{"id":15480,"date":"2026-08-06T16:36:44","date_gmt":"2026-08-06T09:36:44","guid":{"rendered":"https:\/\/galaxyholdings.co\/?post_type=job&#038;p=15480"},"modified":"2026-08-06T16:36:44","modified_gmt":"2026-08-06T09:36:44","slug":"defensive-security-lead","status":"publish","type":"job","link":"https:\/\/galaxyholdings.co\/en\/job\/defensive-security-lead\/","title":{"rendered":"Defensive Security Lead"},"content":{"rendered":"<h2 data-section-id=\"1f787jk\" data-start=\"122\" data-end=\"140\"><span style=\"font-size: 18pt; color: #0000ff;\">Key Responsibilities:<\/span><\/h2>\n<ul>\n<li>Develop and drive the SOC, Threat Detection, and Incident Response strategy for systems and MSSP services.<\/li>\n<li>Design, implement, and operate the SIEM platform using the Elastic Stack (ELK), ensuring scalability, high performance, and high availability.<\/li>\n<li>Develop use cases, correlation rules, dashboards, alerts, and continuously optimize attack detection quality.<\/li>\n<li>Deploy and operate SIEM on AWS, integrating services such as CloudTrail, GuardDuty, Security Hub, CloudWatch, and VPC Flow Logs.<\/li>\n<li>Develop Incident Response (IR) processes, SOC Playbooks, and Runbooks, and participate in handling information security incidents.<\/li>\n<li>Apply AI\/LLMs to Monitoring, Alert Triage, Threat Hunting, and Security Automation to improve SOC operational efficiency.<\/li>\n<li>Collaborate with internal customers (GalaxyOne), provide solution consulting, conduct current-state assessments, and support the implementation of information security projects.<\/li>\n<li>Lead, mentor, and develop the SOC\/Security Engineer team.<\/li>\n<\/ul>\n<h2 data-section-id=\"1uxnuvu\" data-start=\"2250\" data-end=\"2270\"><span style=\"font-size: 18pt; color: #0000ff;\">Job Requirements:<\/span><\/h2>\n<h3><span style=\"font-size: 14pt;\">1. Education<\/span><\/h3>\n<ul data-spread=\"false\">\n<li>Bachelor&#8217;s degree in Information Security, Information Technology, Computer Science, or a related field.<\/li>\n<li>Preferred certifications: CISSP, GCIH, GCIA, CySA+, AWS Security Specialty, Elastic Certified Engineer.<\/li>\n<\/ul>\n<h3><span style=\"font-size: 14pt;\">2. Experience<\/span><\/h3>\n<ul data-spread=\"false\">\n<li>Minimum of 5 years of experience in Cybersecurity, including at least 2 years in a Senior or Lead role.<\/li>\n<li>Hands-on experience in designing, implementing, and operating Elastic SIEM (ELK) in an enterprise environment.<\/li>\n<li>Experience in building or operating a SOC, Detection Engineering, and Incident Response.<\/li>\n<li>Experience in deploying and operating systems on AWS.<\/li>\n<li>Experience in delivering Managed Security Services (MSSP).<\/li>\n<\/ul>\n<h3><span style=\"font-size: 14pt;\">3. Knowledge &amp; Skills<\/span><\/h3>\n<ul data-spread=\"false\">\n<li>Strong understanding of SOC, SIEM, Threat Hunting, Incident Response, MITRE ATT&amp;CK, and Detection Engineering.<\/li>\n<li>Proficient in the Elastic Stack (Elasticsearch, Logstash, Kibana, Beats\/Fleet).<\/li>\n<li>Knowledge of Cloud Security, particularly AWS.<\/li>\n<li>Ability to use Python, Bash, or PowerShell for automation.<\/li>\n<li>Knowledge of or experience in applying AI\/LLMs to Security Operations is an advantage.<\/li>\n<\/ul>\n<h3><span style=\"font-size: 14pt;\">4. Soft Skills<\/span><\/h3>\n<ul data-spread=\"false\">\n<li>Leadership and team management skills.<\/li>\n<li>Strong communication, consulting, and customer-facing skills.<\/li>\n<li>Strong analytical, problem-solving, and incident-handling skills.<\/li>\n<li>Proactive in researching new technologies and committed to continuous improvement.<\/li>\n<\/ul>\n<h3><span style=\"font-size: 14pt;\">5. Preferred Qualifications<\/span><\/h3>\n<ul data-spread=\"false\">\n<li>Experience in building a SOC from the ground up or operating an MSSP.<\/li>\n<li>Experience in deploying SIEM on AWS at scale.<\/li>\n<li>Experience with SOAR, Threat Intelligence, or Detection-as-Code.<\/li>\n<li>Experience applying AI\/GenAI to Monitoring, Alert Triage, Threat Hunting, or Incident Response.<\/li>\n<\/ul>\n<h2><span style=\"font-size: 18pt; color: #0000ff;\"><strong><span class=\"rnc2Gd\">Benefits:<\/span><\/strong><\/span><\/h2>\n<ul>\n<li>Competitive salary package (Base salary and performance bonuses).<\/li>\n<li>Probation period salary is 100% of the official salary.<\/li>\n<li>Comprehensive health and accident insurance.<\/li>\n<li>15 days of annual leave, 3 remote work days per month.<\/li>\n<li>Provision of work equipment (Macbook\/ Laptop, mouse, monitor, etc.).<\/li>\n<li>A creative and modern working environment.<\/li>\n<\/ul>\n<p><span style=\"color: #0000ff;\"><span style=\"font-weight: 400;\">Working location: <\/span><b>Galaxy Innovation Hub \u2013 D1 Hi Tech Park, Tang Nhon Phu Ward, HCMC<\/b><\/span><\/p>\n<p><span style=\"color: #0000ff;\"><span style=\"font-weight: 400;\">Kindly send your CV to: <\/span><b>talent@galaxyholdings.co\u00a0<\/b><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Key Responsibilities: Develop and drive the SOC, Threat Detection, and Incident Response strategy for systems and MSSP services. Design, implement, and operate the SIEM platform using the Elastic Stack (ELK), ensuring scalability, high performance, and high availability. Develop use cases, correlation rules, dashboards, alerts, and continuously optimize attack detection quality. Deploy and operate SIEM on [&hellip;]<\/p>\n","protected":false},"template":"","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","theme-transparent-header-meta":"default","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"set","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}}},"class_list":["post-15480","job","type-job","status-publish","hentry","company-galaxy-one","field-tech-en","job_type-full-time-en","location-ho-chi-minh"],"acf":[],"_links":{"self":[{"href":"https:\/\/galaxyholdings.co\/en\/wp-json\/wp\/v2\/job\/15480","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/galaxyholdings.co\/en\/wp-json\/wp\/v2\/job"}],"about":[{"href":"https:\/\/galaxyholdings.co\/en\/wp-json\/wp\/v2\/types\/job"}],"wp:attachment":[{"href":"https:\/\/galaxyholdings.co\/en\/wp-json\/wp\/v2\/media?parent=15480"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}