Cyber Incident Responder

Amaris Consulting

Singapore

On-site

SGD 90,000 - 130,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Amaris Consulting in Singapore is seeking a Cyber Incident Responder with expertise in cybersecurity to strengthen their monitoring and detection capabilities. This role will focus on designing security use cases, enhancing SIEM capabilities, and leading incident response activities.

The ideal candidate will possess strong experience in incident response, detection engineering, and collaboration across global security teams. The position requires a Bachelor's degree in a relevant field and extensive hands-on experience with security tools.

Qualifications

  • 7+ years of experience in cybersecurity operations or incident response.
  • At least 4+ years focused on security use case design and development.
  • Strong hands-on experience with ELK in a cybersecurity environment.

Responsibilities

  • Design and enhance security detection use cases using MITRE ATT&CK.
  • Conduct threat hunting and analysis to detect emerging threats.
  • Collaborate with teams to improve monitoring and detection capabilities.

Skills

SIEM platforms expertise
Incident response techniques
Threat hunting
Security analysis
Stakeholder management

Education

Bachelor’s degree in Cybersecurity or related field

Tools

ELK (Elastic, Logstash, Kibana)
Python
PowerShell
Bash
SQL

Job description

We are looking for an experienced Cyber Incident Responder to strengthen cybersecurity monitoring, detection engineering, and incident response capabilities across regional operations.

This role will play a key part in designing and enhancing security detection use cases, improving SIEM/SOAR capabilities, supporting SOC operations, and leading security investigation activities based on evolving cyber threats and real-world attack scenarios. The ideal candidate combines strong hands-on expertise in detection engineering, incident response, threat hunting, and security operations with the ability to work effectively across regional and global stakeholders.

A major focus of this role is security use case design and development, leveraging MITRE ATT&CK methodologies, SIEM technologies, and security automation capabilities to improve overall threat detection and incident response effectiveness.

Your Missions
Security Detection Engineering & Threat Monitoring
  • Design, develop, implement, and enhance security detection use cases based on real-world attack scenarios and MITRE ATT&CK framework
  • Strengthen cybersecurity detection capabilities across enterprise environments through continuous improvement of detection logic and monitoring strategies
  • Enhance SIEM and SOAR capabilities to improve threat detection, alert enrichment, automation, and incident response efficiency
  • Perform threat hunting and proactive security analysis to identify emerging threats, suspicious activities, and detection gaps
  • Develop and enrich security monitoring content, use cases, correlation rules, and detection models across multiple security layers
  • Collaborate with security operations teams to improve monitoring coverage and detection effectiveness for enterprise security events
  • Investigate cybersecurity incidents and assess the severity, impact, and scope of security events
  • Lead and support incident response activities including detection, triage, investigation, containment, remediation, recovery, and reporting
  • Perform log analysis, event correlation, and forensic investigation activities across enterprise environments
  • Act as a subject matter expert for security investigations, malware analysis, and detection engineering activities
  • Identify recurring security issues, operational gaps, and cyber risks, while recommending mitigation plans and process improvements
  • Support 24/7 SOC operations and collaborate closely with security monitoring teams on critical incidents and escalations
Security Operations & Continuous Improvement
  • Work closely with regional and global cybersecurity teams to improve operational readiness and incident response effectiveness
  • Contribute to the continuous improvement of SOC processes, operational playbooks, incident response procedures, and security monitoring frameworks
  • Support integrated security monitoring and incident handling initiatives across multiple cybersecurity functions
  • Participate in audit, compliance, governance, and control-related activities to ensure alignment with internal security standards and regulatory requirements
  • Contribute to cybersecurity reporting, metrics, and operational improvement initiatives across the organization
About You
  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Engineering, or related field
  • 7+ years of experience in cybersecurity operations, incident response, or security engineering, with at least 4+ years specifically focused on security use case design and development
  • Strong hands-on experience with SIEM platforms, particularly ELK (Elastic, Logstash, Kibana) within a cybersecurity operations environment (not limited to observability use cases)
  • Proven experience in security use case design using MITRE ATT&CK framework, including threat modelling, detection engineering, and detection logic development
  • Solid understanding of the full incident response lifecycle including detection, triage, investigation, containment, remediation, and reporting
  • Experience in threat hunting, security event investigation, and log analysis across enterprise environments
  • Knowledge of Java development for security use case coding and customization within security platforms
  • Good working knowledge of Linux environments (RedHat/Ubuntu)
  • Experience with scripting and automation using Python, PowerShell, Bash, or SQL
  • Strong analytical, troubleshooting, and problem-solving capabilities with the ability to work autonomously in high‑pressure environments
  • Strong stakeholder management and communication skills, with experience collaborating across regional and global security teams
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cyber Incident Responder
Senior Cyber Incident Responder

Keyrus • Singapore

On-site
SGD 120,000 - 180,000
Senior Cyber Security Consultant
Senior Cyber Security Consultant

Singtel • Singapore

On-site
Confidential
Cyber Threat Intelligence & Incident Response Specialist
Cyber Threat Intelligence & Incident Response Specialist

PERCEPT SOLUTIONS PTE. LTD. • Singapore

On-site
SGD 180,000 - 260,000
Senior Lead Cyber Detection Engineer
Senior Lead Cyber Detection Engineer

NETS • Singapore

On-site
SGD 180,000 - 280,000
Cyber Incident Responder (Python / ELK / Java / SIEM)
Cyber Incident Responder (Python / ELK / Java / SIEM)

Maltem Asia-Pacific • Singapore

On-site
SGD 120,000 - 180,000
Cybersecurity Engineer – Incident Response
Cybersecurity Engineer – Incident Response

Jobtailor • Singapore

Hybrid
SGD 90,000 - 140,000
Cyber Incident Responder
Cyber Incident Responder

AMARIS GROUP SA • Singapore

On-site
SGD 80,000 - 120,000
Robust training system with 250+ modules
Vibrant workplace events
Focus on sustainability and community impact
Senior Cyber Defence Engineer
Senior Cyber Defence Engineer

Newbridge • Singapore

On-site
SGD 180,000 - 280,000
Senior Cyber Defence Engineer [Threat Intel & Response]
Senior Cyber Defence Engineer [Threat Intel & Response]

Newbridge • Singapore

On-site
SGD 120,000 - 180,000
Cybersecurity Consultant
Cybersecurity Consultant

PERCEPT SOLUTIONS PTE. LTD. • Singapore

On-site
SGD 120,000 - 180,000