обновлено 1 месяц назад
HK Senior Detection and Response Engineer (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Detection and Response Engineer (Cybersecurity): Designing, implementing, and improving security detection use cases and incident response capabilities for a regional IT production SOC with an accent on MITRE ATT&CK, SIEM, threat hunting, and security automation. Focus on investigating cyber incidents, analyzing large security datasets, developing detection content, and strengthening SOC processes and operational playbooks.
Location: Hong Kong; hybrid working mode
Company
is a European technology group providing consulting, digital services, software, infrastructure, cloud, and cybersecurity services across Europe, North America, and Asia. The Hong Kong entity operates with Singapore to support clients across the Asia Pacific region.
What you will do
- Lead the definition, design, implementation, and enrichment of security detection use cases based on real-world attack scenarios and the MITRE ATT&CK framework.
- Monitor evolving threats and develop detection, protection, and mitigation approaches across multiple technology layers.
- Oversee detection capabilities for the 24/7 regional IT Production SOC and conduct threat hunting and research.
- Respond to cyber and IT security incidents, assess event severity, investigate root causes, and coordinate remediation through closure.
- Partner with APAC CSIRT and global, regional, and local stakeholders on alert handling, incident response, compliance, audits, and reporting.
- Improve SOC policies, operational playbooks, control frameworks, and processes for detecting and responding to suspicious activity.
Requirements
- 7+ years of overall cybersecurity incident response or security professional experience, including 4+ years in security use-case design, development, and coding.
- Experience developing security use cases and understanding Java.
- Working knowledge of Linux, including Red Hat and Ubuntu.
- Experience with SIEM platforms, security incident management, security log interpretation, threat modeling, and incident investigation.
- Experience with Python, PowerShell, Bash, and SQL scripting.
- Ability to work with large datasets, create detection content and models, and apply a SecOps-DevOps and automation mindset.
Nice to have
- Experience with the ELK stack: Elasticsearch, Logstash, and Kibana.
- Relevant security certifications such as SANS, CISSP, or OSCP.
Culture & Benefits
- Hybrid working mode with work-from-abroad benefits.
- 18 days of annual leave.
- Health insurance covering general practitioner and hospitalization services.
- Annual performance-based bonus.
- Training programs, certification opportunities, and learning incentives.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →