Senior Analyst, Threat Detection and Response

14 hours ago


East Region, Singapore SATS Ltd. Full time $104,000 - $130,878 per year

Company description:

About Us

Headquartered in Singapore, SATS Ltd. is one of the world's largest providers of air cargo handling services and Asia's leading airline caterer. SATS Gateway Services provides airfreight and ground handling services including passenger services, ramp and baggage handling, aviation security services, aircraft cleaning and aviation laundry. SATS Food Solutions serves airlines and institutions, and operates central kitchens with large-scale food production and distribution capabilities for a wide range of cuisines.

SATS is present in the Asia-Pacific, the Americas, Europe, the Middle East and Africa, powering an interconnected world of trade, travel and taste. Following the acquisition of Worldwide Flight Services (WFS) in 2023, the combined SATS and WFS network operates over 215 stations in 27 countries. These cover trade routes responsible for more than 50% of global air cargo volume. SATS has been listed on the Singapore Exchange since May 2000. For more information, please visit

Why Join Us

At SATS, people are our greatest asset and we build our success on the knowledge, expertise and performance of every contributor, by embracing diversity and uniqueness. As part of our holistic approach and commitment to embracing FAM (Fulfilling, Appreciated, Meaningful) in the workplace, we offer the runway to develop Fulfilling careers that foster your career growth, recognising and Appreciating the strength of talent and capabilities that we continue to build internally; and inspiring and encouraging each other to make Meaningful contributions in the work we do at SATS.

Job description:

About Us

Headquartered in Singapore, SATS Ltd. is one of the world's largest providers of air cargo handling services and Asia's leading airline caterer. SATS Gateway Services provides airfreight and ground handling services including passenger services, ramp and baggage handling, aviation security services, aircraft cleaning and aviation laundry. SATS Food Solutions serves airlines and institutions, and operates central kitchens with large-scale food production and distribution capabilities for a wide range of cuisines.

SATS is present in the Asia-Pacific, the Americas, Europe, the Middle East and Africa, powering an interconnected world of trade, travel and taste. Following the acquisition of Worldwide Flight Services (WFS) in 2023, the combined SATS and WFS network operates over 215 stations in 27 countries. These cover trade routes responsible for more than 50% of global air cargo volume. SATS has been listed on the Singapore Exchange since May 2000. For more information, please visit

Why Join Us

At SATS, people are our greatest asset and we build our success on the knowledge, expertise and performance of every contributor, by embracing diversity and uniqueness. As part of our holistic approach and commitment to embracing FAM (Fulfilling, Appreciated, Meaningful) in the workplace, we offer the runway to develop Fulfilling careers that foster your career growth, recognising and Appreciating the strength of talent and capabilities that we continue to build internally; and inspiring and encouraging each other to make Meaningful contributions in the work we do at SATS.

Key Responsibilities

This position focuses on threat detection, incident response, event analysis, and proactive threat hunting across the organization's IT environments. The Threat Detection and Response Sr. Analyst monitors security systems, analyzes alerts, and investigates potential incidents to protect critical assets and data. Serving as an integral part of the global Security Operations Center (SOC) team, this analyst works closely with regional teams in Europe and Singapore to ensure timely identification and remediation of cyber threats.

The senior analyst will respond to security incidents in accordance with established procedures and industry best practices, collaborating with cross-functional IT and security teams. They leverage advanced security tools (SIEM, EDR, SOAR) and follow frameworks like MITRE ATT&CK to understand adversary techniques and continuously improve detection capabilities. The ideal candidate has 3+ years of experience in cybersecurity operations (Tier 2 / Tier 3 SOC analyst or incident responder), combining strong technical skills with effective communication.

