Cyber Incident Responder

AMARIS GROUP SA

Singapore

On-site

SGD 80,000 - 120,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Robust training system with 250+ modules
Vibrant workplace events
Focus on sustainability and community impact

Job summary

AMARIS GROUP SA is seeking an experienced Cyber Incident Responder in Singapore. This role focuses on enhancing cybersecurity monitoring, design and development of security detection use cases, and incident response efforts. The ideal candidate will have strong expertise in detection engineering and the ability to collaborate with global teams.

Applicants should possess a Bachelor's degree in Cybersecurity or related fields and have over 7 years of experience in cybersecurity operations, including specific knowledge of SIEM technologies.

Qualifications

  • 7+ years of experience in cybersecurity operations, with at least 4 years focused on security use case design.
  • Strong hands-on experience with SIEM platforms in cybersecurity operations.
  • Proven experience in threat modeling and detection logic development using MITRE ATT&CK.

Responsibilities

  • Design and enhance security detection use cases based on real-world scenarios.
  • Investigate cybersecurity incidents and lead incident response activities.
  • Collaborate across regional and global cybersecurity teams to improve incident response.

Skills

Cybersecurity operations
Incident response
Threat hunting
Detection engineering
SIEM technologies

Education

Bachelor's degree in Cybersecurity, Computer Science, IT or related field

Tools

ELK (Elastic, Logstash, Kibana)
Linux (RedHat/Ubuntu)
Python
PowerShell
Bash

Job description

We are looking for an experienced Cyber Incident Responder to strengthen cybersecurity monitoring, detection engineering, and incident response capabilities across regional operations.

This role will play a key part in designing and enhancing security detection use cases, improving SIEM/SOAR capabilities, supporting SOC operations, and leading security investigation activities based on evolving cyber threats and real‑world attack scenarios. The ideal candidate combines strong hands‑on expertise in detection engineering, incident response, threat hunting, and security operations with the ability to work effectively across regional and global stakeholders.

A major focus of this role is security use case design and development, leveraging MITRE ATT&CK methodologies, SIEM technologies, and security automation capabilities to improve overall threat detection and incident response effectiveness.

Your Missions
Security Detection Engineering & Threat Monitoring
  • Design, develop, implement, and enhance security detection use cases based on real‑world attack scenarios and MITRE ATT&CK framework
  • Strengthen cybersecurity detection capabilities across enterprise environments through continuous improvement of detection logic and monitoring strategies
  • Enhance SIEM and SOAR capabilities to improve threat detection, alert enrichment, automation, and incident response efficiency
  • Perform threat hunting and proactive security analysis to identify emerging threats, suspicious activities, and detection gaps
  • Develop and enrich security monitoring content, use cases, correlation rules, and detection models across multiple security layers
  • Collaborate with security operations teams to improve monitoring coverage and detection effectiveness for enterprise security events
Cyber Incident Response & Investigation
  • Investigate cybersecurity incidents and assess the severity, impact, and scope of security events
  • Lead and support incident response activities including detection, triage, investigation, containment, remediation, recovery, and reporting
  • Perform log analysis, event correlation, and forensic investigation activities across enterprise environments
  • Act as a subject matter expert for security investigations, malware analysis, and detection engineering activities
  • Identify recurring security issues, operational gaps, and cyber risks, while recommending mitigation plans and process improvements
  • Support 24/7 SOC operations and collaborate closely with security monitoring teams on critical incidents and escalations
Security Operations & Continuous Improvement
  • Work closely with regional and global cybersecurity teams to improve operational readiness and incident response effectiveness
  • Contribute to the continuous improvement of SOC processes, operational playbooks, incident response procedures, and security monitoring frameworksSupport integrated security monitoring and incident handling initiatives across multiple cybersecurity functions
  • Participate in audit, compliance, governance, and control‑related activities to ensure alignment with internal security standards and regulatory requirements
  • Contribute to cybersecurity reporting, metrics, and operational improvement initiatives across the organization
About You
  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Engineering, or related field
  • 7+ years of experience in cybersecurity operations, incident response, or security engineering, with at least 4+ years specifically focused on security use case design and development
  • Strong hands‑on experience with SIEM platforms, particularly ELK (Elastic, Logstash, Kibana) within a cybersecurity operations environment (not limited to observability use cases)
  • Proven experience in security use case design using MITRE ATT&CK framework, including threat modelling, detection engineering, and detection logic development
  • Solid understanding of the full incident response lifecycle including detection, triage, investigation, containment, remediation, and reporting
  • Experience in threat hunting, security event investigation, and log analysis across enterprise environments
  • Knowledge of Java development for security use case coding and customization within security platforms
  • Good working knowledge of Linux environments (RedHat/Ubuntu)
  • Experience with scripting and automation using Python, PowerShell, Bash, or SQL
  • Strong analytical, troubleshooting, and problem‑solving capabilities with the ability to work autonomously in high‑pressure environments
  • Strong stakeholder management and communication skills, with experience collaborating across regional and global security teams
Why Amaris?
  • An international community bringing together 110+ different nationalities
  • An environment where trust has a central place: 70% of our key leaders started their careers at the first level of responsibilities
  • A robust training system with our internal Academy and 250+ available modules
  • A vibrant workplace that frequently gathers for internal events (afterworks, team buildings, etc.)
  • At Mantu, sustainability is part of everything we do. You’ll have the opportunity to turn your ideas into action and make a tangible impact. Every day, our teams bring our ESG commitments to life, from reducing our footprint to driving positive change within our communities. Through our WeCare Together program, you’ll be empowered to design and lead projects that create real social or environmental impact, with the company’s full support.

