Security Detection & SIEM Engineer
About the Role
Join our security team and help strengthen how we identify, investigate and respond to security threats. You will work hands-on with security alerts, logs, detection rules and vulnerability findings, turning technical evidence into clear and actionable outcomes.
What You’ll Do
- Manage daily SIEM operations and security monitoring activities.
- Investigate security alerts and cases through TheHive, including evidence review, analysis, documentation and case handling.
- Analyse CVE findings, identify affected systems and potential impact, and coordinate remediation tracking and follow-up.
- Tune and maintain security detection rules and basic correlation logic to improve detection effectiveness.
- Investigate security incidents and determine the appropriate escalation or case closure.
- Analyse suspicious commands, logs, scripts and system activities, validating findings before reaching conclusions.
- Prepare security monitoring reports, metrics, dashboards and operational summaries.
- Work with infrastructure and application teams to support incident handling and continuous improvement.
What We’re Looking For (Must Have)
- Bachelor’s degree inInformation Security, Cybersecurity, Computer Science or a related field.
- At least 3 years of relevant experience in SIEM operations, security monitoring, security analysis or security engineering.
- Hands-on experience with SIEM, log management or security monitoring platforms.
- Hands-on OpenSearch experience covering log queries, log analysis, security event investigation and basic index management.
- Strong knowledge of Linux andWindows administration fundamentals and security log analysis.
- Practical experience insecurity event investigation, incident analysis and detection tuning.
- Strong analytical, troubleshooting and problem-solving skills, with the ability to investigate unfamiliar technical behaviour independently.
- Effective communication inEnglish and Mandarin, as the role works with regional stakeholders who primarily communicate in these languages.
Good to Have
- Experience using TheHive for alert or case investigation.
- Familiarity with event correlation, behavioural analysis and detection engineering concepts.
- Experience in CVE analysis and vulnerability remediation tracking.
- Python, Shell scripting or security automation experience.