Cybersecurity Engineer – Detection Engineering

Jobtailor

Singapore

On-site

SGD 70,000 - 120,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor in Singapore seeks a Security Detection Engineer to develop and tune detection rules for government environments. You will analyze SIEM/EDR logs, differentiate real threats from benign activity, and research attacker TTPs to improve coverage across on-premises and cloud systems.

The role requires hands-on experience with Sigma, KQL, SPL, EQL, YARA, and automation, plus collaboration with incident responders and security engineers to operationalize detections.

Qualifications

  • Degree in Cybersecurity, Information Security, Computer Science or a related field.
  • Certifications from OffSec, SANS, GIAC or related for cloud security, detection engineering, incident response, malware analysis, or pen-testing.
  • Minimum 3 years’ experience in security operations, incident response or related cybersecurity fields in enterprise/government settings.
  • Knowledge of MITRE ATT&CK and attacker TTPs, and detection use cases.
  • Hands-on experience with SIEM, EDR, SOAR; scripting (Python/PowerShell); automation.

Responsibilities

  • Develop, implement, and document detection rules using Sigma, KQL, SPL, EQL, or YARA.
  • Analyze security logs and alerts from SIEM and EDR within government environments.
  • Differentiate true threats from benign activity and reduce false positives across networks, endpoints, and cloud.
  • Research threats targeting government networks, endpoints, and cloud environments.
  • Collaborate with security analysts and incident responders on government IR protocols.
  • Operationalize detection rules for accurate alert escalation.
  • Collaborate with security engineers to integrate detection systems.

Skills

Detection Rule Development
Threat Analysis
Automation
Scripting (Python/PowerShell)
Collaboration

Education

Bachelor's degree in Cybersecurity, Information Security, or Computer Science

Tools

Splunk
Elastic
SIEM
EDR
SOAR

Job description

  • Develop, implement, and document security detection rules using frameworks and languages such as Sigma, KQL, SPL, EQL, or YARA, along with playbooks to identify potential threats and malicious activity targeting government systems in on-premises and cloud environments.
  • Analyze security logs and alerts from SIEM and EDR systems deployed within the government environment.
  • Differentiate true threats from benign activity and reduce false positives across network, endpoint, and cloud security domains.
  • Research threats targeting government networks, endpoints, and cloud environments.
  • Write and tune detection rules and signatures for enhanced threat detection while reducing benign alerts, leveraging automation for efficiency.
  • Collaborate with security analysts and incident responders on government-specific incident response protocols and investigations.
  • Operationalize detection rules for accurate alert escalation.
  • Collaborate with security engineers to integrate detection systems by providing detection requirements and defining problem areas.
  • Maintain understanding of evolving threat landscapes, attacker TTPs, security trends, and detection development best practices.
Requirements
  • Degree in Cybersecurity, Information Security, Computer Science or a related field.
  • Relevant cybersecurity certifications from OffSec, SANS, GIAC or related institution in cloud security, detection engineering, incident response, malware analysis, or security penetration testing domain.
  • A minimum of 3 years’ experience in security operations, incident response or related cybersecurity fields, demonstrating a proven track record in threat detection and analysis, preferably within an enterprise or government environment.
  • Understand security concepts and cybersecurity frameworks such as MITRE ATT&CK, including commonly used attacker TTPs and their detection.
  • Demonstrate strong technical foundation, preferably with hands-on experience in SIEM, EDR, SOAR, scripting languages such as Python and PowerShell, and automation tools.
  • Working knowledge of Sigma, YARA-L, Splunk SPL, Microsoft KQL, or Elastic EQL, with the ability to translate threat intelligence and attacker TTPs into structured, testable detection logic.
  • Experience with version control processes and tools and detections-as-code workflow, including peer review and testing detection logic against sample log data.
  • Excellent analytical and problem-solving skills; ability to prioritise tasks and willingness to learn new technology and approaches.
  • Strong communication and collaboration skills to work effectively on intra-team and inter-team tasks.
Core Competencies

Demonstrates expertise in developing and implementing security detection rules using frameworks such as Sigma and KQL, with a strong foundation in cybersecurity principles and hands-on experience in SIEM and EDR systems. Proven ability to analyze threats, reduce false positives, and collaborate effectively within government environments.

Highest-signal resume keywords
  • Security Detection Rule Development
  • SIEM and EDR Experience
  • Cybersecurity Certifications
  • Threat Analysis and Research
  • Collaboration with Security Teams
Hard Skills
  • Security Detection Rules
  • Threat Detection
  • Incident Response
  • Cybersecurity Frameworks
  • Scripting Languages
  • Automation Tools
  • Version Control Processes
  • Detection Logic Development
  • Log Analysis
  • False Positive Reduction
Soft Skills
  • Analytical Skills
  • Problem-Solving Skills
  • Communication Skills
  • Collaboration Skills
  • Task Prioritization
Certifications & Qualifications
  • OffSec Certification
  • SANS Certification
  • GIAC Certification
  • Cloud Security Certification
  • Incident Response Certification
Industry Keywords
  • Cybersecurity
  • Threat Intelligence
  • Government Security
  • Malware Analysis
  • Detection Engineering
Tools & Technologies
  • Sigma
  • KQL
  • SPL
  • EQL
  • YARA
  • SIEM
  • EDR
  • SOAR
  • Splunk
  • Elastic
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cyber Security Consultant
Senior Cyber Security Consultant

Singtel • Singapore

On-site
Confidential
Cybersecurity Engineer – Incident Response
Cybersecurity Engineer – Incident Response

Jobtailor • Singapore

Hybrid
SGD 90,000 - 140,000
Senior Lead Cyber Detection Engineer
Senior Lead Cyber Detection Engineer

network for electronic transfers (singapore) pte ltd • Singapore

On-site
SGD 180,000 - 300,000
Senior Lead Cyber Detection Engineer
Senior Lead Cyber Detection Engineer

NETS • Singapore

On-site
SGD 180,000 - 280,000
Senior Lead Cyber Detection Architect
Senior Lead Cyber Detection Architect

network for electronic transfers (singapore) pte ltd • Singapore

On-site
SGD 180,000 - 300,000
Security Engineer
Security Engineer

INFINITY CYBERSEC PTE. LTD. • Singapore

On-site
SGD 90,000 - 140,000
Threat Detection Engineer — Cybersecurity & SIEM
Threat Detection Engineer — Cybersecurity & SIEM

Assurity Trusted Solutions • Singapore

On-site
SGD 90,000 - 130,000
Cyber Incident Responder
Cyber Incident Responder

Amaris Consulting • Singapore

On-site
SGD 90,000 - 130,000
Vice President, Threat Detection Engineer
Vice President, Threat Detection Engineer

SGX Group • Singapore

On-site
SGD 180,000 - 280,000
Cyber Threat Intelligence & Incident Response Specialist
Cyber Threat Intelligence & Incident Response Specialist

PERCEPT SOLUTIONS PTE. LTD. • Singapore

On-site
SGD 180,000 - 260,000