The posting
To support PDAP Security Operations in detecting, investigating, and coordinating the resolution of cybersecurity risks while driving accountability, closure, continuous improvement, and AIOps adoption across the region.
Job Responsibilities:
Security Monitoring & Incident Operations
- Monitor and analyse alerts and cases from SOC, SIEM, EDR, identity-threat detection, endpoint security, IDS/IPS, WAF, email security and other integrated security technologies.
- Validate alerts, collect evidence, assess severity and business impact, and coordinate containment, recovery and follow-up with the SOC provider and relevant teams.
- Support major-incident coordination, including war-room activities, stakeholder updates, investigation records, root-cause analysis and lessons learned.
Accountability, Remediation Tracking & Closure
- Assign or confirm accountable owners, target dates and escalation paths for actionable incidents, vulnerabilities and security findings.
- Track remediation to evidence-based validation and closure; escalate overdue, blocked or high-risk items and maintain a complete audit trail.
- Confirm residual risk and ensure findings are not closed without sufficient evidence or the appropriate risk decision.
Vulnerability & External Attack Surface Management
- Coordinate vulnerability notices, assessment findings, penetration-test findings and urgent remediation follow-up across infrastructure, cloud, application and local IT teams.
- Support EASM operations, validate external exposures and unregistered assets, engage asset owners and track corrective actions to closure.
- Produce vulnerability and exposure trends, ageing views, recurring-risk themes and management reporting.
SOC, SIEM/SOAR & AIOps Improvement
- Work with the SOC provider to improve detection use cases, alert quality, enrichment, correlation, ticket routing and response playbooks.
- Identify and implement automation opportunities for repetitive triage, evidence collection, notification, assignment, remediation tracking, validation and reporting.
- Measure automation outcomes such as workload reduction, response improvement, false-positive reduction and closure performance.
- Apply human oversight, authorization, auditability and rollback controls to AI-assisted or automated actions.
Regional Centre of Excellence & Governance
- Maintain SOPs, runbooks, RACI matrices, escalation procedures, contact lists, control evidence and reusable templates for consistent regional operations.
- Provide operational guidance, coaching and knowledge sharing to regional stakeholders and operating companies.
- Participate in security architecture and service reviews by providing operational risk, monitoring, response and supportability input; final approvals remain with the accountable governance authority.
Reporting, Stakeholder & Vendor Management
- Prepare weekly, monthly and ad-hoc dashboards covering incidents, vulnerabilities, SLA/KPI performance, ageing, closure and improvement actions.
- Coordinate with SOC/MDR providers, security-tool vendors, infrastructure, cloud, application, Service Desk, local IT and management stakeholders.
- Monitor vendor service performance, challenge gaps and ensure agreed actions are tracked to completion.
Main activities & projects
- Daily: SOC/SIEM/EDR/WAF/identity and security-tool alerts, tickets, escalations and remediation follow-up.
- Weekly: High-risk incidents and vulnerabilities, overdue actions, vendor performance and operational coordination.
- Monthly: Security dashboards, SLA/KPI and trend reporting, EASM engagement, vulnerability posture, improvement backlog and management updates.
- Periodic / project-based: SOP standardization, SOC transformation, SIEM/SOAR onboarding, automation use cases, CyberArk/PAM, phishing operations, WAF and other security initiatives.
Job Requirements:
- Bachelor’s degree in computer science, Information Technology, Cybersecurity or a related field; equivalent relevant experience may be considered.
- Approximately 3–5 years of relevant experience in security operations, SOC, incident response, vulnerability management or infrastructure security.
- Practical experience with SIEM and security monitoring technologies. Microsoft Sentinel exposure is preferred; experience with equivalent platforms is relevant.
- Familiarity with technologies such as Microsoft Defender, EDR, WAF, IDS/IPS, IAM/PAM, CyberArk, DLP/CASB, vulnerability-management and EASM solutions.
- Understanding of common cyberattack techniques, alert triage, incident investigation, containment, recovery coordination and evidence handling.
- Ability to manage multiple cases, owners, due dates and escalations and to drive issues through verified closure.
- Working knowledge of automation or orchestration concepts, APIs, scripting, SOAR workflows or AI-assisted security operations is advantageous.
- Strong written and verbal communication skills for technical and non-technical stakeholders across APAC.
- Ability to work independently, collaborate across teams and participate in after-hours incident support when required by the approved operating model.



