Cyber Security Engineer

Astek

Singapore

On-site

SGD 90,000 - 150,000

Full time

3 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Astek is hiring a Detection Engineer to support the Security Exposure and Third-Party Cyber Assurance Centre of Excellence within CASD—External Threat Operations. The role covers continuous monitoring across SEM and TPCA, plus third-party risk assessments and threat validation.

The successful candidate will build scripts and dashboards, leverage CTI, and collaborate with stakeholders to reduce exposure timelines and improve security posture across the organization and its partners.

Qualifications

  • Degree in Computer Science, Information Technology, or a related discipline.
  • 3–5 years hands-on cybersecurity experience in operations, exposure management, or third-party risk.
  • Experience conducting third‑party/vendor security assessments (VDD, ODD, SIG).
  • Knowledge of NIST, ISO 27001, CIS Controls.
  • Hands-on experience with ASM/EASM, cyber exposure management, digital risk monitoring, dark-web monitoring, or CTI platforms.
  • Strong scripting skills in Python, PowerShell, or Bash.
  • Understanding of TCP/IP, DNS, HTTP/S; familiar with AWS, Azure, GCP.
  • Understanding of third- and fourth-party cyber risk and supply chain exposure.
  • Excellent analytical and documentation abilities; strong stakeholder communication.

Responsibilities

  • Operate and maintain always-on security exposure and external threat monitoring platforms.
  • Monitor organisation, portfolio companies, and third parties for internet-facing vulnerabilities and threats.
  • Perform ASM/EASM activities to identify, assess, validate, and prioritise external exposures.
  • Conduct third-party/vendor cybersecurity assessments, including VDD/ODD/SIG.
  • Assess third-party security controls against NIST, ISO 27001, CIS Controls.
  • Leverage CTI, digital risk, and dark-web monitoring to identify threats.
  • Develop scripts in Python/PowerShell/Bash to automate monitoring and reporting.
  • Build dashboards and cyber posture metrics using data lakes.
  • Document findings for technical and business stakeholders.
  • Support continuous improvement of detection logic and exposure management capabilities.

Skills

Attack Surface Management
Cyber Threat Intelligence
Digital risk monitoring
Dark-web monitoring
Python
PowerShell
Bash
TCP/IP
DNS
HTTP/S
AWS
Azure
GCP
VDD/ODD/SIG
Third-Party Cyber Risk
Analytical thinking

Education

Bachelor's degree in Computer Science or Information Technology

Tools

ASM/EASM platforms
CTI platforms
Data Lake platforms

Job description

Detection Engineer – Security Exposure & Third-Party Cyber Assurance
Role Overview

We are looking for a Detection Engineer to support the build-out and operations of the Security Exposure and Third-Party Cyber Assurance Centre of Excellence, under Cybersecurity Assurance and Defense (CASD) – External Threat Operations.

The role will provide hands-on technical and operational support across two key areas:

  • Security Exposure Management (SEM): Continuous, outside-in monitoring of the organisation and its portfolio companies’ internet-facing attack surface.
  • Third-Party Cyber Assurance (TPCA): Cybersecurity due diligence and continuous assurance across third parties and the broader supply chain.

The successful candidate will operate continuous monitoring platforms, conduct third-party cyber assessments, validate active and emerging threats, and coordinate remediation to reduce the time between exposure identification and potential exploitation.

Key Responsibilities
  • Operate and maintain always-on security exposure and external threat monitoring platforms.
  • Monitor the organisation, portfolio companies, and third parties for internet-facing vulnerabilities, exposures, and emerging cyber threats.
  • Perform Attack Surface Management (ASM/EASM) activities to identify, assess, validate, and prioritise external security exposures.
  • Conduct third-party/vendor cybersecurity assessments, including security questionnaires and due diligence activities such as VDD, ODD, and SIG.
  • Assess third-party security controls against established frameworks including NIST, ISO 27001, and CIS Controls.
  • Leverage Cyber Threat Intelligence (CTI), digital risk, and dark-web monitoring to identify and validate relevant threats.
  • Investigate and validate high-risk or imminent security threats and coordinate appropriate remediation with relevant stakeholders.
  • Analyse third- and fourth-party cyber risks and their potential impact across the organisation and supply chain.
  • Develop scripts and automation using Python, PowerShell, or Bash to streamline monitoring, analysis, reporting, and operational activities.
  • Build and maintain operational dashboards, reporting capabilities, and cyber posture metrics using data lake platforms.
  • Document findings, processes, assessments, and remediation actions clearly for both technical and business stakeholders.
  • Support continuous improvement of detection logic, control baselines, monitoring processes, and exposure management capabilities.
Requirements
  • Degree in Computer Science, Information Technology, or a related discipline.
  • 3–5 years of hands‑on cybersecurity experience, preferably within cybersecurity operations, attack surface/exposure management, third‑party cyber risk assessment, or data lake environments.
  • Practical experience conducting third‑party/vendor security assessments and questionnaires, including VDD, ODD, and SIG.
  • Good knowledge of cybersecurity frameworks such as NIST, ISO 27001, and CIS Controls.
  • Hands‑on experience with ASM/EASM, cyber exposure management, digital risk monitoring, dark- web monitoring, and/or Cyber Threat Intelligence (CTI) platforms.
  • Strong scripting capabilities using Python, PowerShell, or Bash, particularly for automation and reporting.
  • Strong understanding of TCP/IP, DNS, HTTP/S, and common security exposures across AWS, Azure, and GCP.
  • Understanding of third- and fourth-party cyber risk and how security exposure can propagate through the supply chain.
  • Strong analytical and documentation skills, with the ability to handle sensitive security findings appropriately.
  • Good communication and stakeholder management skills across technical and business teams.
  • Collaborative, adaptable, and comfortable working in a fast‑evolving cybersecurity environment.
Good to Have
  • Certifications such as Security+, CEH, GIAC (GSEC/GCIH), CompTIA CySA+, or equivalent.
  • CISSP Associate or CISM candidature.
  • Experience developing cyber posture scorecards and operational security dashboards.
  • Familiarity with detection engineering, including tuning detection logic and refining security control baselines as capabilities mature.
Key Skills / Technologies

SEM | TPCA | ASM/EASM | CTI | Third-Party Cyber Risk | VDD/ODD | SIG | NIST | ISO 27001 | CIS Controls | Digital Risk & Dark-Web Monitoring | Python | PowerShell | Bash | TCP/IP | DNS | HTTP/S | AWS | Azure | GCP | Data Lakes | Detection Engineering

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Detection Engineer – EASM / ASM / Cyber Threat Intelligence (CTI)
Detection Engineer – EASM / ASM / Cyber Threat Intelligence (CTI)

ASTEK SINGAPORE INNOVATION TECHNOLOGY PTE. LTD. • Singapore

On-site
SGD 90,000 - 150,000
Detection Engineer
Detection Engineer

U3 PROJECTS PTE. LTD. • Singapore

On-site
SGD 90,000 - 160,000
Certifications support
Dashboard tooling exposure
Detection Engineer
Detection Engineer

U3 INFOTECH PTE. LTD. • Singapore

On-site
SGD 90,000 - 150,000
Threat Detection Engineer - Contract
Threat Detection Engineer - Contract

NTT SINGAPORE PTE. LTD. • Singapore

On-site
SGD 70,000 - 110,000
Detection Engineer
Detection Engineer

U3 SOLUTIONS PTE. LTD. • Singapore

On-site
SGD 100,000 - 170,000
Cybersecurity Detection Engineer
Cybersecurity Detection Engineer

ASTEK SINGAPORE INNOVATION TECHNOLOGY PTE. LTD. • Singapore

On-site
SGD 90,000 - 140,000
Senior Cyber Security Consultant
Senior Cyber Security Consultant

Singtel • Singapore

On-site
Confidential
Cybersecurity Detection Engineer – Security Exposure & Third-Party Risk_ Contract
Cybersecurity Detection Engineer – Security Exposure & Third-Party Risk_ Contract

NTT SINGAPORE PTE. LTD. • Singapore

On-site
SGD 90,000 - 130,000
Cybersecurity Consultant
Cybersecurity Consultant

PERCEPT SOLUTIONS PTE. LTD. • Singapore

On-site
SGD 120,000 - 180,000
Cyber Threat Intelligence & Incident Response Specialist
Cyber Threat Intelligence & Incident Response Specialist

PERCEPT SOLUTIONS PTE. LTD. • Singapore

On-site
SGD 180,000 - 260,000