Detection Engineer – EASM / ASM / Cyber Threat Intelligence (CTI)

Astek

Santo Niño 1st

On-site

PHP 900,000 - 1,300,000

Full time

4 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Astek is seeking a Detection Engineer to support building and operating the Security Exposure and Third-Party Cyber Assurance Centre of Excellence within CASD – External Threat Operations. The role covers SEM and TPCA with continuous monitoring of internet-facing exposures and third-party cyber risk.

You will employ ASM/EASM, CTI, and data lake dashboards, while developing automation in Python/PowerShell/Bash and reporting to both technical and business stakeholders.

Qualifications

  • 3–5 years of hands-on cybersecurity experience
  • Experience with third-party/vendor security assessments (VDD, ODD, SIG)
  • Knowledge of NIST, ISO 27001, and CIS Controls
  • Experience with ASM/EASM, CTI, digital risk monitoring
  • Strong scripting for automation
  • Understanding of TCP/IP, DNS, HTTP/S and cloud environments (AWS, Azure, GCP)
  • Strong analytical and documentation skills

Responsibilities

  • Operate and maintain always-on security exposure and external threat monitoring platforms.
  • Monitor organisation, portfolio companies, and third parties for internet-facing vulnerabilities and threats.
  • Perform ASM/EASM activities to identify and prioritize external exposures.
  • Conduct third-party/vendor cybersecurity assessments (VDD, ODD, SIG).
  • Assess third-party security controls against NIST, ISO 27001, CIS Controls.
  • Leverage CTI and dark-web monitoring to identify threats.
  • Investigate and coordinate remediation with stakeholders.
  • Develop scripts to streamline monitoring and reporting.
  • Build dashboards and cyber posture metrics.
  • Document findings for technical and business audiences.
  • Support continuous improvement of detection logic and exposure management.

Skills

Cybersecurity experience
Python scripting
PowerShell scripting
Bash scripting
Threat monitoring
Threat intel (CTI)
Stakeholder communication

Education

Degree in Computer Science or IT

Tools

ASM/EASM platforms
Digital risk monitoring tools
Dark-web monitoring tools
CTI platforms

Job description

Detection Engineer – Security Exposure & Third-Party Cyber Assurance
Role Overview

We are looking for a Detection Engineer to support the build-out and operations of the Security Exposure and Third-Party Cyber Assurance Centre of Excellence, under Cybersecurity Assurance and Defense (CASD) – External Threat Operations.

The role will provide hands-on technical and operational support across two key areas:

  • Security Exposure Management (SEM): Continuous, outside-in monitoring of the organisation and its portfolio companies’ internet-facing attack surface.
  • Third-Party Cyber Assurance (TPCA): Cybersecurity due diligence and continuous assurance across third parties and the broader supply chain.

The successful candidate will operate continuous monitoring platforms, conduct third-party cyber assessments, validate active and emerging threats, and coordinate remediation to reduce the time between exposure identification and potential exploitation.

