SOC Analyst (L1 / L2 / L3)
Join Provido Global as a SOC Analyst (L1–L3): monitor, triage, and investigate security events; collaborate with a diverse, global team; grow in a structured, shift-based SOC.
At Provido Global, we’re more than a technology company. We are a global hub of innovation, creativity, and engineering excellence.
Our teams design and deliver intelligent, secure, and high-performance digital solutions that help organizations modernize operations, scale their platforms, and succeed in an increasingly digital world.
As part of a dynamic international ecosystem, we bring together forward-thinking engineers, technology specialists, designers, and delivery professionals who transform ideas into scalable, real-world solutions with measurable business impact.
If you are motivated by challenge, inspired by technology, and ready to grow with a company that truly invests in its people, your journey starts here.
👉 Why We Need You
The SOC Analyst is responsible for security monitoring, alert triage, incident investigation, threat analysis, and escalation support within the Security Operations Center.
This role supports the protection of enterprise systems by identifying suspicious activity, analysing security events, documenting investigations, and coordinating response activities according to established procedures.
We are hiring SOC Analysts across multiple levels (L1, L2, and L3). The role level will be determined based on the candidate’s experience, technical capability, and hands-on exposure in cybersecurity operations.
The role is based on-site in Kuala Lumpur and is designed for candidates who can operate effectively in a structured, shift-based environment while coordinating with global teams to operate Security Operations in a Follow-the-Sun model.
👉 What You’ll Be Doing
SOC Analyst (L1)
Monitor security alerts and events across SIEM, endpoint, network, email, and cloud security tools.
Perform first-level triage to validate alerts, identify false positives, and determine whether escalation is required.
Escalate suspected or confirmed incidents to senior SOC analysts, incident responders, or relevant technical teams according to defined runbooks.
Document alerts, investigations, and response actions accurately in ticketing and case management systems for audit and reporting purposes.
Correlate logs and events from multiple sources to identify suspicious patterns, indicators of compromise, or repeated attack activity.
Support 24/7 monitoring operations through shift work, handovers, and adherence to service level expectations where applicable.
Communicate effectively in English when documenting incidents, coordinating with internal stakeholders, or supporting regional operations.
Maintain awareness of current threats affecting enterprise environments.
SOC Analyst (L2)
Monitor security alerts and events across SIEM, endpoint, network, email, and cloud security tools.
Perform L2 triage and investigation of security alerts, including validation, enrichment, impact assessment, containment recommendations, and escalation where required.
Escalate suspected or confirmed incidents to incident responders, platform owners, infrastructure teams, or business stakeholders according to defined runbooks and severity criteria.
Document investigations, response actions, evidence, and closure rationale accurately in ticketing and case management systems for audit, reporting, and knowledge management purposes.
Correlate logs and events from multiple sources to identify suspicious patterns, indicators of compromise, or repeated attack activity.
Administer and support security platforms by performing user access updates, configuration changes, log source onboarding, connector health checks, alert tuning, rule updates, dashboard maintenance, and operational troubleshooting.
Support 24/7 monitoring operations through shift work, handovers, and adherence to service level expectations where applicable.
Communicate effectively in English when documenting incidents, coordinating with internal stakeholders, and supporting regional or global security operations.
Maintain awareness of current threats affecting enterprise environments across financial services, retail, logistics, telecommunications, and other industries.
SOC Analyst (L3)
Lead advanced triage, investigation, and analysis of high-severity alerts and incidents across SIEM, endpoint, network, email, identity, and cloud security platforms.
Perform deep-dive log analysis, event correlation, threat hunting, and root-cause analysis to identify attack patterns, indicators of compromise, and control gaps.
Administer and maintain security platforms, including configuration updates, rule tuning, alert logic validation, data source onboarding, connector health checks, and access administration where applicable.
Develop, refine, and maintain detection use cases, correlation rules, dashboards, playbooks, standard operating procedures, and response runbooks.
Coordinate incident response activities with security engineering, infrastructure, cloud, network, identity, application, and business teams to ensure timely containment and remediation.
Provide technical guidance, quality review, and mentoring to L1 and L2 SOC analysts, including escalation review and investigation coaching.
Ensure accurate documentation of investigations, evidence, actions taken, lessons learned, and control recommendations in ticketing and case management systems for reporting and audit purposes.
Support 24/7 SOC operations through structured handovers, shift support, service level adherence, and collaboration with global teams operating in a Follow-The-Sun model.
👉 What You Bring to the Team
SOC Analyst (L1)
Bachelor’s degree or currently completed studies in Cybersecurity, Information Technology, Computer Science, Systems Engineering, or a related discipline.
2+ years of experience in cybersecurity, IT support, network operations, security monitoring, or a related technical role.
Basic understanding of networking, operating systems, identity and access concepts, and common cyber threats such as phishing, malware, and unauthorized access attempts.
Familiarity with SIEM platforms, endpoint detection tools, or log analysis concepts acquired through work experience, academic training, internships, or labs.
Ability to write clear incident notes, follow procedures consistently, and work effectively in a structured operational environment.
Working proficiency in English is strongly preferred to support multinational teams and stakeholders.
Availability to work on-site in Kuala Lumpur, Malaysia required.
SOC Analyst (L2)
Bachelor’s degree or currently completed studies in Cybersecurity, Information Technology, Computer Science, Systems Engineering, or a related discipline.
3–5 years of experience in cybersecurity operations, SOC monitoring, incident investigation, security engineering support, platform administration, or a related technical role.
Strong understanding of networking, operating systems, identity and access concepts, cloud services, attacker techniques, and common cyber threats such as phishing, malware, credential compromise, and unauthorized access attempts.
