Назад
Company hidden
обновлено 8 часов назад

Detection Engineer/Cyber Incident Responder (SOC)

Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Singapore
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Detection Engineer/Cyber Incident Responder (SOC) (Cybersecurity): Designing and implementing security detection use cases, investigating incidents, and strengthening a 24/7 regional SOC with an accent on MITRE ATT&CK mapping, SIEM content development, and threat hunting. Focus on translating emerging threats into detection logic, leading investigations from triage through remediation, and reducing false positives through continuous tuning.

Location: Singapore; permanent onsite position

Company

hirify.global is an independent technology consulting firm providing technology guidance and solutions to businesses through an international team across more than 60 countries.

What you will do

  • Define, design, implement, and continuously enrich security use cases mapped to the MITRE ATT&CK framework.
  • Research emerging threats and translate attack scenarios, indicators of compromise, and adversary tactics into detection logic.
  • Tune detection content to reduce false positives and improve detection fidelity.
  • Lead incident investigations from triage and impact assessment through root cause analysis, containment, remediation, and closure.
  • Conduct proactive threat hunting and coordinate incident response with technical, regional, and global stakeholders.
  • Improve 24/7 SOC capabilities, playbooks, operational procedures, reporting, and compliance controls.

Requirements

  • 7+ years of overall cybersecurity experience, including incident response and security operations.
  • 4+ years of experience designing security use cases, developing detection content, and coding detection logic.
  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field.
  • Working knowledge of Java or a similar language, Linux, TCP/IP, authentication, Windows Event IDs, and Kerberos.
  • Hands-on experience with a SIEM platform such as Elastic/ELK, Splunk, QRadar, Sentinel, or ArcSight.
  • Strong understanding of MITRE ATT&CK, adversary TTPs, large dataset analysis, and detection-content automation.

Nice to have

  • Experience with ELK, including Elastic, Logstash, and Kibana.
  • Scripting and automation skills in Python, PowerShell, Bash, or SQL.
  • SANS, CISSP, OSCP, or equivalent certification.
  • French language proficiency.

Culture & Benefits

  • International community representing more than 110 nationalities.
  • Internal Academy with more than 250 training modules.
  • Regular internal events, including afterworks and team-building activities.
  • Opportunities to contribute to sustainability and social or environmental impact projects through the WeCare Together program.

Hiring process

  • Brief virtual or phone conversation.
  • Approximately three interviews, adjusted according to seniority.
  • Potential case study, technical assessment, role play, or problem-solving exercise.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →