HK Senior Detection and Response Engineer
Summary
Senior Detection and Response Engineer designs and implements security detection use cases, hunts threats, and leads incident response for a regional SOC using frameworks like MITRE ATT&CK and SIEM tools.
- Lead technical activities (security usecase definition, design, implementation & enrichment) in the team of IT Production Security Investigation & Incident Response based on real-world attack scenarios and framework like MITRE ATT&CK, ensuring robust security detection posture across various layers.
- Understand ongoing security threats in the wild and propose security usecase to detect and when possible, protect or mitigate.
- Be autonomous on technical activities (definition, R&D/threat hunting) in the team of IT Production Security Investigation & Incident Response and oversee the detection capabilities of the 24/7 regional IT Production SOC
- Respond to Cyber / IT security incidents and evaluates the type and severity of security events.
- Identify recurring security issues and risks and develops mitigation plans and recommends process improvements.
- Partner with global, regional and local stakeholders to ensure organizational and procedural efficiency and readiness for detection of suspicious events and reaction
- Continuously improve the processes to strengthen the current SOC framework via review of policies and operational playbooks
Contributing Responsibilities:
- Partner with the APAC Business CSIRT for integrated security monitoring and alert/incident handling operations.
- Contribute to local security incident response outside the direct scope of responsibilities (i.e.,local IT production in some APAC business entities)
- Contribute to the Bank compliance with regulatory requirements and internal policies
- Contribute to the reporting of all incidents according to the Incident Management System
- Contribute to the control frameworks in day‐to‐day business activities, such as Control Plan;
- Participate to Audit interview and provide the require evidence
- Requires a minimum of 7 or more years of experience as security professional
- Experience in security usecase design/development with understanding of Java language.
- Good working knowledge of Linux (RedHat/Ubuntu).
- Working knowledge to interpret security logs or instructions into threat models. SecOPS-DevOPS mindset & skills.
- Experience and knowledge in investigating incidents, remediation, tracking and follow-up for incident closure with concerned teams, stakeholders.
- Thorough understanding of technologies and security concepts, with knowledge & hands on experience in SIEM Product and Security Incident Management
- Experience on incident response activities (threat hunting, event analysis, incident investigation, reporting)
- Comfortable working with and making the most of large data sets (collection, analysis, response), creating content/use cases/models and bringing an automation mindset.
Qualifications:
- Candidate MUST have 7 or more years of experience on overall cybersecurity incident response with 4+ years specifically on security usecase design, development, coding
- Experience in common scripting languages such as Python, PowerShell, Bash, SQL
- Experience in SIEM on ELK(Elastic Logstash Kibana) stack is a plus
- Professional credentials in one of the relevant IT Security disciplines is a plus (SANS / CISSP / OSCP)
•Work-life balance: Hybrid working mode and Work-from-Abroad benefits, 18 days of Annual leave
•Health & insurance: Comprehensive coverage including General Practitioner, hospitalization
•Performance incentives: Annual bonus based on individual performance
•Learning & development: Training programs, certification opportunities, and training incentives to support career growth