Cyber Incident Analyst

3 weeks ago


Singapore WE-PLUS PTE. LTD. Full time
Roles & Responsibilities

Role Summary

Our client is looking for Cybersecurity expert/SME in Detection Engineering & Security Investigation areas, part of Production SOC & Security Investigation & Incident Response team.

The role will be to:

  • Strengthen the detection capabilities in APAC and be member of the Global Use Case development team for a worldwide alignment of the security use cases.
  • Contribute to the enhancement of SIEM and SOAR capabilities.
  • Act as reference point in team of experts on Security Incident Response activities, Anti-Malware/Defense activities and Security Detection activities.
  • Oversee the detection capabilities for the 24/7 regional IT Production SOC which handles the IT Production security alerts for the APAC region.
  • Participate to the global continuous improvement of the framework of tools and processes for Security Incident Management, Anti-Malware/Defense and Security Detection.
  • Collaborate with the APAC Business CSIRT, accountable for the Security Incident practice in APAC, to strengthen the extended security monitoring setup between Business Information Security and IT Production Security.

Main Responsibilities

  • Lead technical activities (security usecase definition, design, implementation & enrichment) in the team of IT Production Security Investigation & Incident Response based on real-world attack scenarios and framework like MITRE ATT&CK, ensuring robust security detection posture across various layers.
  • Understand ongoing security threats in the wild and propose security usecase to detect and when possible, protect or mitigate.
  • Lead technical activities (definition, R&D/threat hunting) in the team of IT Production Security Investigation & Incident Response and oversee the detection capabilities of the 24/7 regional IT Production SOC.
  • Respond to Cyber / IT security incidents and evaluates the type and severity of security events.
  • Identify recurring security issues and risks and develops mitigation plans and recommends process improvements.
  • Partner with global, regional and local stakeholders to ensure organizational and procedural efficiency and readiness for detection of suspicious events and reaction.
  • Continuously improve the processes to strengthen the current SOC framework via review of policies and operational playbooks.
  • Partner with the APAC Business CSIRT for integrated security monitoring and alert/incident handling operations.
  • Contribute to local security incident response outside the direct scope of responsibilities (i.e., local IT production in some APAC business entities).
  • Contribute to the Bank compliance with regulatory requirements and internal policies.
  • Contribute to the reporting of all incidents according to the Incident Management System.
  • Contribute to the control frameworks in day‐to‐day business activities, such as Control Plan; Participate to Audit interview and provide the require evidence.

Qualifications & Experience

  • Bachelor's Degree in Information Technology or related fields.
  • Must have 7 or more years of experience on overall cybersecurity incident response with over 4 years specifically on security usecase design, development, coding.
  • A minimum of 7 or more years of experience as security professional.
  • Experience in security usecase design/development with understanding of Java language.
  • Good working knowledge of Linux (RedHat/Ubuntu).
  • Working knowledge to interpret security logs or instructions into threat models – SecOPS-DevOPS mindset & skills.
  • Experience and knowledge in investigating incidents, remediation, tracking and follow-up for incident closure with concerned teams, stakeholders.
  • Thorough understanding of technologies and security concepts, with knowledge & hands on experience in SIEM Product and Security Incident Management.
  • Experience of performing security monitoring and incident response activities in an advanced Security Operation Centers (SOC) environment (log analysis, event analysis, incident investigation, reporting).
  • Comfortable working with and making the most of large data sets (collection, analysis, response), creating content/use cases/models and bringing an automation mindset.
  • Experience in SIEM on ELK(Elastic Logstash Kibana) stack is a plus.
  • Professional credentials in one of the relevant IT Security disciplines is a plus (SANS / CISSP / OSCP).
  • Experience in common scripting languages such as Python, PowerShell, Bash, SQL is a plus.

