpan

Lokasi Kerja

  • Jalan Sultan Mizan Zainal Abidin, Kompleks Kerajaan Kuala Lumpur Federal Territory Malaysia

Penerangan Kerja

Tanggungjawab

Resident Engineer – Cybersecurity

Senior Detection Engineering & SOAR Specialist


We are seeking an experienced cybersecurity specialist to support a major enterprise security transformation engagement. This is a hands-on resident engineering role focused on detection engineering, security automation, SOAR playbooks, MITRE ATT&CK coverage, telemetry assessment and AI-assisted security content development.

The successful candidate will work closely with the customer’s security team to develop sustainable detection and response capabilities while transferring the knowledge required for independent operation.


Key Responsibilities

• Design, build and tune correlation rules, queries and security alerts across endpoint, network, identity, email and cloud telemetry sources.

• Map detection content to the MITRE ATT&CK framework and document its detection logic, rationale, dependencies and intended outcomes.

• Develop, test and document automated incident-response playbooks.

• Integrate the security automation platform bidirectionally with the customer’s case-management or ticketing platform, including incident triggering, ticket creation, status updates and feedback loops.

• Collaborate with security stakeholders to define, prioritise and deliver the approved security use-case backlog.

• Establish a complete detection-content lifecycle covering entry criteria, quality reviews, false-positive management, version control and content retirement.

• Produce baseline and updated MITRE ATT&CK coverage maps, identifying detection gaps by tactic and technique.

• Conduct formal telemetry coverage assessments to identify threat scenarios that cannot be detected because of missing, insufficient or degraded telemetry.

• Review the existing automation and playbooks supporting the China environment, identify gaps against global security standards and develop the required enhancements.

• Design and implement integration between the security platform and the China-based ticketing system.

• Evaluate, design, build and deploy AI agents supporting detection-content automation, including an agent capable of drafting correlation rules from threat-intelligence inputs.

• Mentor the customer’s security personnel and transfer the knowledge, documentation and operational practices required for independent ownership after the engagement.


Requirements

• Strong hands-on experience in security detection engineering, SIEM content development and alert tuning.

• Practical experience developing SOAR playbooks and integrating security platforms with ticketing or case-management systems.

• Strong understanding of MITRE ATT&CK, threat-detection methodologies and security use-case development.

• Experience working with telemetry from endpoint, network, identity, email and cloud security platforms.

• Ability to develop correlation rules, search queries and detection logic within enterprise SIEM platforms.

• Experience with REST APIs, scripting and system integration using technologies such as Python, PowerShell or similar tools.

• Knowledge of detection-content lifecycle management, version control and false-positive reduction.

• Exposure to AI agents, large language models or AI-assisted cybersecurity automation would be highly advantageous.

• Strong documentation, stakeholder-management, mentoring and knowledge-transfer capabilities.

• Experience supporting complex multinational or China-based enterprise environments would be advantageous.


Preferred Background

• Approximately 7–10 years of cybersecurity experience, including significant hands-on detection engineering and security automation exposure.

• Relevant certifications such as CISSP, GIAC, Splunk, Microsoft Security, Google Security Operations, Palo Alto Networks, Fortinet or equivalent would be advantageous.

This role is suitable for a senior security engineer who can independently design and implement detection and response capabilities—not solely monitor alerts or perform routine SOC operations.

Interested candidates may apply with an updated CV, current and expected salary, notice period and work-authorisation status.

Peringatan Penting

Jangan pernah kongsikan maklumat bank atau kad kredit anda semasa memohon pekerjaan. Elakkan membuat sebarang pembayaran atau mengisi survey yang tidak berkaitan. Jika ada yang mencurigakan, sila laporkan iklan pekerjaan ini segera.

Lebih Lanjut