  • Continuously monitor security consoles and dashboards (SIEM, EDR, etc.) for suspicious activity; triage alerts to identify valid security incidents versus false positives and prioritize response based on asset criticality and business risk.
  • Investigate suspicious activities and security events, determine the scope and severity of incidents, and gather relevant evidence. Perform root cause analysis to identify attack vectors and affected systems.
  • Execute incident response actions end-to-end - including timely containment of threats, eradication of malicious artifacts, and system recovery - following the organization's incident response plan. Coordinate with IT infrastructure, application owners, and other stakeholders to ensure effective remediation of incidents.
  • Proactively hunt for indicators of compromise and hidden threats in logs, network traffic, and endpoint telemetry, even without specific alerts. Use hypothesis-driven techniques and knowledge of attacker TTPs to uncover stealthy or emerging threats that evaded initial detection.
  • Continuously tune SIEM/EDR detection rules, thresholds, and SOAR playbooks—automating repetitive response actions to reduce false positives and accelerate containment
  • Leverage internal and external threat intelligence sources to enrich analysis and response. Stay updated on new vulnerabilities and adversary tactics; incorporate this knowledge to adjust monitoring rules and incident response strategies. Map observed malicious activities to frameworks like MITRE ATT&CK for reporting and analysis.
  • Work closely with global SOC team members and escalate complex incidents to senior analysts or incident response leads when necessary. Collaborate with colleagues in other regions to ensure seamless coverage and knowledge sharing across the security team.
  • Document investigation steps, findings, and actions taken for each incident in a clear and concise manner. Prepare incident reports and contribute to post-incident review meetings, highlighting what occurred, how it was resolved, and recommendations to prevent future occurrences.
  • Assist in developing and updating incident response playbooks, standard operating procedures, and knowledge base documentation. Provide feedback and suggestions to improve security monitoring tools, analytics content (detection rules), and workflow automation (SOAR playbooks) for greater efficiency and effectiveness.
  • Share insights from incidents and trending threats with the broader team to enhance overall awareness. Mentor and guide junior analysts (Tier 1 SOC analysts) by sharing analysis techniques and best practices, elevating the team's collective skill level.

Key Requirements

  • Bachelor's degree in Cybersecurity, Computer Science, Information Systems, or equivalent threat management & incident response experience
  • Currently hold cybersecurity certifications such as GCIH, GCFA, GCIA, CEH, others
  • With 3 years or more, progressive experience in at least two of the following disciplines:
  • Threat Detection & Analysis (leveraging SIEM tools, IDS/IPS, endpoint detection, log analysis, etc.)
  • Incident Response & Management (developing response plans, executing playbooks, forensic investigations, root cause analysis)
  • Threat Hunting (identifying undetected threats through proactive analysis and hypothesis-driven investigation)
  • Cyber Threat Intelligence (gathering and analyzing threat intelligence to inform detection capabilities and preventive measures)
  • Network Security (TCP/IP protocols, firewalls, intrusion prevention systems, and network traffic analysis)
  • Securing and monitoring operating system and cloud environments (AWS, Azure, GCP), including analyzing cloud service logs and configurations for suspicious activities, and understanding cloud-native security controls and best practices
  • Demonstrated ability to:
  • Function as a Level 2 or 3 SOC Analyst (analyzing and responding to cybersecurity incidents)
  • Preferred Experience:
  • Experience with SOAR tools and some proficiency in scripting languages (e.g., Python, PowerShell) to automate repetitive tasks and streamline incident response workflows
  • Advanced understanding of emerging threats, zero-day vulnerabilities, and common attack vectors (phishing, malware, ransomware, lateral movement) with the ability to ensure rapid detection and response
  • Hands-on experience using SIEM and EDR platforms for centralized log analysis, real-time threat monitoring, and in-depth incident investigations
  • In-depth knowledge of the incident response lifecycle
  • Proven ability to conduct proactive threat hunting operations, leveraging the MITRE ATT&CK framework to map adversary tactics, techniques, and procedures (TTPs), uncover stealthy threats, and close gaps in detection coverage
  • Familiarity with cyber threat intelligence feeds and standards (e.g., STIX, TAXII), incorporating IOCs (Indicators of Compromise) and threat intel data into monitoring and investigations to enrich context and anticipate emerging threats
  • Understanding of key security frameworks and regulations (e.g., NIST CSF, ISO 27001, GDPR) and the ability to align threat detection and incident response processes with organizational policies and compliance requirements
  • Effective at coordinating with cross-functional teams (IT, DevOps, Business, etc.) during high-impact incidents and translating complex technical findings into clear, actionable insights for executive and non-technical stakeholders


  • Central Region, Singapore Halcyon Knights Pty Ltd Full time $75,000 - $90,000 per year

    We're hiring on behalf of a leading US-based Technology & Cybersecurity Services provider — a globally recognized S&P 500 company with a workforce of over 35,000 professionals. This organization delivers high-level managed security and IT services to major enterprises around the world. Cybersecurity Threat Analyst / Threat Hunter They're currently...