Personal Attributes

  • Strong problem-solving skills and Good communication skills.
  • Ability to communicate in French is a plus in order to effectively communicate with French-speaking stakeholders.
  • Positive attitude, willing to upskill and carry out in-depth troubleshooting.
  • Has the ability to work autonomously and think on feet, be-proactive.
  • Good interpersonal skills and team player.
  • High energy level coupled with a desire to take on responsibility.
  • Able to multi-task & deliver within agreed deadlines.
Tell employers what skills you have

Work Autonomously
Information Security
Able To Multitask
Troubleshooting
Remediation
Bash
Information Technology
Logstash
Incident Investigation
French
Kibana
Evidence
Linux
Incident Management
CISSP

  • Singapore UBS AG Full time

    Roles & ResponsibilitiesYour role : Are you keen on working in world class Cyber Security Operations Center for one of the best Swiss private banks? Do you have related experience and are willing to take it further by learning how to defend an enterprise against cyber-attacks? We are looking for an incident response expert who will:• respond to cyber...


  • Singapore UBS AG Full time

    Roles & ResponsibilitiesYour role : Are you keen on working in world class Cyber Security Operations Center for one of the best Swiss private banks? Do you have related experience and are willing to take it further by learning how to defend an enterprise against cyber-attacks? We are looking for an incident response expert who will:• respond to cyber...


  • Singapore Bayer CropScience Limited Full time

    MAIN JOB PURPOSE: The CIRT Jr Analyst investigates complex cyberattacks and establishes defense measures if needed with minimal to no supervision/direction. The person is responsible for analyzing system events, security incidents and potential malware, ensuring the security capabilities across the Bayer Group globally. In addition, he supports to maintain...


  • Singapore Citi Full time

    Are you looking for a career move that will put you at the heart of a global financial institution? Then bring your skills in analysis, problem solving and communication to Citi bank. By Joining Citi, you will become part of a global organisation whose mission is to serve as a trusted partner to our clients by responsibly providing financial services that...


  • Singapore UBS Full time

    Singapore - Information Technology (IT) - Group Functions **Job Reference #** - 266972BR **City** - Singapore **Job Type** - Full Time **Your role** - Are you keen on working in world class Cyber Security Operations Center for one of the best Swiss private banks? - Do you have related experience and are willing to take it further by learning how to...


  • Singapore Changi Airport Group Full time

    **Senior Associate/Assistant Manager, Digital Forensics and Incident Response Analyst** **About the role** During “war time”, the Digital Forensics and Incident Response (DFIR) analyst is responsible for executing our digital forensics and incident response protocols to conduct in-depth investigation and analysis to understand the scope and impact of...


  • Singapore CHEVRON SINGAPORE PTE. LTD. Full time

    **Requisition ID: R000024012** **Job Location: Singapore Duo Tower **Responsibilities for this position may include but are not limited to**: - Responsible for supporting 24/7 cyber threat monitoring and incident response, leveraging threat intelligence to proactively hunt for and respond to external cyber threats to Chevron's global network infrastructure,...


  • Singapore UBS Full time

    Singapore - Information Technology (IT) - Group Functions **Job Reference #** - 266983BR **City** - Singapore **Job Type** - Full Time **Your role** - Are you a cybersecurity professional who is passionate about proactive security? Do you enjoy working closely with business, legal, compliance, and technology stakeholders to manage cyber incidents? Do you...


  • Central Singapore Chevron Full time

    All interested applicants, please read the Data Privacy Notice Responsibilities for this position may include but are not limited to: - Responsible for supporting 24/7 cyber threat monitoring and incident response, leveraging threat intelligence to proactively hunt for and respond to external cyber threats to Chevron's global network infrastructure,...


  • Singapore UBS Full time

    Singapore - Information Technology (IT) - Group Functions **Job Reference #** - 263525BR **City** - Singapore **Job Type** - Full Time **Your role** - Are you from the World of Cyber? Are you the one to defend the organization against advance threat? Do you have what it takes to coordinate and respond to cyber-attacks? - respond to cyber security...