обновлено 8 часов назад
Detection Engineer/Cyber Incident Responder (SOC)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Detection Engineer/Cyber Incident Responder (SOC) (Cybersecurity): Designing and implementing security detection use cases, investigating incidents, and strengthening a 24/7 regional SOC with an accent on MITRE ATT&CK mapping, SIEM content development, and threat hunting. Focus on translating emerging threats into detection logic, leading investigations from triage through remediation, and reducing false positives through continuous tuning.
Location: Singapore; permanent onsite position
Company
is an independent technology consulting firm providing technology guidance and solutions to businesses through an international team across more than 60 countries.
What you will do
- Define, design, implement, and continuously enrich security use cases mapped to the MITRE ATT&CK framework.
- Research emerging threats and translate attack scenarios, indicators of compromise, and adversary tactics into detection logic.
- Tune detection content to reduce false positives and improve detection fidelity.
- Lead incident investigations from triage and impact assessment through root cause analysis, containment, remediation, and closure.
- Conduct proactive threat hunting and coordinate incident response with technical, regional, and global stakeholders.
- Improve 24/7 SOC capabilities, playbooks, operational procedures, reporting, and compliance controls.
Requirements
- 7+ years of overall cybersecurity experience, including incident response and security operations.
- 4+ years of experience designing security use cases, developing detection content, and coding detection logic.
- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field.
- Working knowledge of Java or a similar language, Linux, TCP/IP, authentication, Windows Event IDs, and Kerberos.
- Hands-on experience with a SIEM platform such as Elastic/ELK, Splunk, QRadar, Sentinel, or ArcSight.
- Strong understanding of MITRE ATT&CK, adversary TTPs, large dataset analysis, and detection-content automation.
Nice to have
- Experience with ELK, including Elastic, Logstash, and Kibana.
- Scripting and automation skills in Python, PowerShell, Bash, or SQL.
- SANS, CISSP, OSCP, or equivalent certification.
- French language proficiency.
Culture & Benefits
- International community representing more than 110 nationalities.
- Internal Academy with more than 250 training modules.
- Regular internal events, including afterworks and team-building activities.
- Opportunities to contribute to sustainability and social or environmental impact projects through the WeCare Together program.
Hiring process
- Brief virtual or phone conversation.
- Approximately three interviews, adjusted according to seniority.
- Potential case study, technical assessment, role play, or problem-solving exercise.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
2 часа назад
Cybersecurity Engineer
5 дней назад
Cybersecurity Architect (CyberArk)
6 дней назад
Information Security Analyst (Cybersecurity)
12 часов назад
Sr Platform Security Engineer (Zero Trust and Platform Security)
4 дня назад
Sr. Security Engineer (Cybersecurity)
155 000 - 187 000$
14 часов назад