zh

服務項目

我們為企業量身打造招募解決方案,以其快速、有效深受臺灣頂尖企業信賴。瀏覽由Robert Walters臺灣提供的各種客製化服務與資源。

探索更多

聯繫我們

真正具有國際視野並深耕在地市場的招募機構,我們服務臺灣市場超過 10 年,並在臺北設有完善的辦公室。

聯繫我們
職缺

我們各領域的專業顧問會用心聆聽您的理想與抱負,並與臺灣知名企業、機構分享您的職涯故事。

讓我們的團隊與您攜手開啟職涯的下一個精彩篇章。

瀏覽全部職缺
服務項目

我們為企業量身打造招募解決方案,以其快速、有效深受臺灣頂尖企業信賴。瀏覽由Robert Walters臺灣提供的各種客製化服務與資源。

探索更多
關於Robert Walters臺灣

在Robert Walters臺灣,招募絕不僅是一份工作。

我們明白,每個機會的背後都是改變人們生活的可能性。

探索更多

加入我們

人永遠是企業的核心,也是Robert Walters與眾不同之處,了解更多關於臺灣團隊的故事,加入我們讓職涯更進一步。

探索更多
聯繫我們

真正具有國際視野並深耕在地市場的招募機構,我們服務臺灣市場超過 10 年,並在臺北設有完善的辦公室。

聯繫我們

SOC Analyst (English is a must)

已收藏的職缺

A leading global organisation is seeking a Senior Security Operations Centre Analyst (Tier 3) to join their highly skilled security operations team in Taiwan. You will play a crucial part in ensuring the organisation’s digital environment remains secure against evolving threats, and your expertise will be instrumental in supporting global security projects and audits such as ISO 27001, TISAX, and customer security assessments.

What you'll do:

As a Senior Security Operations Centre Analyst based in Taiwan, you will be at the heart of the organisation’s cyber defence strategy. Your daily responsibilities will involve responding to escalated incidents from the MDR provider with precision and empathy—leading containment efforts while collaborating closely with cross-functional teams. You will conduct comprehensive investigations across multiple platforms including endpoints, networks, identities, and cloud environments. Acting as incident commander during major events requires you to coordinate responses efficiently while maintaining clear communication with leadership. Beyond core SecOps duties, you will oversee MDR operations by validating triage quality and tuning detection mechanisms. Your expertise in threat hunting using KQL within Microsoft Sentinel will enable you to proactively identify risks. You’ll also contribute significantly to global security projects by supplying operational evidence for audits such as ISO 27001 or TISAX. Continuous improvement is central to this role; you’ll help refine SOC playbooks and mentor junior colleagues while sharing knowledge across the team.

  • Serve as the internal escalation point for incidents escalated by the Managed Detection and Response provider, ensuring thorough investigation and resolution.
  • Lead containment, eradication, and recovery activities for confirmed security incidents while coordinating cross-functional response efforts.
  • Conduct deep-dive investigations including root cause analysis and forensic review across endpoint, identity, network, and cloud environments.
  • Act as incident commander during significant events by running bridge calls, coordinating teams, and communicating status updates to management.
  • Produce clear documentation including incident reports and post-incident reviews to ensure transparency and learning from each event.
  • Manage day-to-day operational relationships with the MDR provider by reviewing escalations for quality, accuracy, completeness, and providing constructive feedback.
  • Partner with management on quarterly business reviews (QBRs), service level agreement (SLA) reviews, and tuning detection services for optimal performance.
  • Perform proactive threat hunts using KQL in Microsoft Sentinel and Defender XDR to identify emerging risks before they escalate.
  • Develop custom detection rules, analytics, correlation logic in Sentinel to reduce false positives and improve alert fidelity both internally and within MDR rule sets.
  • Support global security projects by providing operational evidence, control validation, log extracts, audit narratives for ISO 27001, TISAX, customer audits; participate in tabletop exercises and purple team engagements.

What you bring:

To excel as a Senior Security Operations Centre Analyst in this organisation’s global team based in Taiwan, you will bring proven experience from previous roles within SOC environments where you handled escalated incidents requiring deep investigation skills. Your technical background includes hands-on work with Microsoft Sentinel/Defender XDR platforms—enabling you to write effective KQL queries for hunting threats or tuning detections. You understand network protocols thoroughly along with operating system internals across Windows/Linux/macOS platforms. Experience working alongside MDR providers means you can manage operational relationships constructively—reviewing escalations critically while ensuring business context is understood. Familiarity with cloud security fundamentals (Azure/M365 preferred) allows you to adapt quickly within hybrid environments; additional exposure to AWS/GCP is beneficial but not essential. Your knowledge extends into identity/access management systems such as Entra ID/Active Directory plus frameworks like MITRE ATT&CK which inform your approach to threat intelligence correlation. Strong interpersonal skills are vital—you communicate clearly whether documenting incidents or mentoring junior colleagues—and your willingness to participate in on-call rotations demonstrates reliability within a globally distributed team.

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity or equivalent hands-on experience demonstrating technical proficiency.
  • At least three years of experience in a Security Operations Centre or similar security operations role handling escalated incidents and complex investigations.
  • Hands-on expertise with Microsoft Sentinel and Microsoft Defender XDR covering endpoint protection, identity management, cloud security monitoring.
  • Proficiency writing KQL (Kusto Query Language) for threat hunting, investigation workflows, detection tuning within enterprise environments.
  • Experience managing relationships with MDR/MSSP providers including receiving escalations, providing feedback on triage quality or missed context.
  • Solid understanding of TCP/IP networking protocols such as DNS or HTTP/S alongside Windows/Linux/macOS OS internals and logging practices.
  • Familiarity with cloud security fundamentals especially Azure or M365; AWS/GCP experience is considered advantageous.
  • Knowledge of identity/access management systems like Entra ID/Active Directory plus working familiarity with MITRE ATT&CK framework or cyber kill chain concepts.
  • Strong analytical skills paired with excellent written/verbal communication abilities enabling effective collaboration across global teams.
  • Ability to participate in on-call rotation for major incidents ensuring dependable coverage across time zones.

招募類型: 永久性

專業領域: 資訊科技及數位轉型

職務類別: 資安技術/資安管理

產業: 資訊技術

薪資: Negotiable

辦公模式: 實體辦公模式

經驗: 專員

地區 Taipei

職務參考: J9RQUA-695F6B0A

發佈日期: 2026年8月4日

獵頭顧問 Amy Lin

已收藏的職缺

分享