Security Operation Support Engineer
Must-have:CloudAISecurity
To support PDAP Security Operations in detecting, investigating, and coordinating the resolution of cybersecurity risks while driving accountability, closure, continuous improvement, and AIOps adoption across the region.
Job Responsibilities:
Security Monitoring & Incident Operations
- Monitor and analyse alerts and cases from SOC, SIEM, EDR, identity-threat detection, endpoint security, IDS/IPS, WAF, email security and other integrated security technologies.
- Validate alerts, collect evidence, assess severity and business impact, and coordinate containment, recovery and follow-up with the SOC provider and relevant teams.
- Support major-incident coordination, including war-room activities, stakeholder updates, investigation records, root-cause analysis and lessons learned.
Accountability, Remediation Tracking & Closure
- Assign or confirm accountable owners, target dates and escalation paths for actionable incidents, vulnerabilities and security findings.
- Track remediation to evidence-based validation and closure; escalate overdue, blocked or high-risk items and maintain a complete audit trail.
- Confirm residual risk and ensure findings are not closed without sufficient evidence or the appropriate risk decision.
Vulnerability & External Attack Surface Management
- Coordinate vulnerability notices, assessment findings, penetration-test findings and urgent remediation follow-up across infrastructure, cloud, application and local IT teams.
- Support EASM operations, validate external exposures and unregistered assets, engage asset owners and track corrective actions to closure.
- Produce vulnerability and exposure trends, ageing views, recurring-risk themes and management reporting.
SOC, SIEM/SOAR & AIOps Improvement
- Work with the SOC provider to improve detection use cases, alert quality, enrichment, correlation, ticket routing and response playbooks.
- Identify and implement automation opportunities for repetitive triage, evidence collection, notification, assignment, remediation tracking, validation and reporting.
- Measure automation outcomes such as workload reduction, response improvement, false-positive reduction and closure performance.
- Apply human oversight, authorization, auditability and rollback controls to AI-assisted or automated actions.
Regional Centre of Excellence & Governance
- Maintain SOPs, runbooks, RACI matrices, escalation procedures, contact lists, control evidence and reusable templates for consistent regional operations.
- Provide operational guidance, coaching and knowledge sharing to regional stakeholders and operating companies.
- Participate in security architecture and service reviews by providing operational risk, monitoring, response and supportability input; final approvals remain with the accountable governance authority.
Reporting, Stakeholder & Vendor Management
- Prepare weekly, monthly and ad-hoc dashboards covering incidents, vulnerabilities, SLA/KPI performance, ageing, closure and improvement actions.
- Coordinate with SOC/MDR providers, security-tool vendors, infrastructure, cloud, application, Service Desk, local IT and management stakeholders.
- Monitor vendor service performance, challenge gaps and ensure agreed actions are tracked to completion.
Main activities & projects
- Daily: SOC/SIEM/EDR/WAF/identity and security-tool alerts, tickets, escalations and remediation follow-up.
- Weekly: High-risk incidents and vulnerabilities, overdue actions, vendor performance and operational coordination.
- Monthly: Security dashboards, SLA/KPI and trend reporting, EASM engagement, vulnerability posture, improvement backlog and management updates.
- Periodic / project-based: SOP standardization, SOC transformation, SIEM/SOAR onboarding, automation use cases, CyberArk/PAM, phishing operations, WAF and other security initiatives.
Job Requirements:
- Bachelor’s degree in computer science, Information Technology, Cybersecurity or a related field; equivalent relevant experience may be considered.
- Approximately 3–5 years of relevant experience in security operations, SOC, incident response, vulnerability management or infrastructure security.
- Practical experience with SIEM and security monitoring technologies. Microsoft Sentinel exposure is preferred; experience with equivalent platforms is relevant.
- Familiarity with technologies such as Microsoft Defender, EDR, WAF, IDS/IPS, IAM/PAM, CyberArk, DLP/CASB, vulnerability-management and EASM solutions.
- Understanding of common cyberattack techniques, alert triage, incident investigation, containment, recovery coordination and evidence handling.
- Ability to manage multiple cases, owners, due dates and escalations and to drive issues through verified closure.
- Working knowledge of automation or orchestration concepts, APIs, scripting, SOAR workflows or AI-assisted security operations is advantageous.
- Strong written and verbal communication skills for technical and non-technical stakeholders across APAC.
- Ability to work independently, collaborate across teams and participate in after-hours incident support when required by the approved operating model.