  • Changi, East Region, Singapore MUFG Full time $90,000 - $120,000 per year

    Job Responsibilities:The AVP of Global Threat Hunting Centre is responsible for performing threat hunting and detection engineering to proactively hunt for and detect cyber threats across the Banking group globally. This role involves implementing a threat hunting program and methodology, establishing detection engineering to achieve the program objectives,...


  • Changi, East Region, Singapore MUFG Full time $150,000 - $200,000 per year

    Job Responsibilities:The Director of Global Threat Hunting Centre is responsible for overseeing and managing the threat hunting, detection engineering and platform engineering teams to implement a top class threat hunting program for the Banking group globally. This role involves developing a global threat hunting strategy and roadmap, implementing hunting...


  • Central Region, Singapore Marina Bay Sands Pte Ltd Full time $90,000 - $120,000 per year

    Senior Cyber Threat Analyst (Offensive Security, Threat Hunting & Incident Response)LOVE WHAT YOU DO? THERE IS A PLACE FOR YOU HEREBe part of our diverse and inclusive team.Job ResponsibilitiesThe candidate is expected to perform the following activities:Adversarial Simulation:Perform comprehensive analyses and simulations to mimic cyber threats and identify...


  • Central Region, Singapore Univers. Pte. Ltd. Full time $36,000 - $72,000 per year

    CompanyUnivers. Pte. Ltd.DesignationLevel 1 SOC Security Analyst InternDate Listed30 Jun 2025Job TypeEntry Level / Junior ExecutiveIntern/TSJob PeriodImmediate Start - Jul 2026ProfessionIT / Information TechnologyIndustryComputer and ITLocation NameHarbourFront Avenue, Keppel Bay Tower, SingaporeAddress1 HarbourFront Ave, Singapore 098632MapAllowance /...


  • West Region, Singapore ST ENGINEERING INFO-SECURITY PTE. LTD Full time $90,000 - $120,000 per year

    Company description: ST Engineering Info-Security Pte LtdJob description: Job SummaryThe Tier 3 MSSP SOC Analyst is a senior-level role that provides leadership for SOC operations. The role includes advanced threat hunting, incident analysis, process optimization, and team mentorship, ensuring the highest level of security operations for MSSP...


  • East Singapore APERSONA Full time

    Full Time - Singapore East (onsite) - Posted 1 year ago About the role - As Senior Cyber Security Consultant, you will work within the Security Operation Center in evaluating risks, conducting log analysis, and acting upon security threats across a complex and dispersed IT estate. - You will carry out threat analysis and handling process to ensure the...

  • SOC Analyst

    2 days ago


    East Region, Singapore ST ENGINEERING INFO-SECURITY PTE. LTD Full time $70,000 - $120,000 per year

    This role focuses on the detection, prevention & response to cyber security threats and alerts. This person will have the opportunity to work on technology and processes with a global reach and is an integral part of the security controls that the company uses to protect its data and intellectual property.To be successful you'll need to demonstrate you have...


  • Central Region, Singapore Adecco Personnel Pte Ltd. Full time $90,000 - $120,000 per year

    The Opportunity:Permanent roleWork location: EastWork hours: Mon to Fri 8:30am - 6pmAdecco is partnering with recognised organisation and they are looking for Digital Forensics Incident Response (DFIR) to join the Team A great opportunity to work with the company who value growth opportunities, trainings and diversity.Responsibilities:Incident Response &...


  • Changi, East Region, Singapore MUFG Full time $90,000 - $120,000 per year

    Job Responsibilities:As a Global Red Team Operator at the Assistant Vice President level, you will play a key role in executing advanced adversary simulation exercises that test and improve MUFG's global security posture. This role is ideal for professionals with a strong foundation in offensive security and a demonstrated ability to plan and execute Red...