Senior Threat

22 hours ago


Singapore ALLEN & OVERY LLP Full time

**It’s Time**

Allen & Overy is a leading global law firm operating in over thirty countries. By turning our insight, technology and talent into ground-breaking solutions, we’ve earned a place at the forefront of our industry. Our lawyers are leaders in their field - and the same goes for our support teams. Ambitious, driven and open to fresh perspectives, we find innovative new ways to deliver our services and maintain our reputation for excellence, in all that we do.

The nature of law is changing and with that change brings unique opportunities. With our collaborative working culture, flexibility, and a commitment to your progress, we build rewarding careers. By joining our global team, you are supported by colleagues from around the world. If you’re ready for a new challenge, it’s time to seize the opportunity.

**Department purpose**

The Global Information Security & IT Risk team is responsible for setting the firm wide strategy for Information Security and changing, managing and maintaining controls to ensure continuous alignment with the strategy. The team must deliver and support robust, reliable, cyber and information security controls 24x7x365 on a global basis.

The Information Security & IT Risk team is responsible for primary controls assurance, client compliance and security requirements and controls definition. In addition the team is also responsible for tracking obvious and far less obvious threats and vulnerabilities to ensure that protection of client data and the firms digital services, information and data remains robust even as the threat environment constantly evolves.

**Role purpose**

The Senior Threat and Vulnerability Analyst (Singapore) is a key member of the Global Information Security Operations team.

The job is focused on six outcomes:

- Expand the scope of IT assets addressed by the operational vulnerability management process to meet the vision and requirements of the IT Vulnerability Management Standard. Further together with the Snr Threat & Vulnerability Analyst New York own the primary vulnerability analysis tool (Qualys) and ensure it is maintained and operationally effective and provisioned into new operating environments (for example new cloud VMs) before those environments go live.
- Lift the quality of documented InfoSec risk and threat analysis such that there is a clear description of the potential technical and business impact associated with the issues within the monthly vulnerability reporting pack, vulnerabilities in general and/or the solutions under assessment. Provide input into the vulnerability and threat register and be able to justify vulnerability and threat characterisations when challenged especially during the monthly vulnerability reporting cycle.
- Find back doors and miss-direct attackers adopt a “think like a hacker” mind-set and look for open services (for example network APIs) and ensure that those services are only available to legitimate digital service consumers. Miss-direct attackers by leading the deployment, maintenance and monitoring cyber honeypots. Adopt and actively use the MITRE and STRIDE frameworks and their lexicon and promote the use of the frameworks in InfoSec globally and IT.
- Build reliable consistent primary vulnerability data by firstly taking a leading role in collaborating across IT Service and InfoSec to draft the monthly top 15 vulnerability pack. Secondly maintain the vulnerability and threat registers in the firm. Thirdly collaborating closely with the Security Operations Manager (Belfast) and the Snr Mngr Security and Data Compliance (Belfast) to ensure vulnerability and threat information is shared quickly and efficiently. Fourthly attending weekly vulnerability working group meetings with IT Service to ensure service patching teams are leveraging the best quality vulnerability intelligence.
- Globalise the InfoSec incident response process by a) Monitoring the main InfoSec mailbox and ticket queue during local business hours b) Initiating and managing the InfoSec incident response process when a suspect incident occurs in local business hours c) Collaborating with InfoSec colleagues in Europe and North America to ensure that priority tasks and issues are handed over before close of local business operations.

**Key relationships**
- Works closely with the Senior Manager Security & Data Compliance (Belfast) who is the global leader of security operations.
- Work alongside Senior Threat and Vulnerability Analyst (New York) sharing vulnerability and threat intelligence and the Manager Security Operations (Belfast).
- Maintain a close working relationship with the IT Service patching teams globally.
- Maintain a relationship with the CISO.

**Job description**

Role and responsibilities
- Expand the scope of IT assets addressed by the operational vulnerability management process in order that scanning and analysis is performed for all digital services.
- Provide InfoSec risk and threat analysis and be



  • Singapore Centre for Strategic Infocomm Technologies (CSIT) Full time

    Overview Senior Cyber Threat Investigator role at Centre for Strategic Infocomm Technologies (CSIT). Responsibilities Overcome techniques employed to mask anomalous behaviours. Improve and automate validation or detection techniques. Identify alternate fingerprinting techniques to extend visibility. Assess adversary's objectives, sophistication, resources...


  • Singapore HRS TALENTS PTE. LTD. Full time

    Lead and manage end-to-end threat detection, analysis, and incident response activities, including handling advanced persistent threats and complex attack scenarios. - Design and execute threat intelligence programs, leveraging open-source intelligence (OSINT), deep/dark web monitoring, and commercial threat feeds to proactively identify emerging risks. -...


  • Singapore SATS Full time

    Senior Analyst, Threat Detection and Response Headquartered in Singapore, SATS Ltd. is one of the world's largest air cargo handling and airline catering services. SATS Gateway Services delivers airfreight, ground handling, security, aircraft cleaning and laundry. SATS Food Solutions supplies airlines and institutions with central kitchens for large‐scale...


  • Singapore Hays Full time

    **Your new company** My client is a Global Technology/Electronics company with presence across the world. With their growing stature and expanding business, they are looking for a a Senior Threat Detection Engineer to join their growing team. **Your new role** - Investigate and review threats/intrusions on initial infection vector determination,...


  • Singapore MSD Full time

    **Cyber Threat Intelligence Senior Specialist** - Opportunity to **be a part of the Information Technology Risk Management and Security’s Cyber Fusion Center in Singapore!**: - **Based in Singapore,** the regional hub for Asia Pacific (AP) and top-ranked biopharmaceutical company on The Straits Times and Statista’s list of Best Employers in Singapore...


  • Singapore Concentric Full time

    Are you interested in joining an organization with a global reach? At Concentric, "We Manage Risk Everywhere to Keep People Safe." If you are passionate about intelligence, risk analysis, threat management, executive protection, security operations, or business resiliency, Concentric may be the organization you've been searching for! Concentric is a risk...


  • Singapore Acronis Full time

    Senior Cybersecurity Researcher (Threat Analysis and Detection Engineering) Join to apply for the Senior Cybersecurity Researcher (Threat Analysis and Detection Engineering) role at Acronis Acronis is revolutionizing cyber protection—providing natively integrated, all-in-one solutions that monitor, control, and protect the data that businesses and lives...


  • Singapore JPMorganChase Full time

    Security Operations Vice President - Senior Threat Detection Engineer Join to apply for the Security Operations Vice President - Senior Threat Detection Engineer role at JPMorganChase Job Description Embrace the challenge of maintaining robust digital security, driving operational excellence, and implementing cutting-edge solutions in cybersecurity. As a...

  • Wholesale Bank

    2 weeks ago


    Singapore Black Swan Group Full time

    Posted by: Richard Aldridge Recruiter View profile & contact An international wholesale bank is looking for a seasoned cyber risk professional to be in charge of cyber security threat management. **The organisation offers you the chance to**: - Performing investigations into cyber security incidents including incident response, threat hunting and threat...


  • Carpenter Street, Singapore, Singapore Propine Digital Tech Full time $80,000 - $120,000 per year

    Work should be challenging.Your work should challenge the status quo.You should be defining the future, not being dependent on it.You don't like it safe and prefer to swim in the deep end while figuring things out.You want to be avant-garde.If this resonates with you, then you'll fit right in here at Propine.Propine is re-inventing capital markets using...