Detection Engineer/Cyber Incident Responder (SOC)

Amaris Consulting

Singapore

On-site

SGD 140,000 - 190,000

Full time

46 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Amaris Consulting in Singapore is seeking an experienced Detection Engineer & Incident Responder to join our Cybersecurity practice. You will design and build detection logic, hunt threats, and lead investigations for a 24/7 SOC.

This hands-on role blends defender mindset with builder skills, focusing on use-case development and incident response. The candidate will contribute to threat detection content, incident management, and cross-functional collaboration across regional teams, with a

Qualifications

  • 7+ years of cybersecurity experience including incident response and SOC work.
  • 4+ years in security use case design and detection content coding.
  • Hands-on experience with a SIEM platform and detection development.
  • Strong knowledge of MITRE ATT&CK and threat actor techniques.
  • Proficient Linux knowledge (RedHat/Ubuntu) and core security concepts.

Responsibilities

  • Lead the definition, design, implementation, and continuous enrichment of security use cases, mapped to the MITRE ATT&CK framework.
  • Research emerging threats and translate them into new detection logic to detect, protect, or mitigate.
  • Tune and refine existing detection content to reduce false positives and improve fidelity.
  • Respond to cybersecurity incidents, assessing type, severity, and impact.
  • Lead investigations from triage through root cause analysis, containment, and remediation.
  • Conduct proactive threat hunting using IOC and TTP analysis.
  • Track incidents through to closure, coordinating with technical stakeholders.

Skills

Incident response
Threat hunting
Security operations
MITRE ATT&CK
Java

Education

Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or related field

Tools

Elastic/ELK
Splunk
QRadar
Sentinel
ArcSight

Job description

We are looking for an experienced Detection Engineer & Incident Responder to join our Cybersecurity practice in Singapore, supporting a client's regional Security Operations function. This role sits at the intersection of security use case development, threat detection, and incident response - you will design and build detection logic based on real-world attack scenarios, respond to security incidents, and help mature the detection posture of a 24/7 SOC. This is a hands-on technical role for someone who thinks like both a defender and a builder - you'll be writing detection content, hunting for threats, and leading investigations, not just monitoring dashboards. Key Responsibilities include:

Detection Engineering & Use Case Development
  • Lead the definition, design, implementation, and continuous enrichment of security use cases, mapped to the MITRE ATT&CK framework
  • Research emerging threats in the wild and translate them into new detection logic to detect, protect, or mitigate
  • Tune and refine existing detection content to reduce false positives and improve fidelity
  • Respond to cybersecurity and IT security incidents, assessing type, severity, and impact
  • Lead investigations from triage through root cause analysis, containment, and remediation
  • Conduct proactive threat hunting using IOC and TTP analysis
  • Track incidents through to closure, coordinating with technical stakeholders
SOC Capability & Process Improvement
  • Oversee and enhance detection capabilities supporting a 24/7 regional SOC
  • Identify recurring security issues and risks; develop mitigation plans and process improvements
  • Review and refine SOC policies, playbooks, and operational procedures
  • Partner with regional and global stakeholders to ensure detection and response readiness
Reporting & Compliance
  • Document and report incidents in line with the client's incident management framework
  • Contribute to control frameworks, audits, and regulatory compliance activities as required
ABOUT YOU
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or related field
  • 7+ years of overall cybersecurity experience, including incident response and security operations
  • 4+ years specifically in security use case design, development, and detection content coding
  • Working knowledge of Java (or similar language) for use case/detection logic development
  • Hands-on experience with a SIEM platform (Elastic/ELK, Splunk, QRadar, Sentinel, or ArcSight)
  • Solid understanding of MITRE ATT&CK and adversary TTPs
  • Working knowledge of Linux (RedHat/Ubuntu) and core security concepts (TCP/IP, authentication, Windows Event IDs, Kerberos)
  • Proven experience investigating, remediating, and closing security incidents with cross-functional stakeholders
  • Comfortable working with large datasets — collection, analysis, and automation of detection content
Preferred Qualifications
  • Experience with ELK (Elastic, Logstash, Kibana) specifically
  • Industry certifications: SANS, CISSP, OSCP (or equivalent)
  • French language proficiency is a plus
Soft Skills
  • Strong problem-solving ability and comfort working autonomously
  • Clear communicator, able to explain technical findings to varied stakeholders
  • Proactive, self-directed, and able to multitask under deadlines
  • Team player with strong interpersonal skills
WHY AMARIS?
  • An international community bringing together 110+ different nationalities
  • An environment where trust has a central place: 70% of our key leaders started their careers at the first level of responsibilities
  • A robust training system with our internal Academy and 250+ available modules
  • A vibrant workplace that frequently gathers for internal events (afterworks, team buildings, etc.)
  • At Mantu, sustainability is part of everything we do. You'll have the opportunity to turn your ideas into action and make a tangible impact. Every day, our teams bring our ESG commitments to life, from reducing our footprint to driving positive change within our communities. Through our WeCare Together program, you'll be empowered to design and lead projects that create real social or environmental impact, with the company's full support.

Amaris Consulting is proud to be an equal-opportunity workplace. We are committed to promoting diversity within the workforce and creating an inclusive working environment. For this purpose, we welcome applications from all qualified candidates regardless of gender, sexual orientation, race, ethnicity, beliefs, age, marital status, disability, or other characteristics.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Threat Detection Engineer & Incident Response Lead
Threat Detection Engineer & Incident Response Lead

Amaris Consulting • Singapore

On-site
SGD 140,000 - 190,000
Cyber Incident Responder
Cyber Incident Responder

AMARIS GROUP SA • Singapore

On-site
SGD 80,000 - 120,000
Robust training system with 250+ modules
Vibrant workplace events
Focus on sustainability and community impact
Senior Cyber Incident Response & Detection Engineer
Senior Cyber Incident Response & Detection Engineer

AMARIS GROUP SA • Singapore

On-site
SGD 80,000 - 120,000
Cyber Threat Intelligence & Incident Response Specialist
Cyber Threat Intelligence & Incident Response Specialist

PERCEPT SOLUTIONS PTE. LTD. • Singapore

On-site
SGD 180,000 - 260,000
Cybersecurity Engineer (Detection Engineering)
Cybersecurity Engineer (Detection Engineering)

Assurity Trusted Solutions Pte Ltd • Singapore

On-site
SGD 120,000 - 180,000
Senior Analyst, Threat Detection and Response
Senior Analyst, Threat Detection and Response

SATS Ltd • Singapore

On-site
SGD 70,000 - 120,000
Cyber Security Resident Engineer - Incident Response & SIEM
Cyber Security Resident Engineer - Incident Response & SIEM

Ensign InfoSecurity • Singapore

On-site
SGD 70,000 - 100,000
Senior Analyst, Threat Detection and Response
Senior Analyst, Threat Detection and Response

SATS Ltd. • Singapore

On-site
SGD 110,000 - 140,000
Cyber Security Resident Engineer
Cyber Security Resident Engineer

Ensign InfoSecurity • Singapore

On-site
SGD 70,000 - 100,000
Vice President, Threat Detection Engineer
Vice President, Threat Detection Engineer

Singapore Exchange Limited • Singapore

On-site
SGD 230,000 - 350,000