Cyber Incident Responder
Summary
Cybersecurity expert designs and enhances detection use cases, responds to incidents, and strengthens monitoring for a regional SOC in a financial services context.
Position Purpose
We are looking for a Cybersecurity expert/SME in Detection Engineering and Security Investigation areas, as part of the Production SOC, Security Investigation and Incident Response team.
Your role will be to:
- Strengthen detection capabilities across APAC and contribute to the global use case development programme to ensure alignment of security detection use cases.
- Contribute to the enhancement of SIEM and SOAR capabilities.
- Act as a reference point within a team of experts on Security Incident Response, Anti-Malware/Defense and Security Detection activities.
- Oversee detection capabilities supporting the regional IT Production SOC.
- Participate in the continuous improvement of tools and processes relating to Security Incident Management, Anti-Malware/Defense and Security Detection.
- Collaborate with regional security teams to strengthen security monitoring and incident response capabilities.
Key Responsibilities
Direct Responsibilities
- Lead technical activities (security usecase definition, design, implementation & enrichment) in the team of IT Production Security Investigation & Incident Response based on real-world attack scenarios and framework like MITRE ATT&CK, ensuring robust security detection posture across various layers.
- Understand ongoing security threats in the wild and propose security usecase to detect and when possible, protect or mitigate.
- Be autonomous on technical activities (definition, R&D/threat hunting) in the team of IT Production Security Investigation & Incident Response and oversee the detection capabilities of the 24/7 regional IT Production SOC
- Respond to Cyber / IT security incidents and evaluates the type and severity of security events.
- Identify recurring security issues and risks and develops mitigation plans and recommends process improvements.
- Partner with global, regional and local stakeholders to ensure organizational and procedural efficiency and readiness for detection of suspicious events and reaction
- Continuously improve the processes to strengthen the current SOC framework via review of policies and operational playbooks
Contributing Responsibilities
- Partner with the APAC Business CSIRT for integrated security monitoring and alert/incident handling operations.
- Contribute to local security incident response outside the direct scope of responsibilities (i.e., local IT production in some APAC business entities)
- Contribute to the Bank compliance with regulatory requirements and internal policies
- Contribute to the reporting of all incidents according to the Incident Management System
- Contribute to the control frameworks in day‐to‐day business activities, such as Control Plan; Participate to Audit interview and provide the require evidence.
Competencies (Technical / Behavioural)
Role Specific Technical Skills
- Requires roughly 7 years of experience as a cybersecurity professional.
- Strong experience in security use case design, development and enhancement within security monitoring and incident response environments.
- Strong hands-on experience with Python and JavaScript.
- Good working knowledge of Linux (RedHat/Ubuntu).
- Ability to interpret security logs, attack patterns and threat intelligence into detection logic and actionable security use cases.
- Strong SecOps / DevOps mindset with experience building security automation and operational tooling.
- Experience and knowledge in investigating incidents, remediation, tracking and follow-up for incident closure with concerned teams, stakeholders.
- Thorough understanding of technologies and security concepts, with knowledge & hands on experience in SIEM Product and Security Incident Management
- Strong L3 experience in incident response activities including threat hunting, event analysis, incident investigation and reporting.
- Comfortable working with and making the most of large data sets (collection, analysis, response), creating content/use cases/models and bringing an automation mindset.
Personal Attributes
- Strong problem-solving skills.
- Good communication skills.
- Positive attitude with a willingness to learn and perform in-depth technical investigations.
- Ability to work independently, think critically and take initiative.
- Strong interpersonal and teamwork skills.
- High level of accountability and ownership.
- Ability to manage multiple priorities and deliver within agreed timelines.
Specific Preferred Qualifications
- Minimum 7 years of cybersecurity experience with a strong focus on Security Operations, Incident Response, Threat Detection or Detection Engineering.
- Proven experience operating at an L3 Incident Response level.
- Minimum 4 years of experience in security use case design, development, coding and detection engineering activities.
- Hands-on experience developing and maintaining custom security use cases and detection content.
- Strong working knowledge of both Python and JavaScript is mandatory.
- Experience working with on-premises security environments and customised security tooling.
- Experience with ELK (Elastic, Logstash, Kibana) is highly desirable.
- Banking or financial services experience is advantageous.
- Professional credentials in one of the relevant IT Security disciplines is a plus (SANS / CISSP / OSCP)
- Experience in common scripting languages such as PowerShell, Bash, SQL is a plus
We regret to inform that only shortlisted candidates will be notified.
EA registration number : Ng Xuan, R24123530
Allegis Group Singapore Pte Ltd, Company Reg No. 200909448N, EA Licence No. 10C4544