FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

SOC Analyst, L1 / L2 / L3
NexTbil Tech. Monitor security alerts and events across SIEM, endpoint, network, email, identity, and cloud security tools .
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in cybersecurity operations, including incident response, threat hunting, and security platform administration. Proficient in documenting investigations and coordinating SOC activities while maintaining compliance in regulated environments.
Highest-signal resume keywords
Incident Response CoordinationSecurity Platform AdministrationThreat HuntingSIEM ExperienceCybersecurity Operations
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Incident ResponseThreat HuntingLog AnalysisAlert TuningDetection Logic ValidationNetwork ProtocolsOperating SystemsCloud ServicesIdentity and Access ConceptsCyber Threats
Soft Skills
DocumentationMentoringCoachingStructured Work EnvironmentCollaboration
Tools & Technologies
SIEMEDR/XDRMicrosoft SentinelSplunkQRadarCrowdStrikePalo AltoFortinetProofpointZscaler
Certifications & Qualifications
CompTIA Security+CySA+GCIAGCIHGCFACEHSC-200AZ-500Microsoft Security Operations Analyst
Industry Keywords
Cybersecurity OperationsSOCComplianceRegulated EnvironmentsAudit Support
Tech Stack
Tools & technologiesCloudCyber SecuritySplunk
About the role
Key responsibilities & impact- Monitor security alerts and events across SIEM, endpoint, network, email, identity, and cloud security tools
- Perform alert triage, investigation, enrichment, impact assessment, threat hunting, and root-cause analysis according to role level
- Identify false positives, suspicious patterns, indicators of compromise, repeated attack activity, and control gaps
- Escalate suspected or confirmed incidents to incident responders, platform owners, infrastructure teams, and business stakeholders
- Document alerts, investigations, evidence, response actions, closure rationale, lessons learned, and recommendations in ticketing and case management systems
- Administer and maintain security platforms, including access updates, configuration changes, log source onboarding, connector health checks, alert tuning, rule updates, and dashboard maintenance
- Develop and maintain detection use cases, correlation rules, dashboards, playbooks, standard operating procedures, and response runbooks
- Coordinate incident response activities to support timely containment and remediation
- Provide technical guidance, quality review, mentoring, and investigation coaching to L1 and L2 analysts
- Support 24/7 SOC operations through structured shifts, handovers, service-level adherence, and Follow-The-Sun collaboration with global teams
- Maintain awareness of current threats affecting enterprise environments
Requirements
What you’ll need- Bachelor’s degree or currently completed studies in Cybersecurity, Information Technology, Computer Science, Systems Engineering, or a related discipline for L1/L2
- Bachelor’s degree in a related discipline or equivalent practical experience for L3
- 2+ years of experience for L1
- 3–5 years of experience for L2
- 5+ years of experience in cybersecurity operations for L3
- Basic to strong understanding of networking, operating systems, identity and access concepts, cloud services, attacker techniques, cyber threats, incident response, log analysis, endpoint telemetry, network protocols, and authentication flows, depending on level
- Familiarity or hands-on experience with SIEM, EDR/XDR, email security, vulnerability management, cloud security, identity security, SOAR, case management, or network security monitoring platforms
- Experience with security platform administration, alert tuning, detection logic validation, log source onboarding, dashboards, connectors, and operational troubleshooting, depending on level
- Ability to document incidents and investigations clearly, follow procedures and runbooks, and work in a structured security operations environment
- Working proficiency in English preferred for L1/L2 and required for L3
- Availability to work on-site in Kuala Lumpur, Malaysia required
- Preferred certifications include CompTIA Security+, CySA+, GCIA, GCIH, GCFA, CEH, SC-200, AZ-500, Microsoft Security Operations Analyst, or equivalent
- Exposure to Microsoft Sentinel, Microsoft Defender XDR, Splunk, QRadar, CrowdStrike, Palo Alto, Fortinet, Proofpoint, Zscaler, or comparable technologies
- Experience in regulated or compliance-focused environments, audit support, documentation, mentoring, technical escalations, and SOC process improvement
Benefits
Comp & perks- Attractive salary package and performance-based bonuses
- Flexible working options, including remote and hybrid working models
- Comprehensive health insurance
- Wellness initiatives and physical and mental well-being resources
- Continuous learning through training programs
- Mentorship
- Clearly defined career development paths
- Diverse, inclusive, and collaborative workplace
- Regular team-building activities and social events
- Competitive compensation and performance-based incentives
- Medical insurance and wellness initiatives
- Structured learning, development, and career growth opportunities