20 часов назад
Senior Security Analyst (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Security Analyst (Cybersecurity): Leading technical investigations of security alerts and incidents across SIEM, EDR/XDR, cloud, identity, network, and endpoint telemetry with an accent on incident escalation, detection engineering, and vulnerability validation. Focus on correlating complex security events, applying the MITRE ATT&CK framework, reducing false positives, and improving SOC investigation processes.
Location: Singapore, Singapore; hybrid work with work-from-home up to 2 days per week depending on team needs
Company
provides technology and communications solutions for airports, airlines, borders, and the global air travel industry.
What you will do
- Act as the primary escalation point for SOC Analysts during security investigations.
- Lead technical investigations of security alerts and incidents across SIEM, EDR/XDR, cloud, identity, network, and endpoint telemetry.
- Validate alert classification, severity, scope, and escalation decisions; build investigation timelines and document evidence.
- Escalate confirmed or suspected incidents to the SIRT team and collaborate with technical stakeholders.
- Develop and tune detection rules, correlation logic, SOC use cases, and investigation playbooks to reduce false positives.
- Mentor SOC Analysts, review investigation quality, produce reports and metrics, and support vulnerability validation and remediation.
Requirements
- 3–5 years of experience as a SOC L2 Analyst or in an equivalent Security Operations role.
- Advanced experience investigating security events with SIEM and EDR/XDR platforms, preferably Elastic, Palo Alto Cortex XDR, Microsoft Defender XDR, or CrowdStrike Falcon.
- Experience analyzing endpoint, identity, cloud, firewall, proxy, DNS, VPN, and application logs.
- Proficiency with KQL, Lucene, EQL, and Sigma; working knowledge of PowerShell and/or Python.
- Strong knowledge of Windows, Linux, Active Directory, Microsoft 365, Azure/AWS, networking, common attack techniques, and MITRE ATT&CK.
- Bachelor’s degree in IT, Cybersecurity, Computer Science, or a related field, plus at least one recognized cybersecurity certification.
Culture & Benefits
- Hybrid flexibility with up to 2 work-from-home days per week, subject to team needs.
- Flex Day options to adjust the workday to personal plans.
- Up to 30 days per year working from any location in the world as a flex-location benefit.
- Employee Assistance Program and personalized wellbeing support through Champion Health.
- Access to professional development platforms and learning programs, including LinkedIn Learning, Microsoft’s Enterprise Skills Initiative, Pluralsight, and other specialized providers.
- Benefits aligned with the local market and employment status, within an inclusive and diverse work environment.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
9 часов назад
Senior Information Security Engineer
2 часа назад
Mobile and Cloud Security Engineer
3 часа назад
Infra Security Engineer
3 часа назад
Cyber Security Software Engineer (Network Devices)
3 часа назад
Security Software Developer (Cybersecurity)
14 часов назад