← back to jobs
> job detail
T
👽Other

DFIR Specialist / Senior SOC Analyst (Malaysia)

Theos ·
// classified as
Other (Adjacent or hard to classify.)
posted
1d ago
location
languages
tools
aws, azure
> stack
awsazure
> description

DFIR Specialist / Senior SOC Analyst

Manila | Kuala Lumpur | Hong Kong | Singapore | APAC Remote


Our Mission


Our mission is to empower businesses to thrive in the digital security age by defining and executing practical strategies that build true cyber resilience. At Theos, security is not an afterthought. It is our foundation. We believe in disciplined execution over silver bullets, and real outcomes over noise.


Who We Are


Theos is a cybersecurity company delivering premium services across Asia and beyond. We support SMEs and enterprises with capabilities traditionally reserved for global Tier-1 firms, spanning Penetration Testing, Red Teaming, Managed Detection and Response, and Digital Forensics and Incident Response. We combine deep technical capability with commercial discipline and operational maturity.


Our culture is grounded in five core values: Security as Our Foundation; Global Collaboration and Respect; Embrace Change and Innovate; Integrity and Accountability; and Strive for Excellence.


As we grow, we are building a culture that moves from heroics to process, from reaction to discipline, and from surviving to thriving. We value ownership, clarity, execution, and people who continuously raise the standard for themselves, their teams, and our clients.


Job Summary


As a DFIR Specialist / Senior SOC Analyst at Theos, you will lead client-facing engagements across the full incident response lifecycle. You will work closely with diverse customers and senior stakeholders to deliver critical outcomes and guide organisations through complex investigations.


Your role will be central to managing engagements, containing security incidents with precision, and providing clear, actionable remediation plans that strengthen client resilience and enhance overall security posture.


Key Responsibilities


  •  Lead end-to-end incident response engagements, guiding clients through investigation, containment, and long-term remediation across business email compromise (BEC), ransomware, data breaches, insider threats, and compromise assessment cases.
  •  Conduct forensic analysis across cloud, Windows, Linux, and macOS environments, including network traffic and log data from web application firewalls, firewalls, endpoints, cloud platforms, and applications.
  •  Use tools such as CrowdStrike, FTK, next-generation SIEM platforms, and Magnet AXIOM to identify indicators of compromise (IOCs), threat-actor tactics, techniques, and procedures (TTPs), root cause, and scope of impact.
  •  Collaborate with clients and internal stakeholders to communicate findings, provide timely updates, and deliver comprehensive reports.
  •  Mentor junior staff and share expertise in incident response and digital forensics best practices.
  •  Maintain awareness of the evolving threat landscape, including emerging AI- and large language model-related threats.
  •  Improve playbooks, methodologies, and tooling, including artefact collectors and parsers, and feed lessons from live engagements back into processes and automation.
  •  Travel as required, approximately 5%, to support client and business needs through on-site engagements.


Qualifications


- Required Qualifications


  •  Bachelor's degree in Information Security, Computer Science, Digital Forensics, Cybersecurity, or a related discipline, or equivalent professional experience.
  •  Experience administering, monitoring, or investigating cloud platforms such as Microsoft Azure, AWS, Google Workspace, or Alibaba Cloud.
  •  Minimum of four years of direct experience in cybersecurity operations.
  •  Strong proficiency in rapid incident response, creative problem-solving, and report writing.
  •  An investigative mindset, with an interest in solving complex problems, learning new techniques, and continuously improving.


- Preferred Qualifications


  •  Prior experience in a client-facing incident response consulting role.
  •  Direct experience in incident response and/or digital forensics, with practical experience using forensic and incident response tools.
  •  Prior experience developing and delivering tabletop exercises.
  •  Strong executive presence, with the ability to present complex technical findings to C-level stakeholders.
  •  Proven ability to build collaborative relationships with internal teams, external partners, and clients.


About Your Application


We aim to provide a clear and efficient hiring process. To support your application, please include your expected annual compensation in your local currency and your availability or notice period. Work authorisation requirements may vary by location and will be discussed as part of the process.