We are looking for an experienced Detection Engineer & Incident Responder to join our Cybersecurity practice in Singapore, supporting a client's regional Security Operations function. This role sits at the intersection of security use case development, threat detection, and incident response - you will design and build detection logic based on real-world attack scenarios, respond to security incidents, and help mature the detection posture of a 24/7 SOC. This is a hands-on technical role for someone who thinks like both a defender and a builder - you'll be writing detection content, hunting for threats, and leading investigations, not just monitoring dashboards. Key Responsibilities include:
Detection Engineering & Use Case Development
- Lead the definition, design, implementation, and continuous enrichment of security use cases, mapped to the MITRE ATT&CK framework
- Research emerging threats in the wild and translate them into new detection logic to detect, protect, or mitigate
- Tune and refine existing detection content to reduce false positives and improve fidelity
- Respond to cybersecurity and IT security incidents, assessing type, severity, and impact
- Lead investigations from triage through root cause analysis, containment, and remediation
- Conduct proactive threat hunting using IOC and TTP analysis
- Track incidents through to closure, coordinating with technical stakeholders
SOC Capability & Process Improvement
- Oversee and enhance detection capabilities supporting a 24/7 regional SOC
- Identify recurring security issues and risks; develop mitigation plans and process improvements
- Review and refine SOC policies, playbooks, and operational procedures
- Partner with regional and global stakeholders to ensure detection and response readiness
Reporting & Compliance
- Document and report incidents in line with the client's incident management framework
- Contribute to control frameworks, audits, and regulatory compliance activities as required
ABOUT YOU
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or related field
- 7+ years of overall cybersecurity experience, including incident response and security operations
- 4+ years specifically in security use case design, development, and detection content coding
- Working knowledge of Java (or similar language) for use case/detection logic development
- Hands-on experience with a SIEM platform (Elastic/ELK, Splunk, QRadar, Sentinel, or ArcSight)
- Solid understanding of MITRE ATT&CK and adversary TTPs
- Working knowledge of Linux (RedHat/Ubuntu) and core security concepts (TCP/IP, authentication, Windows Event IDs, Kerberos)
- Proven experience investigating, remediating, and closing security incidents with cross-functional stakeholders
- Comfortable working with large datasets — collection, analysis, and automation of detection content
Preferred Qualifications
- Experience with ELK (Elastic, Logstash, Kibana) specifically
- Industry certifications: SANS, CISSP, OSCP (or equivalent)
- French language proficiency is a plus
Soft Skills
- Strong problem-solving ability and comfort working autonomously
- Clear communicator, able to explain technical findings to varied stakeholders
- Proactive, self-directed, and able to multitask under deadlines
- Team player with strong interpersonal skills
WHY AMARIS?
- An international community bringing together 110+ different nationalities
- An environment where trust has a central place: 70% of our key leaders started their careers at the first level of responsibilities
- A robust training system with our internal Academy and 250+ available modules
- A vibrant workplace that frequently gathers for internal events (afterworks, team buildings, etc.)
- At Mantu, sustainability is part of everything we do. You'll have the opportunity to turn your ideas into action and make a tangible impact. Every day, our teams bring our ESG commitments to life, from reducing our footprint to driving positive change within our communities. Through our WeCare Together program, you'll be empowered to design and lead projects that create real social or environmental impact, with the company's full support.
Amaris Consulting is proud to be an equal-opportunity workplace. We are committed to promoting diversity within the workforce and creating an inclusive working environment. For this purpose, we welcome applications from all qualified candidates regardless of gender, sexual orientation, race, ethnicity, beliefs, age, marital status, disability, or other characteristics.