en

Expertise

Our specialist consultants are experts across a range of disciplines, connecting you with the right talent for your permanent, temporary, contract, or interim jobs. Share your requirements and our experts will get in touch.

Submit a vacancy

Services

Taiwan's leading employers trust us to deliver talent solutions tailored to their exact requirements.

Browse our range of services
Expertise

Our specialist consultants are experts across a range of disciplines, connecting you with the right talent for your permanent, temporary, contract, or interim jobs. Share your requirements and our experts will get in touch.

Submit a vacancy
Jobs

Let our industry specialists listen to your aspirations and present your story to the most esteemed organisations in Taiwan, as we collaborate to write the next chapter of your successful career.

See all jobs
Services

Taiwan's leading employers trust us to deliver talent solutions tailored to their exact requirements.

Browse our range of services
Insights

Whether you’re seeking to hire talent or seeking a new career move for yourself, we have the latest facts, trends and inspiration you need.

See all resources
About Robert Walters Taiwan

For Robert Walters Taiwan, recruitment is more than just a job. We understand that behind every opportunity is the chance to make a difference to people’s lives

Learn more

Work for us

Our people are the difference. Hear stories from our people to learn more about a career at Robert Walters Taiwan.

Learn more

SOC Analyst (English is a must)

Save job

A leading global organisation is seeking a Senior Security Operations Centre Analyst (Tier 3) to join their highly skilled security operations team in Taiwan. You will play a crucial part in ensuring the organisation’s digital environment remains secure against evolving threats, and your expertise will be instrumental in supporting global security projects and audits such as ISO 27001, TISAX, and customer security assessments.

What you'll do:

As a Senior Security Operations Centre Analyst based in Taiwan, you will be at the heart of the organisation’s cyber defence strategy. Your daily responsibilities will involve responding to escalated incidents from the MDR provider with precision and empathy—leading containment efforts while collaborating closely with cross-functional teams. You will conduct comprehensive investigations across multiple platforms including endpoints, networks, identities, and cloud environments. Acting as incident commander during major events requires you to coordinate responses efficiently while maintaining clear communication with leadership. Beyond core SecOps duties, you will oversee MDR operations by validating triage quality and tuning detection mechanisms. Your expertise in threat hunting using KQL within Microsoft Sentinel will enable you to proactively identify risks. You’ll also contribute significantly to global security projects by supplying operational evidence for audits such as ISO 27001 or TISAX. Continuous improvement is central to this role; you’ll help refine SOC playbooks and mentor junior colleagues while sharing knowledge across the team.

  • Serve as the internal escalation point for incidents escalated by the Managed Detection and Response provider, ensuring thorough investigation and resolution.
  • Lead containment, eradication, and recovery activities for confirmed security incidents while coordinating cross-functional response efforts.
  • Conduct deep-dive investigations including root cause analysis and forensic review across endpoint, identity, network, and cloud environments.
  • Act as incident commander during significant events by running bridge calls, coordinating teams, and communicating status updates to management.
  • Produce clear documentation including incident reports and post-incident reviews to ensure transparency and learning from each event.
  • Manage day-to-day operational relationships with the MDR provider by reviewing escalations for quality, accuracy, completeness, and providing constructive feedback.
  • Partner with management on quarterly business reviews (QBRs), service level agreement (SLA) reviews, and tuning detection services for optimal performance.
  • Perform proactive threat hunts using KQL in Microsoft Sentinel and Defender XDR to identify emerging risks before they escalate.
  • Develop custom detection rules, analytics, correlation logic in Sentinel to reduce false positives and improve alert fidelity both internally and within MDR rule sets.
  • Support global security projects by providing operational evidence, control validation, log extracts, audit narratives for ISO 27001, TISAX, customer audits; participate in tabletop exercises and purple team engagements.

What you bring:

To excel as a Senior Security Operations Centre Analyst in this organisation’s global team based in Taiwan, you will bring proven experience from previous roles within SOC environments where you handled escalated incidents requiring deep investigation skills. Your technical background includes hands-on work with Microsoft Sentinel/Defender XDR platforms—enabling you to write effective KQL queries for hunting threats or tuning detections. You understand network protocols thoroughly along with operating system internals across Windows/Linux/macOS platforms. Experience working alongside MDR providers means you can manage operational relationships constructively—reviewing escalations critically while ensuring business context is understood. Familiarity with cloud security fundamentals (Azure/M365 preferred) allows you to adapt quickly within hybrid environments; additional exposure to AWS/GCP is beneficial but not essential. Your knowledge extends into identity/access management systems such as Entra ID/Active Directory plus frameworks like MITRE ATT&CK which inform your approach to threat intelligence correlation. Strong interpersonal skills are vital—you communicate clearly whether documenting incidents or mentoring junior colleagues—and your willingness to participate in on-call rotations demonstrates reliability within a globally distributed team.

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity or equivalent hands-on experience demonstrating technical proficiency.
  • At least three years of experience in a Security Operations Centre or similar security operations role handling escalated incidents and complex investigations.
  • Hands-on expertise with Microsoft Sentinel and Microsoft Defender XDR covering endpoint protection, identity management, cloud security monitoring.
  • Proficiency writing KQL (Kusto Query Language) for threat hunting, investigation workflows, detection tuning within enterprise environments.
  • Experience managing relationships with MDR/MSSP providers including receiving escalations, providing feedback on triage quality or missed context.
  • Solid understanding of TCP/IP networking protocols such as DNS or HTTP/S alongside Windows/Linux/macOS OS internals and logging practices.
  • Familiarity with cloud security fundamentals especially Azure or M365; AWS/GCP experience is considered advantageous.
  • Knowledge of identity/access management systems like Entra ID/Active Directory plus working familiarity with MITRE ATT&CK framework or cyber kill chain concepts.
  • Strong analytical skills paired with excellent written/verbal communication abilities enabling effective collaboration across global teams.
  • Ability to participate in on-call rotation for major incidents ensuring dependable coverage across time zones.

Contract Type: Perm

Specialism: IT & Digital Transformation

Focus: IT Security/IT Governance

Industry: IT

Salary: Negotiable

Workplace Type: On-site

Experience Level: Associate

Location: Taipei

Job Reference: J9RQUA-695F6B0A

Date posted: 4 August 2026

Consultant: Amy Lin