EPAM logo

Cyber Security Operations Lead

EPAM·Salary not specified

Nice to have's

Regulated Financial ServicesMicrosoft CertificationsThreat Intelligence

Job description

About the Position

We are seeking a Cyber Security Operations Lead to join EPAM Systems in Malaysia. You will be responsible for detection and incident response in a regulated hedge fund environment, partnering with an outsourced SOC/MDR while tuning Microsoft Sentinel and Microsoft Defender. Based in Malaysia, you will support Singapore and regional offices with hands-on threat hunting, reporting, and continuous control improvements.

Responsibilities

  • Own and enhance Microsoft Sentinel detection content including analytics rules, workbooks, Kusto Query Language (KQL), and threat-hunting workflows
  • Govern the outsourced SOC/MDR provider including onboarding, service reviews, escalation quality, and service level agreement (SLA) performance
  • Maintain security logging coverage across endpoint, identity, network, and cloud environments
  • Triage SOC escalations, assess severity, coordinate containment, and drive incident communications
  • Lead critical incident response through detection, containment, eradication, recovery, and closure
  • Oversee vulnerability scanning, remediation tracking, patch SLA compliance, and cloud security posture improvements
  • Deliver security operations reporting including key risk indicators (KRIs), key performance indicators (KPIs), mean time to detect (MTTD), mean time to respond (MTTR), and vendor performance
  • Coach the Security Operations Analyst while maintaining runbooks, escalation paths, playbooks, and audit-ready documentation

Requirements

  • Proven experience in security operations, security operations center (SOC) leadership, detection engineering, or incident response
  • Hands-on expertise with Microsoft Sentinel including analytics rules, workbooks, Kusto Query Language (KQL), threat hunting, and detection tuning
  • Strong background with Microsoft Defender, especially Microsoft Defender for Endpoint and Microsoft Defender for Cloud
  • Demonstrated ability to manage or partner with an outsourced SOC/MDR provider including SLA governance and escalation management
  • Working knowledge of incident triage, response coordination, post-incident reviews, and detection improvement
  • Practical understanding of vulnerability management, patch governance, threat intelligence, and cloud security posture management (CSPM)
  • Ability to collaborate with security architecture, engineering, and project delivery teams to improve detection and response outcomes
  • Clear communication with confidence translating technical metrics into business-relevant reporting for senior leaders

Nice to Have

  • Experience working in regulated financial services such as asset management, investment management, or hedge funds
  • Microsoft certifications such as SC-200 or AZ-500 or industry certifications such as GCIA, GCIH, or CISSP
  • Experience integrating threat intelligence feeds and indicators of compromise (IOCs) into detection workflows

We Offer

  • Opportunity to work with a leading technology company
  • Competitive compensation package
  • Professional growth and development opportunities

About the Company

EPAM Systems is a global software engineering and product development company with a focus on delivering digital platforms and solutions for the world's leading companies.

© EPAM. This job description was sourced from the employer's public career page. TheJob is not the employer — we index the posting and route candidates to the source. All content rights and hiring decisions belong to the employer.

EPAM helps organizations innovate their business processes and rethink the way they manage their businesses so they can remain competitive in this new digital age.

More at EPAM

All 2376 roles

Popular searches