Cyber Incident Responder (Python / ELK / Java / SIEM)

Maltem Asia-Pacific

Singapore

On-site

SGD 120,000 - 180,000

Full time

8 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Maltem Asia-Pacific in Singapore is seeking a Cyber Incident Responder for our Banking domain client. You will lead security usecase definition, design, implementation and enrichment within the IT Production Security Investigation & Incident Response team, aligning with MITRE ATT&CK and ensuring robust detection across layers.

You will investigate incidents, hunt threats, and oversee 24/7 SOC activities, collaborating with stakeholders, interpreting logs into threat models, and pursuing

Qualifications

  • 7+ years in cybersecurity incident response.
  • Experience designing and developing security use cases.
  • Strong Linux (RedHat/Ubuntu) knowledge.
  • Ability to translate logs into threat models.
  • Experience with incident response, remediation and reporting.

Responsibilities

  • Lead security usecase definition, design, and enrichment.
  • Oversee detection capabilities of the 24/7 regional SOC.
  • Respond to cyber incidents and assess severity.
  • Collaborate with stakeholders across teams during incidents.
  • Apply MITRE ATT&CK framework to threat modeling.

Skills

Cyber incident response
Threat hunting
SIEM
ELK Stack
Python scripting
Linux
MITRE ATT&CK
English communication
Automation mindset

Tools

ELK Stack
SIEM platforms

Job description

Maltem SG is currently seeking a Cyber Incident Responder for our Banking domain Client.

Summary:

  • Lead technical activities (security usecase definition, design, implementation & enrichment) in the team of IT Production Security Investigation & Incident Response based on real-world attack scenarios and framework like MITRE ATT&CK, ensuring robust security detection posture across various layers.
  • Understand ongoing security threats in the wild and propose security usecase to detect and when possible, protect or mitigate.
  • Be autonomous on technical activities (definition, R&D/threat hunting) in the team of IT Production Security Investigation & Incident Response and oversee the detection capabilities of the 24/7 regional IT Production SOC
  • Respond to Cyber / IT security incidents and evaluates the type and severity of security events.
Technical Skills
  • Requires a minimum of 7 or more years of experience as security professional
  • Experience in security usecase design/development with understanding of Java language.
  • Good working knowledge of Linux (RedHat/Ubuntu).
  • Working knowledge to interpret security logs or instructions into threat models. SecOPS-DevOPS mindset & skills.
  • Experience and knowledge in investigating incidents, remediation, tracking and follow-up for incident closure with concerned teams, stakeholders.
  • Thorough understanding of technologies and security concepts, with knowledge & hands on experience in SIEM Product and Security Incident Management
  • Experience on incident response activities (threat hunting, event analysis, incident investigation, reporting)
  • Comfortable working with and making the most of large data sets (collection, analysis, response), creating content/use cases/models and bringing an automation mindset. Personal Attributes
  • Strong problem-solving skills Good communication skills (English is MUST, French is added advantage)
  • Positive attitude, willing to upskill and carry out in-depth troubleshooting
  • Has the ability to work autonomously and think on feet, be-proactive.
  • Good interpersonal skills and team player
  • High energy level coupled with a desire to take on responsibility
  • Able to multi-task & deliver within agreed deadlines.
Must have:
  • Candidate MUST have 7 or more years of experience on overall cybersecurity incident response with 4+ years specifically on security usecase design, development, coding.
  • Experience in SIEM on ELK(Elastic Logstash Kibana) stack is a plus
  • Professional credentials in one of the relevant IT Security disciplines is a plus (SANS / CISSP / OSCP)
  • Experience in common scripting languages such as Python, PowerShell, Bash, SQL is a plus
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Incident Responder
Cyber Incident Responder

Amaris Consulting • Singapore

On-site
SGD 90,000 - 130,000
Senior Cyber Incident Responder (Python, ELK, SIEM)
Senior Cyber Incident Responder (Python, ELK, SIEM)

Maltem Asia-Pacific • Singapore

On-site
SGD 120,000 - 180,000
Senior Cyber Incident Responder
Senior Cyber Incident Responder

Keyrus • Singapore

On-site
SGD 120,000 - 180,000
Senior Cyber Security Consultant
Senior Cyber Security Consultant

Singtel • Singapore

On-site
Confidential
Cyber Security Resident Engineer - Incident Response & SIEM
Cyber Security Resident Engineer - Incident Response & SIEM

Ensign InfoSecurity • Singapore

On-site
SGD 70,000 - 100,000
Senior SOC Analyst
Senior SOC Analyst

dacta sg pte. ltd. • Singapore

On-site
SGD 120,000 - 180,000
Senior Cyber Threat Intelligence & Incident Response Specialist
Senior Cyber Threat Intelligence & Incident Response Specialist

SPH Media Fund • Singapore

On-site
SGD 120,000 - 190,000
Presales Consultant (Cybersecurity)
Presales Consultant (Cybersecurity)

DACTA SG PTE. LTD. • Singapore

On-site
SGD 120,000 - 190,000
Security Engineer (Elastic stack / Python / RHEL / Ubuntu)
Security Engineer (Elastic stack / Python / RHEL / Ubuntu)

MALTEM ASIA PTE. LTD. • Singapore

On-site
SGD 90,000 - 140,000
Cybersecurity Engineer – Incident Response
Cybersecurity Engineer – Incident Response

Jobtailor • Singapore

Hybrid
SGD 90,000 - 140,000