Senior Security Analysis Engineer
About the Role
We are looking for an experienced security professional to lead complex investigations and advance our detection capabilities. You will design detection mechanisms, solve challenging security monitoring issues and guide other engineers through complex technical analysis.
What You’ll Do
- Design, develop and optimise security detection mechanisms to improve coverage and effectiveness.
- Lead complex incident investigations by correlating logs, system activities, commands, scripts and other evidence.
- Design and maintain detection rules, correlation logic and behavioural detection mechanisms.
- Serve as the technical escalation point for complex incidents and security monitoring issues.
- Research, evaluate, design and implement new SIEM, monitoring and security analysis capabilities.
- Drive continuous improvement across security detection, monitoring and analysis.
- Provide technical guidance toSIEM Engineers during complex investigations and detection-related work.
What We’re Looking For (Must Have)
- Bachelor’s degree inInformation Security, Cybersecurity, Computer Science or a related field.
- At least 5 years of relevant experience in security monitoring, SIEM, detection engineering, security analysis or security engineering.
- Strong hands-on experience with open-source SIEM platforms, security event investigation, log analysis, event correlation and detection engineering.
- Strong knowledge of Linux andWindows systems, security logs, system activities and security event analysis.
- Proven experience leading complex incident investigations and developing detection rules, correlation logic or behavioural analytics.
- Strong analytical, troubleshooting and problem-solving skills, including independent investigation of unfamiliar technologies, commands, logs and scripts.
- Strong communication and technical documentation skills, with the ability to guide other engineers.
- Effective communication inEnglish and Mandarin, as the role works with regional stakeholders who primarily communicate in these languages.
Good to Have
- Python, Shell scripting or automation experience applied to security analysis or detection development.
- Experience researching, evaluating and implementing new SIEM or security monitoring technologies.
- Experience acting as at technical escalation point or mentoring security engineers.
- Experience improving detection coverage, investigation workflows or security monitoring processes across an enterprise environment.