Amaris Consulting is proud to be an equal‑opportunity workplace. We are committed to promoting diversity within the workforce and creating an inclusive working environment. For this purpose, we welcome applications from all qualified candidates regardless of gender, sexual orientation, race, ethnicity, beliefs, age, marital status, disability, or other characteristics.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Detection Engineer/Cyber Incident Responder (SOC)
Detection Engineer/Cyber Incident Responder (SOC)

Amaris Consulting • Singapore

On-site
SGD 140,000 - 190,000
Senior DevOps Engineer – Elastic Stack & Kafka
Senior DevOps Engineer – Elastic Stack & Kafka

Amaris Consulting Pte Ltd • Singapore

On-site
SGD 120,000 - 180,000
Senior DevOps Engineer – Elastic Stack & Kafka
Senior DevOps Engineer – Elastic Stack & Kafka

AMARIS GROUP SA • Singapore

On-site
SGD 120,000 - 180,000
Equal opportunity workplace
Project Engineer (Pharmaceutical)
Project Engineer (Pharmaceutical)

Amaris Consulting Pte Ltd • Singapore

On-site
SGD 120,000 - 160,000
Project Engineer (Pharmaceutical)
Project Engineer (Pharmaceutical)

MANTU INTERNATIONAL PTE LTD • Singapore

On-site
SGD 100,000 - 180,000
Project Engineer (Pharmaceutical)
Project Engineer (Pharmaceutical)

Amaris Consulting • Singapore

On-site
SGD 90,000 - 150,000
Global community of professionals
Internal Academy training
Team events and network gatherings
+1
Senior DevOps Engineer – Elastic Stack & Kafka
Senior DevOps Engineer – Elastic Stack & Kafka

MANTU INTERNATIONAL PTE LTD • Singapore

On-site
SGD 120,000 - 180,000
International community
Amaris Academy
Team events
Senior Cyber Incident Responder
Senior Cyber Incident Responder

Keyrus • Singapore

On-site
SGD 120,000 - 180,000
L2 Support Engineer (VIP Support)
L2 Support Engineer (VIP Support)

MANTU INTERNATIONAL PTE LTD • Singapore

On-site
SGD 90,000 - 150,000
L2 Support Engineer (VIP Support)
L2 Support Engineer (VIP Support)

Amaris Consulting Pte Ltd • Singapore

On-site
SGD 72,000 - 96,000