Deriv.com logo
Deriv.comPosted 1 month ago

Senior SOC Analyst

On-siteCyberjaya, Selangor, Malaysia

Full TimeSenior LevelLarge

Job Summary

Hunt proactively across infrastructure, cloud, identity, and endpoint using hypotheses rather than waiting for alerts. Build, tune, and maintain detections mapped to real attacker TTPs, pushing back on exclusions that trade visibility for noise reduction. Own incidents end to end: triage, containment, root cause analysis, and report writing that leads to actual fixes. Partner with Red Team on purple-team exercises and extend detection coverage into the AI agent stack, covering prompt injection and credential exposure. Perform malware analysis and reverse engineering to understand threats beyond sandbox reports. Mentor junior analysts and raise the bar on triage quality. Work across Dubai and Malaysia within a Security & AI Engineering org focused on autonomous security operations.

Required Qualifications

  • 6+ years in a SOC, threat hunting, or DFIR role
  • real incident ownership
  • not just alert queue work
  • Real depth in at least three of: EDR internals and endpoint telemetry, cloud security monitoring (AWS/GCP), network forensics, malware analysis, SIEM and detection-as-code, identity threat hunting
  • Comfortable writing your own detection logic and tooling in Python or a proper query language
  • not copy-pasting from a vendor blog
  • You think like an attacker when you write a detection
  • You know the difference between reducing noise and creating a blind spot
  • You've caught that mistake before it cost someone
  • You can write a report that gets fixed
  • not filed

Desired Qualifications

  • GCFA, GCIH, GCIA, or equivalent DFIR/detection engineering credential

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce