Lead Security Engineer, IT Security Operations Engineering and Technology Singapore Experienced[...]

SEA Singapore

Singapore

On-site

SGD 120,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Sea Limited Singapore is seeking a Lead Security Engineer to join the Corporate IT Security Operations team. You will support IT Security Operations Manager in engineering, operation, and continuous improvement of enterprise security platforms, including SIEM modernisation, EDR/XDR operations, automation, and data pipelines.

The ideal candidate will bring hands-on security engineering experience, investigations, SIEM/EDR operations, automation, and data-driven SecOps improvements, helping the

Qualifications

  • Bachelor's degree in Computer Science, Cybersecurity, Information Security, Engineering, Information Technology, or a related discipline.
  • Certifications in cybersecurity, cloud, SIEM, incident response, or security engineering (e.g., CISSP, GCIH, GCIA, Security+).
  • Minimum 5+ years of hands-on experience in Security Engineering, SecOps Engineering, SIEM Engineering, Detection Engineering, Incident Response, or related cybersecurity roles; 2+ years in investigation, alert triage, detection tuning, incident response, threat hunting, or SOC operations.
  • Strong understanding of logs across firewalls, proxies, VPN, DNS, DHCP, AD, endpoints, identity, cloud, apps, and infrastructure.
  • Hands-on experience with intrusion analysis, malware analysis, incident response, or security engineering.
  • Experience with at least one major SIEM or security analytics platform (Elastic, Splunk, etc.).
  • Hands-on experience with EDR/XDR platforms (CrowdStrike or similar).
  • Experience with security automation using scripting, APIs, SOAR tools, n8n, Python, PowerShell, Bash, etc.
  • Experience with AI-assisted SecOps including alert enrichment, anomaly detection, investigation support, and SOC workflow automation.
  • Strong interpersonal, leadership, and problem-solving skills.

Responsibilities

  • Support the IT Security Operations Manager in IT security engineering, security platform operations, SIEM modernisation, and SecOps process automation.
  • Engineer, operate, and continuously improve enterprise security platforms, including SIEM, EDR/XDR, automation/orchestration tools, and security data pipelines.
  • Support the migration and modernisation of the SIEM environment to Elastic on GCP, including log ingestion, pipeline development, dashboards, alerting, rule tuning, and platform optimisation.
  • Build and maintain security data pipelines for logs from corporate IT systems, networks, endpoints, identity platforms, cloud services, applications, and security tools.
  • Improve alert enrichment, investigation workflows, case routing, ticketing integration, dashboards, and reporting.
  • Support security monitoring, alert triage, threat investigation, incident response, detection tuning, and mitigation activities.
  • Translate investigation experience and SecOps pain points into practical engineering improvements, including detections, false-positive reduction, automation playbooks, and runbooks.
  • Explore and support AI-enabled SecOps use cases, including anomaly detection, alert enrichment, investigation assistance, behavioural analytics, and automation of repetitive SOC workflows.
  • Partner with infrastructure, network, cloud, endpoint, identity, application, and cybersecurity teams to improve security visibility and operational effectiveness.

Skills

Security engineering
Incident response
SIEM engineering
Detection engineering
EDR/XDR
Security automation
Python
PowerShell
Bash
SOAR tools
APIs
AI-assisted SecOps
Threat hunting
Team leadership

Education

Bachelor's degree in Computer Science / Cybersecurity / Information Security

Tools

Elastic Security
Splunk
CrowdStrike
GCP

Job description

The Corporate IT Security Operations team plays an important role in securing our business operations globally, supporting Corporate IT’s mission of helping Sea develop competitive advantages to achieve strategic goals and meet operational requirements.

The Lead Security Engineer will be a key member of the team, supporting the IT Security Operations Manager in the engineering, operation, and continuous improvement of enterprise security platforms. This includes SIEM modernisation, EDR/XDR operations, security automation/orchestration, security data pipelines, process automation, and AI-assisted SecOps capabilities.

The ideal candidate will bring hands-on experience in security engineering, investigations, SIEM/EDR operations, automation, and data-driven SecOps improvements, helping the team strengthen how it detects, investigates, and responds to cybersecurity threats. This includes improving security data pipelines, alert quality, workflow automation, and AI-assisted capabilities such as alert enrichment, anomaly detection, and investigation support. The candidate should also provide coaching and technical guidance to uplift the team’s engineering, automation, and operational capabilities.