Hands-on experience with SIEM, EDR, email security, vulnerability management, cloud security, identity security, or case management platforms, including basic administration or operational support activities.
Ability to write clear investigation notes, follow runbooks, support detection tuning, maintain operational documentation, and work effectively in a structured security operations environment.
Working proficiency in English is strongly preferred to support multinational teams and stakeholders.
Availability to work on-site in Kuala Lumpur required.
SOC Analyst (L3)
Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Systems Engineering, or a related discipline, or equivalent practical experience.
5+ years of experience in cybersecurity operations, including hands-on SOC analyst experience with exposure to incident response, threat hunting, or detection engineering.
Practical experience administering or supporting security platforms such as SIEM, EDR/XDR, SOAR, email security gateways, cloud security tools, vulnerability management platforms, identity security tools, or network security monitoring solutions.
Strong understanding of security monitoring, cyber kill chain or MITRE ATT&CK techniques, incident response lifecycle, log analysis, endpoint telemetry, network protocols, authentication flows, and common attack methods.
Ability to tune alerts, validate detection logic, assess control effectiveness, and recommend improvements to monitoring coverage and response procedures.
Strong written and verbal communication skills, with the ability to document investigations clearly and brief technical and non-technical stakeholders.
Working proficiency in English is required to support multinational teams and stakeholders.
Availability to work on-site in Kuala Lumpur required.
👉 Preferred Skills
Professional certifications such as CompTIA Security+, CySA+, GCIA, GCIH, GCFA, CEH, SC-200, AZ-500, Microsoft Security Operations Analyst, or equivalent security operations credentials.
Hands-on experience with Microsoft Sentinel, Microsoft Defender XDR, Splunk, QRadar, CrowdStrike, Palo Alto, Fortinet, Proofpoint, Zscaler, or comparable enterprise security technologies.
Experience onboarding log sources, maintaining connectors, building dashboards, managing alert queues, integrating SOAR workflows, or supporting security platform upgrades.
Exposure to cloud security monitoring across Microsoft Azure, AWS, Google Cloud, or hybrid enterprise environments.
Experience working in regulated or compliance-focused environments with strong documentation, control adherence, evidence management, and audit support expectations.
Ability to mentor junior analysts, lead technical escalations, and contribute to continuous improvement of SOC processes, detection maturity, and operational reporting.
Experience supporting SOC, NOC, help desk, IT operations, or managed security environments.
Experience with use case development, alert rule tuning, automation playbooks, threat intelligence enrichment, log source integration, or platform health monitoring.
Understanding of compliance-focused environments and the importance of documentation, control adherence, and audit support.
Strong customer service mindset and the ability to coordinate professionally with internal users, technical teams, and business stakeholders.
👉 Why You’ll Love Working with Us
☐ Employee Benefits & Advantages
At Provido Global, we value our employees and nurture a culture of progress and creativity. Our team members enjoy a supportive, inclusive, and growth-focused environment.
☐ Competitive Compensation & Performance Incentives
Provido Global offers an attractive salary package and performance-based bonuses to recognize and reward your contribution.
☐ Flexible Working Options
We support remote and hybrid working models to help you maintain a healthy work-life balance.
☐ Health & Well-being Support
We provide comprehensive health insurance, wellness initiatives, and resources to support both physical and mental well-being.
☐ Career Advancement & Development Programs
We invest in continuous learning through training programs, mentorship, and clearly defined career development paths.
☐ Team-Oriented & Inclusive Workplace
Our culture is built on diversity, inclusion, and collaboration. Every voice matters and innovation is encouraged.
☐ Team Events & Social Activities
We organize regular team-building activities and social events to strengthen relationships and create a positive, connected workplace.
- Department
- Secuirty (GISD)
- Locations
- Malaysia
- Employment type
- Full-time
- Job Category
- Tech Job
About Provido Global
At PROVIDO GLOBAL, we don’t just deliver technology. We enable organizations to grow, adapt, and compete in a digital-first world.
As a modern IT and software development company, PROVIDO GLOBAL partners with businesses to turn complex challenges into scalable, secure, and high-impact digital solutions. From infrastructure and software engineering to UX-driven digital experiences and technical service delivery, our teams support the full technology lifecycle with precision and creativity.
We work side by side with our clients, combining deep technical expertise, industry best practices, and a practical delivery mindset. Whether you are building new systems, modernizing existing platforms, or strengthening operational resilience, PROVIDO GLOBAL provides the insight, execution, and long-term partnership needed to move your business forward.
At PROVIDO GLOBAL, innovation, reliability, and collaboration define how we work. We believe technology should not only function. It should create real business value.
Our core service areas include:
• Bespoke software and mobile application development
• Website and digital platform development
• Cloud-based solutions and system integration
• Security and cyber protection services
• IT advisory, technical support, and service delivery
• Quality assurance and testing
• Infrastructure and operations support
• UX/UI design and digital experience design
We deliver scalable solutions that improve operational efficiency, enhance user experience, and help organizations remain competitive in an evolving digital landscape.
At PROVIDO GLOBAL, we are equally committed to the people behind the technology.
We offer our team:
• Competitive compensation and performance-based incentives
• Flexible and hybrid working models that support work-life balance
• Health and well-being programs, including medical insurance and wellness initiatives
• Structured learning, development, and career growth opportunities
• A diverse, inclusive, and team-oriented culture where every voice matters
• Regular team events and social activities that strengthen collaboration and connection
PROVIDO GLOBAL is a place where professionals grow, ideas turn into solutions, and technology becomes a true business advantage.