Key Responsibilities
  • Operate and maintain always-on security exposure and external threat monitoring platforms.
  • Monitor the organisation, portfolio companies, and third parties for internet-facing vulnerabilities, exposures, and emerging cyber threats.
  • Perform Attack Surface Management (ASM/EASM) activities to identify, assess, validate, and prioritise external security exposures.
  • Conduct third-party/vendor cybersecurity assessments, including security questionnaires and due diligence activities such as VDD, ODD, and SIG.
  • Assess third-party security controls against established frameworks including NIST, ISO 27001, and CIS Controls.
  • Leverage Cyber Threat Intelligence (CTI), digital risk, and dark-web monitoring to identify and validate relevant threats.
  • Investigate and validate high-risk or imminent security threats and coordinate appropriate remediation with relevant stakeholders.
  • Analyse third- and fourth-party cyber risks and their potential impact across the organisation and supply chain.
  • Develop scripts and automation using Python, PowerShell, or Bash to streamline monitoring, analysis, reporting, and operational activities.
  • Build and maintain operational dashboards, reporting capabilities, and cyber posture metrics using data lake platforms.
  • Document findings, processes, assessments, and remediation actions clearly for both technical and business stakeholders.
  • Support continuous improvement of detection logic, control baselines, monitoring processes, and exposure management capabilities.
Requirements
  • Degree in Computer Science, Information Technology, or a related discipline.
  • 3–5 years of hands-on cybersecurity experience, preferably within cybersecurity operations, attack surface/exposure management, third-party cyber risk assessment, or data lake environments.
  • Practical experience conducting third-party/vendor security assessments and questionnaires, including VDD, ODD, and SIG.
  • Good knowledge of cybersecurity frameworks such as NIST, ISO 27001, and CIS Controls.
  • Hands-on experience with ASM/EASM, cyber exposure management, digital risk monitoring, dark-web monitoring, and/or Cyber Threat Intelligence (CTI) platforms.
  • Strong scripting capabilities using Python, PowerShell, or Bash, particularly for automation and reporting.
  • Strong understanding of TCP/IP, DNS, HTTP/S, and common security exposures across AWS, Azure, and GCP.
  • Understanding of third- and fourth-party cyber risk and how security exposure can propagate through the supply chain.
  • Strong analytical and documentation skills, with the ability to handle sensitive security findings appropriately.
  • Good communication and stakeholder management skills across technical and business teams.
  • Collaborative, adaptable, and comfortable working in a fast-evolving cybersecurity environment.
Good to Have
  • Certifications such as Security+, CEH, GIAC (GSEC/GCIH), CompTIA CySA+, or equivalent.
  • CISSP Associate or CISM candidature.
  • Experience developing cyber posture scorecards and operational security dashboards.
  • Familiarity with detection engineering, including tuning detection logic and refining security control baselines as capabilities mature.

SEM | TPCA | ASM/EASM | CTI | Third-Party Cyber Risk | VDD/ODD | SIG | NIST | ISO 27001 | CIS Controls | Digital Risk & Dark-Web Monitoring | Python | PowerShell | Bash | TCP/IP | DNS | HTTP/S | AWS | Azure | GCP | Data Lakes | Detection Engineering

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Detection Engineer: External Threat & 3rd-Party Risk
Detection Engineer: External Threat & 3rd-Party Risk

Astek • Santo Niño 1st

On-site
PHP 900,000 - 1,300,000
Senior SIEM Engineer for Cybersecurity Detection
Senior SIEM Engineer for Cybersecurity Detection

Boehringer Ingelheim GmbH • Hinoba-an

On-site
PHP 1,200,000 - 1,800,000
Cybersecurity Detection Engineer
Cybersecurity Detection Engineer

Astek • Santo Niño 1st

On-site
PHP 900,000 - 1,300,000
IT Security Specialist
IT Security Specialist

Ibex Limited • Manila

On-site
PHP 600,000 - 900,000
IT Security Specialist
IT Security Specialist

ibex • Mandaluyong

On-site
PHP 420,000 - 640,000
Senior Cyber Security Engineer
Senior Cyber Security Engineer

Morgan McKinley • Philippines

On-site
PHP 1,200,000 - 2,400,000
Junior Cyber Security Engineer/Analyst
Junior Cyber Security Engineer/Analyst

PM Consulting • Philippines

On-site
PHP 600,000 - 900,000
Security Operations Center Analyst
Security Operations Center Analyst

Centrics Networks • Cebu City

On-site
PHP 400,000 - 640,000
Security Analyst / Network Security Analyst
Security Analyst / Network Security Analyst

RippedBoxStation • Philippines

On-site
PHP 260,000 - 420,000
Specialist (Cybersecurity)
Specialist (Cybersecurity)

NTUC FIRST CAMPUS LIMITED • Santo Niño 1st

On-site
PHP 1,200,000 - 1,800,000