Job Description
  • Support the IT Security Operations Manager in IT security engineering, security platform operations, SIEM modernisation, and SecOps process automation.
  • Engineer, operate, and continuously improve enterprise security platforms, including SIEM, EDR/XDR, security automation/orchestration tools, and security data pipelines.
  • Support the migration and modernisation of the SIEM environment to Elastic on GCP, including log ingestion, pipeline development, dashboards, alerting, rule tuning, and platform optimisation.
  • Build and maintain security data pipelines for logs from corporate IT systems, networks, endpoints, identity platforms, cloud services, applications, and security tools.
  • Improve alert enrichment, investigation workflows, case routing, ticketing integration, operational dashboards, and reporting.
  • Support security monitoring, alert triage, threat investigation, incident response, detection tuning, and mitigation activities where required.
  • Translate investigation experience and SecOps pain points into practical engineering improvements, including better detections, false-positive reduction, automation playbooks, and runbooks.
  • Explore and support AI-enabled SecOps use cases, including anomaly detection, alert enrichment, investigation assistance, behavioural analytics, and automation of repetitive SOC workflows.
  • Partner with infrastructure, network, cloud, endpoint, identity, application, and cybersecurity teams to improve security visibility and operational effectiveness.

Provide coaching, technical guidance, solution review, and knowledge sharing to team members.

Maintain technical documentation, operational runbooks, security playbooks, platform standards, and handover materials.

Requirements
  • Bachelor’s degree in Computer Science, Cybersecurity, Information Security, Engineering, Information Technology, or a related discipline.
  • Relevant certifications in cybersecurity, cloud, SIEM, incident response, or security engineering, such as CISSP, GCIH, GCIA, Security+, Elastic, GCP, CrowdStrike, or similar, would be an advantage.
  • Minimum 5+ years of hands-on experience in Security Engineering, SecOps Engineering, SIEM Engineering, Detection Engineering, Incident Response, or related cybersecurity roles, including at least 2 years of exposure to investigation, alert triage, detection tuning, incident response, threat hunting, or SOC operations.
  • Good understanding of corporate IT and security logs, including firewall, proxy, VPN, DNS, DHCP, Active Directory, endpoint, identity, cloud, application, and infrastructure logs.
  • Hands-on experience with intrusion analysis, email analysis, malware analysis, incident response, or security engineering.
  • Hands-on experience with at least one major SIEM or security analytics platform, such as Elastic Security, Splunk, or similar.
  • Hands-on Experience with EDR/XDR platforms, preferably CrowdStrike or similar endpoint detection and response tools.
  • Experience with security automation using scripting, APIs, SOAR tools, n8n, Python, PowerShell, Bash, or similar technologies.
  • Experience with AI-assisted SecOps, including alert enrichment, anomaly detection, investigation support, SOC workflow automation, or LLM-enabled triage and reporting, would be an advantage
  • Strong interpersonal, leadership, and problem-solving skills, with ability to play both leading and supporting roles.
  • Initiative, resourceful, enthusiastic, and eager to learn in a fluid and fast-paced environment.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Resident Engineer - Incident Response & SIEM
Cyber Security Resident Engineer - Incident Response & SIEM

Ensign InfoSecurity • Singapore

On-site
SGD 70,000 - 100,000
Senior Security Engineer, SIEM/EDR & AI SecOps
Senior Security Engineer, SIEM/EDR & AI SecOps

SEA Singapore • Singapore

On-site
SGD 120,000 - 180,000
Cyber Security Resident Engineer
Cyber Security Resident Engineer

Ensign InfoSecurity • Singapore

On-site
SGD 70,000 - 100,000
Security Engineer
Security Engineer

CodSec • Singapore

On-site
SGD 90,000 - 150,000
Vice President, Threat Detection Engineer
Vice President, Threat Detection Engineer

SGX Group • Singapore

On-site
SGD 180,000 - 280,000
Security Engineer
Security Engineer

NETS • Singapore

On-site
SGD 90,000 - 130,000
Principal Cybersecurity Engineer
Principal Cybersecurity Engineer

NETS • Singapore

On-site
SGD 180,000 - 240,000
Security Operations Engineer
Security Operations Engineer

Tap Growth ai • Singapore

On-site
SGD 70,000 - 110,000
Cybersecurity Engineer – Security Operations & Vulnerability Management
Cybersecurity Engineer – Security Operations & Vulnerability Management

MTS GLOBAL PTE. LTD. • Singapore

On-site
Security Operations Engineer
Security Operations Engineer

RAPSYS TECHNOLOGIES PTE LTD • Singapore

On-site
SGD 70,000 - 110,000