Cyber Security Resident Engineer - Incident Response & SIEM

Ensign InfoSecurity

Singapore

On-site

SGD 70,000 - 100,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Ensign InfoSecurity in Singapore seeks an experienced cybersecurity professional to monitor client environments and respond to incidents. The role involves analyzing security alerts, managing detection use cases, and collaborating with clients and teams.

The ideal candidate should have a degree in a relevant field, significant experience in a SOC environment, and certifications like GCIH. Key skills include incident response and effective communication with clients. This position offers a dynamic work environment focused on cybersecurity.

Qualifications

  • 3 to 7 years of experience in cybersecurity operations or a Security Operations Centre (SOC) environment.
  • Hands-on experience with SIEM platforms and solid understanding of network, Windows, and Linux infrastructure.
  • GIAC Certified Incident Handler (GCIH) or equivalent certification required.

Responsibilities

  • Monitor client environments using SIEM and EDR platforms for cybersecurity threats.
  • Analysed security alerts escalated from client teams and lead incident response.
  • Manage detection use cases and automation scripts on SOAR.

Skills

Cybersecurity operations
Incident response
Security alert analysis
Effectively communicating with clients

Education

Degree in Computer Science, Information Security, or related discipline

Tools

SIEM platforms
SOAR platforms

Job description

  • Monitor client environments using SIEM and/or EDR platforms to detect, triage, and respond to cybersecurity threats in accordance with agreed SOPs and industry best practices
  • Analyse and investigate security alerts escalated from client teams, MSSPs, and internal systems; lead or support incident response through to closure
  • Triage alerts from the SIEM to identify notable alerts for escalation, based on established operating procedures or industry best practices
  • Advise clients on possible follow-up actions and remediation measures for escalated alerts
  • Respond to incidents and critical alerts outside of office hours when required
  • Perform indicator of compromise (IOC) searches and triage incoming threat intelligence to assess relevance to client assets
  • Gather and report on threat intelligence using the client's Threat Intelligence Platform
  • Coordinate with client stakeholders including IT, infrastructure, application, and business teams during active incidents and programme activities
  • Collaborate with MSSPs and Ensign delivery teams on detection tuning to reduce noise and improve fidelity
  • Manage detection use cases, dashboards, and reports on SIEM: perform monthly and ad hoc reviews, validate and maintain existing rules, and develop and implement new use cases
  • Manage playbooks, automation scripts, and integrations on SOAR: review, validate, maintain, and develop new playbooks; optimise existing ones for accuracy and efficiency
  • Any other tasks as assigned

Requirements

  • Degree in Computer Science, Information Security, or a related discipline
  • 3 to 7 years of experience in cybersecurity operations or a Security Operations Centre (SOC) environment
  • Hands-on experience with SIEM platforms and solid understanding of network, Windows, and Linux infrastructure
  • Experience in security, network, and cyber threat analysis
  • Demonstrated ability to triage, investigate, and respond to security incidents independently
  • Comfortable operating in a client-facing, on-site environment with direct accountability to client stakeholders
  • Clear written and verbal communication; able to produce structured incident reports and brief senior stakeholders
  • GIAC Certified Incident Handler (GCIH) or equivalent certification required

Preferred Skills / Qualities

  • Working knowledge of SOAR platforms; experience with playbook development or automation scripting
  • Knowledge of cloud infrastructure security (AWS, Azure, or GCP)
  • Familiarity with Threat Intelligence Platforms and IOC management workflows
  • Exposure to Singapore regulatory frameworks: CSA advisories, IMDA guidelines, MAS TRM
  • Additional certifications such as GCFE, GCFA, OSCP, or vendor product certifications
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Resident Engineer
Cyber Security Resident Engineer

Ensign InfoSecurity • Singapore

On-site
SGD 70,000 - 100,000
Lead Security Engineer, IT Security Operations Engineering and Technology Singapore Experienced[...]
Lead Security Engineer, IT Security Operations Engineering and Technology Singapore Experienced[...]

SEA Singapore • Singapore

On-site
SGD 120,000 - 180,000
Security Operations Engineer
Security Operations Engineer

DADACONSULTANTS PTE. LTD. • Singapore

On-site
SGD 90,000 - 150,000
Lead Consultant, IT Security (SOC Experience)
Lead Consultant, IT Security (SOC Experience)

NCS Group • Singapore

On-site
SGD 80,000 - 120,000
Senior Cyber Security Consultant
Senior Cyber Security Consultant

Singtel • Singapore

On-site
Confidential
Security Engineer
Security Engineer

CodSec • Singapore

On-site
SGD 90,000 - 150,000
Lead Cybersecurity Specialist (Security Operations)
Lead Cybersecurity Specialist (Security Operations)

JJ Consulting Services • Singapore

On-site
SGD 80,000 - 120,000
Senior Lead SOC Incident Responder & Security Incident Manager
Senior Lead SOC Incident Responder & Security Incident Manager

NETS • Singapore

On-site
SGD 180,000 - 260,000
Vice President, Threat Detection Engineer
Vice President, Threat Detection Engineer

Singapore Exchange Limited • Singapore

On-site
SGD 230,000 - 350,000
Cybersecurity Consultant
Cybersecurity Consultant

PERCEPT SOLUTIONS PTE. LTD. • Singapore

On-site
SGD 120,000 - 180,000