Senior Analyst, Threat Detection and Response

2 days ago


Singapore SATS Full time

Senior Analyst, Threat Detection and Response Headquartered in Singapore, SATS Ltd. is one of the world’s largest air cargo handling and airline catering services. SATS Gateway Services delivers airfreight, ground handling, security, aircraft cleaning and laundry. SATS Food Solutions supplies airlines and institutions with central kitchens for large‐scale food production and distribution. Key Responsibilities Continuously monitor SIEM, EDR and other consoles for suspicious activity; triage alerts and prioritize response based on asset criticality. Investigate suspicious events, determine incident scope, gather evidence and perform root‐cause analysis to identify attack vectors. Execute end‐to‐end incident response, including containment, eradication, recovery and coordination with IT infrastructure and application owners. Proactively hunt for indicators of compromise and hidden threats in logs, network traffic and endpoint telemetry, employing hypothesis‐driven techniques. Continuously tune SIEM/EDR rules, thresholds and SOAR playbooks to automate response actions, reduce false positives and accelerate containment. Leverage threat intelligence sources to enrich analysis and response; stay updated on new vulnerabilities and adversary tactics; adjust monitoring rules accordingly. Work closely with global SOC team members and escalating complex incidents to senior analysts or incident response leads when necessary. Document investigation steps, findings, and actions taken; prepare incident reports and contribute to post‐incident reviews. Assist in developing and updating incident response playbooks, SOPs and knowledge base documentation; provide feedback to improve monitoring tools and workflow automation. Share insights from incidents and trending threats with the broader team; mentor junior analysts (Tier 1 SOC analysts) by elevating the team’s collective skill level. Key Requirements Bachelor’s degree in Cybersecurity, Computer Science, Information Systems or equivalent threat management & incident response experience. Currently hold cybersecurity certifications such as GCIH, GCFA, GCIA, CEH or others. With 3 years or more, progressive experience in at least two of the following disciplines: Threat Detection & Analysis (leveraging SIEM tools, IDS/IPS, endpoint detection, log analysis). Incident Response & Management (developing response plans, executing playbooks, forensic investigations, root cause analysis). Threat Hunting (identifying undetected threats through proactive analysis and hypothesis‐driven investigation). Cyber Threat Intelligence (gathering and analyzing threat intelligence to inform detection capabilities and preventive measures). Network Security (TCP/IP protocols, firewalls, intrusion prevention systems, and network traffic analysis). Securing and monitoring operating system and cloud environments (AWS, Azure, GCP), including analyzing cloud service logs and configurations for suspicious activities. Demonstrated ability to function as a Level 2 or 3 SOC Analyst (analyzing and responding to cybersecurity incidents). Preferred Experience: Experience with SOAR tools and some proficiency in scripting languages (e.g., Python, PowerShell) to automate repetitive tasks. Advanced understanding of emerging threats, zero‐day vulnerabilities, and common attack vectors (phishing, malware, ransomware, lateral movement). Hands‐on experience using SIEM and EDR platforms for centralized log analysis and real‐time threat monitoring. In‐depth knowledge of the incident response lifecycle. Proven ability to conduct proactive threat hunting operations, leveraging the MITRE ATT&CK framework. Familiarity with cyber threat intelligence feeds and standards (STIX, TAXII) and incorporating IOCs into monitoring and investigations. Understanding of key security frameworks and regulations (NIST CSF, ISO 27001, GDPR) and the ability to align threat detection and incident response processes with organizational policies. Effective at coordinating with cross‐functional teams during high‐impact incidents and translating complex technical findings into actionable insights for executive and non‐technical stakeholders. #J-18808-Ljbffr



  • Singapore SATS Ltd. Full time

    About Us Headquartered in Singapore, SATS Ltd. is one of the world's largest providers of air cargo handling services and Asia's leading airline caterer. SATS Gateway Services provides airfreight and ground handling services including passenger services, ramp and baggage handling, aviation security services, aircraft cleaning and aviation laundry. SATS Food...


  • Singapore TD Full time

    Job Description Role and Responsibilities We are seeking an experienced and technically proficient Senior Information Security Analyst (L9) to join the Cyber Threat Detection (CTD) team. This role will focus on developing and tuning detection alerts for the Cyber Security Operations Center (CSOC), with a strong emphasis on engineering use cases, alert...


  • Singapore Propine Full time

    Work should be challenging. Your work should challenge the status quo. You should be defining the future, not being dependent on it. You don't like it safe and prefer to swim in the deep end while figuring things out. You want to be avant-garde. If this resonates with you, then you'll fit right in here at Propine. Propine is re-inventing capital markets...


  • Singapore IMDA Full time

    Threat Intelligence Analyst Apply locations IMD - Mapletree Business City, MBC BLK 10 time type Full time posted on Posted 12 Days Ago job requisition id JR- . Responsibilities Work with a team of Threat Intelligence analysts to maintain situational awareness for Infocomm and Media sectors. Keep abreast with related threat groups’ tactics and techniques...


  • Singapore PayPal Full time

    **At PayPal (NASDAQ**: PYPL), we believe that every person has the right to participate fully in the global economy. Our mission is to democratize financial services to ensure that everyone, regardless of background or economic standing, has access to affordable, convenient, and secure products and services to take control of their financial lives. **Job...


  • Singapore GIC Private Limited Full time

    Press Tab to Move to Skip to Content Link Select how often (in days) to receive an alert: Create Alert Associate/AVP, Threat Detection Analyst, COO's Office Location: Singapore, SG Job Function: Chief Operating Officer’s Office Job Type: Permanent GIC is one of the world’s largest sovereign wealth funds. With over 2,000 employees across 11 locations...

  • Solutions Engineer

    3 days ago


    Singapore People Profilers Full time

    Job Description: **Location: Hybrid Work Arrangement / Office at Jurong East** **Industry: Automotive - MNC** **Salary Range: Up to $10,000** **Description**: - We are seeking a highly skilled Threat Detection Engineer to join our team. In this role, you will be responsible for overseeing the engineering, development, and maintenance of threat...


  • Singapore JPMorganChase Full time

    Embrace the challenge of maintaining robust digital security, driving operational excellence, and implementing cutting-edge solutions in cybersecurity. As a Security Operations Vice President in Cybersecurity & Tech Controls, you will be a technical leader in our Cyber Defense function, enhancing our capabilities to detect, prevent, and disrupt sophisticated...


  • Singapore UBS Full time

    Singapore - Information Technology (IT) - Group Functions **Job Reference #** - 267238BR **City** - Singapore **Job Type** - Full Time **Your role** - Are you a cybersecurity professional with hands on experience identifying Insider threats? Do you routinely work closely with business, legal, compliance, and technology stakeholders to investigate...


  • Singapore Acronis Full time

    Senior Cybersecurity Researcher (Threat Analysis and Detection Engineering)Join to apply for the Senior Cybersecurity Researcher (Threat Analysis and Detection Engineering)role at Acronis Acronis is revolutionizing cyber protection—providing natively integrated, all-in-one solutions that monitor, control, and protect the data that businesses and lives...