Defensive Security Lead

Key Responsibilities:

  • Develop and drive the SOC, Threat Detection, and Incident Response strategy for systems and MSSP services.
  • Design, implement, and operate the SIEM platform using the Elastic Stack (ELK), ensuring scalability, high performance, and high availability.
  • Develop use cases, correlation rules, dashboards, alerts, and continuously optimize attack detection quality.
  • Deploy and operate SIEM on AWS, integrating services such as CloudTrail, GuardDuty, Security Hub, CloudWatch, and VPC Flow Logs.
  • Develop Incident Response (IR) processes, SOC Playbooks, and Runbooks, and participate in handling information security incidents.
  • Apply AI/LLMs to Monitoring, Alert Triage, Threat Hunting, and Security Automation to improve SOC operational efficiency.
  • Collaborate with internal customers (GalaxyOne), provide solution consulting, conduct current-state assessments, and support the implementation of information security projects.
  • Lead, mentor, and develop the SOC/Security Engineer team.

Job Requirements:

1. Education

  • Bachelor’s degree in Information Security, Information Technology, Computer Science, or a related field.
  • Preferred certifications: CISSP, GCIH, GCIA, CySA+, AWS Security Specialty, Elastic Certified Engineer.

2. Experience

  • Minimum of 5 years of experience in Cybersecurity, including at least 2 years in a Senior or Lead role.
  • Hands-on experience in designing, implementing, and operating Elastic SIEM (ELK) in an enterprise environment.
  • Experience in building or operating a SOC, Detection Engineering, and Incident Response.
  • Experience in deploying and operating systems on AWS.
  • Experience in delivering Managed Security Services (MSSP).

3. Knowledge & Skills

  • Strong understanding of SOC, SIEM, Threat Hunting, Incident Response, MITRE ATT&CK, and Detection Engineering.
  • Proficient in the Elastic Stack (Elasticsearch, Logstash, Kibana, Beats/Fleet).
  • Knowledge of Cloud Security, particularly AWS.
  • Ability to use Python, Bash, or PowerShell for automation.
  • Knowledge of or experience in applying AI/LLMs to Security Operations is an advantage.

4. Soft Skills

  • Leadership and team management skills.
  • Strong communication, consulting, and customer-facing skills.
  • Strong analytical, problem-solving, and incident-handling skills.
  • Proactive in researching new technologies and committed to continuous improvement.

5. Preferred Qualifications

  • Experience in building a SOC from the ground up or operating an MSSP.
  • Experience in deploying SIEM on AWS at scale.
  • Experience with SOAR, Threat Intelligence, or Detection-as-Code.
  • Experience applying AI/GenAI to Monitoring, Alert Triage, Threat Hunting, or Incident Response.

Benefits:

  • Competitive salary package (Base salary and performance bonuses).
  • Probation period salary is 100% of the official salary.
  • Comprehensive health and accident insurance.
  • 15 days of annual leave, 3 remote work days per month.
  • Provision of work equipment (Macbook/ Laptop, mouse, monitor, etc.).
  • A creative and modern working environment.

Working location: Galaxy Innovation Hub – D1 Hi Tech Park, Tang Nhon Phu Ward, HCMC

Kindly send your CV to: talent@galaxyholdings.co 

Other hiring positions

Contact with
Galaxy Holdings

Contact Us