5 дней назад
HK Senior Detection and Response Engineer (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
HK Senior Detection and Response Engineer (Cybersecurity): Designing and implementing security detection use cases and incident response capabilities for a regional security operations center with an accent on MITRE ATT&CK, threat hunting, SIEM, and large-scale security data analysis. Focus on investigating cyber incidents, developing detection content and automation, improving SOC playbooks, and coordinating response across APAC stakeholders.
Location: Hong Kong; hybrid working mode
Company
is a listed European technology company providing consulting, digital services, software, infrastructure, cloud, and cybersecurity services across Europe, North America, and Asia.
What you will do
- Lead the definition, design, implementation, and enrichment of security detection use cases based on real-world attack scenarios and the MITRE ATT&CK framework.
- Develop threat detection capabilities and oversee detection operations for a 24/7 regional IT Production SOC.
- Investigate cyber and IT security incidents, assess event severity, and coordinate remediation and closure.
- Conduct threat hunting, security research, event analysis, and detection content development across large security datasets.
- Improve SOC policies, operational playbooks, incident reporting, control frameworks, and audit readiness.
- Partner with APAC CSIRT and global, regional, and local stakeholders on monitoring and incident response.
Requirements
- At least 7 years of overall cybersecurity incident response experience, including 4+ years in security use-case design, development, and coding.
- Experience with security use-case development and understanding of Java.
- Working knowledge of Linux, including Red Hat and Ubuntu.
- Experience with SIEM platforms, security incident management, incident investigation, remediation, and reporting.
- Experience with Python, PowerShell, Bash, and SQL scripting.
- Ability to interpret security logs, develop threat models, work with large datasets, and apply a SecOps-DevOps and automation mindset.
Nice to have
- Experience with the ELK stack: Elastic, Logstash, and Kibana.
- Professional security certifications such as SANS, CISSP, or OSCP.
Culture & Benefits
- Hybrid working mode with work-from-abroad benefits.
- 18 days of annual leave.
- Comprehensive health and insurance coverage, including general practitioner and hospitalization benefits.
- Annual performance-based bonus.
- Training programs, certification opportunities, and learning incentives.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →