Cygnify
Senior Incident Response Specialist, Cyber Security-Malaysia
Kuala Lumpur, Malaysia
Get past the screening software and onto a recruiter's desk
hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.
- Keywords matched to this posting
- Fit score before you apply
- Cover letter included
Matched against 2.6M live jobs from 190,000+ employers in 200+ countries.
Tailor my resume for this job →Apply from your AI assistant
Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.
Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.
hirly's read of this role
- Seniority
- Senior
- Country
- MY
- Work mode
- On-site / unstated
- First seen by hirly
- 28 Sept 2026
Derived automatically from the posting. Upload your resume above to see how the role scores against it.
the posting
Role Mission
The Senior Analyst - Cyber Security Incident Response is responsible for monitoring, detecting, and analyzing cybersecurity incidents through the Security Operations Centre (SOC) platform. The role supports the end-to-end incident lifecycle — including triage, investigation, containment, and closure — ensuring timely response to security events and maintaining cyber resilience. This role acts as the Level 2 (L2) Incident Responder, bridging SOC analysts and Incident Response management by performing deep technical analysis and coordinating with internal teams for resolution.
Accountabilities:
Perform end-to-end incident triage and investigation of security alerts escalated from L1 SOC analysts.
Ensure timely incident analysis, containment, and escalation aligned with MTTD and MTTR goals.
Support the SIEM platform (Elastic Stack) by fine-tuning existing rules and suggesting new detections.
Conduct log analysis and correlation across multiple data sources (network, endpoint, and cloud).
Create and maintain incident documentation, reports, and lessons learned.
Support incident response playbook execution during containment and recovery phases.
Collaborate with IT, network, and application teams for incident remediation and root cause analysis.
Provide insights for use case improvements and participate in use case validation and testing.
Escalate confirmed incidents to CSIRT / Assistant Manager - Incident Response for further action.
Participate in post-incident reviews, contributing to process and detection improvements.
Monitor alerts generated from the SOC/SIEM and perform initial to intermediate-level investigations.
Review and validate security events from multiple log sources and identify legitimate threats.
Perform deep-dive investigations for incidents involving malware, phishing, insider threats, and cloud breaches.
Assist in detection rule creation and tuning under the guidance of senior incident responders.
Use frameworks like MITRE ATT&CK for mapping and improving detection quality.
Conduct threat hunting using Elastic Stack and related tools.
Collaborate with MSSP, CSIRT, and IT infrastructure teams to ensure timely incident handling.
Support incident response reporting, evidence collection, and documentation for compliance and audit.
Contribute to automation opportunities in detection and response workflows.
Participate in training sessions, simulations, and tabletop exercises to enhance readiness.
Responsible for the log source onboarding and managing the continuous logs availability on the SIEM platform.
Requirements
Monitor alerts generated from the SOC/SIEM and perform initial to intermediate-level investigations.
Review and validate security events from multiple log sources and identify legitimate threats.
Perform deep-dive investigations for incidents involving malware, phishing, insider threats, and cloud breaches.
Assist in detection rule creation and tuning under the guidance of senior incident responders.
Use frameworks like MITRE ATT&CK for mapping and improving detection quality.
Conduct threat hunting using Elastic Stack and related tools.
Collaborate with MSSP, CSIRT, and IT infrastructure teams to ensure timely incident handling.
Support incident response reporting, evidence collection, and documentation for compliance and audit.
Contribute to automation opportunities in detection and response workflows.
Participate in training sessions, simulations, and tabletop exercises to enhance readiness.
Responsible for the log source onboarding and managing the continuous logs availability on the SIEM platform.
#LI-KI1
Listed on hirly, a job board. hirly is not the employer: Cygnify is hiring for this role.
Similar jobs
- Senior Emergency Response SpecialistMission Support & Test Services, LLC MSTS · Andrews Afb, MD, United StatesFirst seen 6d ago
- Senior Compliance Response SpecialistWheels · Schaumburg, ILFirst seen 9d ago
- Senior Cybersecurity Incident Response SpecialistUvcyber · HyderabadFirst seen 13d ago
- Threat Detection and Response SpecialistPwc · 2 LocationsFirst seen today
- Cybersecurity and Incident Response SpecialistAccentureFirst seen today
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job