Cyber Security Analyst (WAF, IPS)

QUESS SELECTION & SERVICES PTE. LTD.

Singapore

On-site

SGD 90,000 - 150,000

Full time

3 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

QUESS SELECTION & SERVICES PTE. LTD. is seeking an experienced cybersecurity professional to administer WAF, IPS and DAM systems, lead maintenance contracts, and triage security incidents across cloud and on‑prem environments.

You will leverage AI/ML tools for real‑time investigations, analyze SIEM data, and contribute to readiness exercises while ensuring continuous monitoring and timely management reporting.

Qualifications

  • At least 3–5 years of cybersecurity experience with hands‑on WAF/IPS/DAM in mid/large environments.
  • Experience in onboarding apps to WAF and DAM for monitoring and triage.
  • Familiar with SIEM, incident response, and vulnerability management processes.
  • Demonstrated ability to analyze security events and logs to identify root causes.
  • Knowledge of TCP/IP, DNS, TLS, HTTP/S, and OWASP Top 10.
  • Certifications like CISSP, GCIH, GCIA, CEH are advantageous.

Responsibilities

  • Administer WAF, IPS, and DAM security systems with ongoing tuning.
  • Secure maintenance contracts via ITQ/RFP processes.
  • Onboard internet apps to WAF and critical databases to DAM for monitoring.
  • Use AI/ML tools to monitor investigations and initiate containment.
  • Analyze large datasets, correlate with SIEM, and investigate anomalies.
  • Conduct investigations in cloud, on‑prem, and hybrid setups.
  • Prepare weekly/monthly security metrics for management reports.
  • Participate in readiness exercises (red team, cyber range).
  • Perform ethical hacking to identify threats and vulnerabilities.
  • Monitor, track, and close security events and requests from SOC.

Skills

WAF management
IPS management
DAM administration
Cybersecurity investigations
SIEM analysis
Automation scripting
Data visualization
MITRE ATT&CK
Governance
Networking basics

Education

Diploma or degree in Cybersecurity

Tools

SIEM platforms
Threat intelligence feeds

Job description

Key Responsibilities
  • Proven experience administering Web Application Firewall (WAF), Intrusion Prevention System (IPS) and Database Activity Monitoring (DAM) Security Systems.
  • Ensure these systems have valid maintenance support contract with the product vendors through preparing and awarding of these maintenance support contracts via ITQ/RFP to the vendors.
  • Onboard internet facing applications to WAF and critical databases to DAM for monitoring and triage of abnormal alerts and activities.
  • Knowledge of using AI-driven and Machine Learning tools to monitor and analyse real‑time security investigations to initiate triage, containment and remediation of security threats.
  • Using analytical and data visualization tools to automate the analysis and provide insights of large dataset and correlate with SIEM and other sources of information and conduct investigative works into all traffic anomalies against established, historical baselines to identify the root cause to an incident.
  • Support in‑depth triage and investigations of cyber incidents in cloud, on‑premises, and hybrid environments
  • Prepare relevant Systems Operations metrics and statistics for weekly, monthly and quarterly management reporting.
  • Participate in readiness exercises such as red team, table‑tops, cyber range, etc.
  • Knowledge in ethical hacking to identify potential threats and expose vulnerabilities to protect the organisation from malicious attackers.
  • Responsible for continuous monitoring, tracking and closure of security events and requests from managed SOC, systems and users.
  • Stay current with the latest Cyber threats, Attacks and vulnerabilities, and updated with the evolving and emerging attack techniques and methods.
  • Work on other project and tasks duties.
Qualifications
  • Experience: At least three‑five years of relevant cybersecurity experience, including three years of hands‑on administration and investigation using WAF, IPS and/or DAM in a medium‑to‑large enterprise. Experience in a financial institution or regulated environment is preferred.
  • WAF: Practical experience with application and DNS‑zone onboarding, policy and rule configuration, certificate lifecycle management, bot and DDoS controls, attack analysis, tuning and troubleshooting.
  • IPS: Practical knowledge of inline prevention, signatures, severity and actions, policy tuning, traffic analysis and investigation of exploitation attempts; familiarity with firewall‑integrated IPS is advantageous.
  • DAM: Experience onboarding databases, validating agents or log sources, defining policies, monitoring privileged and anomalous activity, and investigating database access across on‑premises and cloud environments.
  • Investigation: Demonstrated ability to analyse security events, network and application logs, HTTP/S traffic and packet‑level data; correlate multiple data sources; identify indicators of compromise and attack paths; and produce defensible findings.
  • Technical foundation: Strong knowledge of TCP/IP, DNS, TLS, HTTP/S, web application architecture, APIs, databases, firewalls, VPNs and common system, network, application and database attacks, including the OWASP Top 10.
  • Security operations: Experience leveraging SIEM and ticketing or case‑management platforms, detection tuning, incident response processes and MITRE ATT&CK.
  • Automation: Ability to use scripting, analytics, automation or AI‑assisted capabilities to enrich investigations, process large datasets, identify patterns and streamline repeatable operational tasks, with appropriate validation of outputs.
  • Governance: Familiarity with change, access, configuration, incident, evidence and vendor‑management processes. Knowledge of applicable MAS Technology Risk Management and Cyber Hygiene requirements, the NIST Cybersecurity Framework and relevant security standards is advantageous.
  • Qualifications: Diploma or degree in Cybersecurity, Information Technology, Computer Science or a related discipline, or equivalent practical experience.
  • Certifications: Relevant certifications such as CISSP, GCIH, GCIA, CEH, CSA, vendor WAF/IPS/DAM certifications or equivalent are advantageous.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

I44 - Security Analyst (104)
I44 - Security Analyst (104)

FPT Asia Pacific Pte Ltd • Singapore

On-site
SGD 90,000 - 120,000
I44 - Security Analyst (104)
I44 - Security Analyst (104)

FPT Asia Pacific • Singapore

On-site
SGD 70,000 - 110,000
Senior Cyber Security Consultant
Senior Cyber Security Consultant

Singtel • Singapore

On-site
Confidential
IT Security Officer (Central / 5 days / Standby required)
IT Security Officer (Central / 5 days / Standby required)

ALPSOFT TECHNOLOGIES PTE. LTD. • Singapore

On-site
SGD 60,000 - 100,000
Senior Cybersecurity Engineer
Senior Cybersecurity Engineer

Enggsol Pte Ltd • Singapore

On-site
SGD 90,000 - 130,000
IT Security Operations
IT Security Operations

U3 INFOTECH PTE. LTD. • Singapore

On-site
SGD 120,000 - 180,000
Senior Cyber Security Analyst — WAF, IPS & DAM Expert
Senior Cyber Security Analyst — WAF, IPS & DAM Expert

QUESS SELECTION & SERVICES PTE. LTD. • Singapore

On-site
SGD 90,000 - 150,000
Cybersecurity Engineer * (AMK)
Cybersecurity Engineer * (AMK)

MAESTRO HUMAN RESOURCE PTE. LTD. • Singapore

On-site
SGD 90,000 - 130,000
Cybersecurity Consultant
Cybersecurity Consultant

PERCEPT SOLUTIONS PTE. LTD. • Singapore

On-site
SGD 120,000 - 180,000
System Administrator
System Administrator

Ensign InfoSecurity • Singapore

On-site
SGD 60,000 - 90,000