Security Engineer (Blue Team)
On-siteKuala Lumpur, Kuala Lumpur, Malaysia
Job Summary
Manage the installation, setup, and maintenance of EDR and UEM agents to achieve complete operational coverage across company endpoints. Triage, analyse, and validate alerts generated by EDR platforms, distinguishing true positives from false positives and escalating confirmed threats. Conduct threat intelligence analysis by ingesting IOCs and TTPs from feeds, assessing relevance, and translating findings into actionable detection rules. Assist in establishing SOC operations, developing playbooks, and tuning detection rules to reduce noise. Participate in incident response activities including containment, investigation, and post-incident reviews. Maintain documentation of security configurations and collaborate with IT teams to ensure endpoint compliance. Coordinate the bug bounty program lifecycle, including report triage and audit log maintenance. Requires one year of relevant experience, a Bachelor's degree, and knowledge of MITRE ATT&CK.
Required Qualifications
- One year of relevant work experience in cybersecurity, IT operations, or a related field
- Bachelor's degree in Computer Science, Information Management, Information Security, or a related discipline
- Understanding of common attack techniques and frameworks (MITRE ATT&CK)
- Basic knowledge of endpoint hardening, network security fundamentals, and log analysis
- Strong analytical and problem-solving skills with attention to detail
Desired Qualifications
- Relevant certifications (CompTIA Security+, CySA+, BTL1, or similar)
- Experience with EDR and UEM solutions (e.g., Crowdstrike, SentinelOne, JumpCloud, Jamf, etc.)
- Familiarity with threat intelligence platforms and IOC management
- Scripting skills (Python, PowerShell, or Bash) for automation of routine tasks
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.