Key Responsibilities:
- Develop and drive the SOC, Threat Detection, and Incident Response strategy for systems and MSSP services.
- Design, implement, and operate the SIEM platform using the Elastic Stack (ELK), ensuring scalability, high performance, and high availability.
- Develop use cases, correlation rules, dashboards, alerts, and continuously optimize attack detection quality.
- Deploy and operate SIEM on AWS, integrating services such as CloudTrail, GuardDuty, Security Hub, CloudWatch, and VPC Flow Logs.
- Develop Incident Response (IR) processes, SOC Playbooks, and Runbooks, and participate in handling information security incidents.
- Apply AI/LLMs to Monitoring, Alert Triage, Threat Hunting, and Security Automation to improve SOC operational efficiency.
- Collaborate with internal customers (GalaxyOne), provide solution consulting, conduct current-state assessments, and support the implementation of information security projects.
- Lead, mentor, and develop the SOC/Security Engineer team.
Job Requirements:
1. Education
- Bachelor’s degree in Information Security, Information Technology, Computer Science, or a related field.
- Preferred certifications: CISSP, GCIH, GCIA, CySA+, AWS Security Specialty, Elastic Certified Engineer.
2. Experience
- Minimum of 5 years of experience in Cybersecurity, including at least 2 years in a Senior or Lead role.
- Hands-on experience in designing, implementing, and operating Elastic SIEM (ELK) in an enterprise environment.
- Experience in building or operating a SOC, Detection Engineering, and Incident Response.
- Experience in deploying and operating systems on AWS.
- Experience in delivering Managed Security Services (MSSP).
3. Knowledge & Skills
- Strong understanding of SOC, SIEM, Threat Hunting, Incident Response, MITRE ATT&CK, and Detection Engineering.
- Proficient in the Elastic Stack (Elasticsearch, Logstash, Kibana, Beats/Fleet).
- Knowledge of Cloud Security, particularly AWS.
- Ability to use Python, Bash, or PowerShell for automation.
- Knowledge of or experience in applying AI/LLMs to Security Operations is an advantage.
4. Soft Skills
- Leadership and team management skills.
- Strong communication, consulting, and customer-facing skills.
- Strong analytical, problem-solving, and incident-handling skills.
- Proactive in researching new technologies and committed to continuous improvement.
5. Preferred Qualifications
- Experience in building a SOC from the ground up or operating an MSSP.
- Experience in deploying SIEM on AWS at scale.
- Experience with SOAR, Threat Intelligence, or Detection-as-Code.
- Experience applying AI/GenAI to Monitoring, Alert Triage, Threat Hunting, or Incident Response.
Benefits:
- Competitive salary package (Base salary and performance bonuses).
- Probation period salary is 100% of the official salary.
- Comprehensive health and accident insurance.
- 15 days of annual leave, 3 remote work days per month.
- Provision of work equipment (Macbook/ Laptop, mouse, monitor, etc.).
- A creative and modern working environment.
Working location: Galaxy Innovation Hub – D1 Hi Tech Park, Tang Nhon Phu Ward, HCMC
Kindly send your CV to: talent@galaxyholdings.co







