Security Analyst - Contract

QUESS SELECTION & SERVICES PTE. LTD.

Singapore

On-site

SGD 120,000 - 180,000

Full time

5 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

QUESS SELECTION & SERVICES PTE. LTD. is seeking an experienced cybersecurity incident responder in Singapore. The role focuses on monitoring security events, investigating high-severity incidents, and performing advanced threat analysis across SIEM, EDR/XDR, and network security layers.

The ideal candidate will bring 7+ years in incident response with 4+ years in use-case design, strong SIEM skills, and proficiency in scripting. Willingness to support weekend/night shifts is required.

Qualifications

  • Bachelors in cybersecurity/IT/computer science or equivalent experience.
  • 7+ years in cybersecurity incident response with 4+ years in use-case design/development.
  • SIEM with ELK stack experience is a plus.
  • Credentials in IT security (e.g., SANS/CISSP/OSCP) are a plus.
  • Proficient in Python/PowerShell/Bash/SQL scripting.
  • Familiarity with SOC structure and incident response lifecycle.

Responsibilities

  • Continuously monitor and analyse security events from SIEM, EDR/XDR, firewalls, IDS/IPS, and more.
  • Investigate and respond to security incidents, including high-severity events.
  • Analyze logs, network traffic, and endpoints to determine incident root cause.
  • Perform containment, eradication, recovery, and remediation actions.
  • Conduct threat hunting to identify IOCss and attacker behaviours.
  • Develop threat-hunting queries and techniques to identify emerging threats.
  • Correlate information from multiple sources to identify attack patterns.
  • Analyze malware, URLs, domains, IPs, and other IOCs as required.
  • Review threat intelligence to identify emerging threats and techniques.
  • Apply MITRE ATT&CK during investigations and threat analysis.
  • Develop and tune SIEM rules, dashboards, and alerts.
  • Improve detection accuracy and reduce false positives in SOC.
  • Identify gaps in monitoring and recommend tool/process improvements.
  • Coordinate with IT/network teams for incident containment and remediation.
  • Participate in major incident management and provide technical recommendations.
  • Conduct post-incident root cause analyses and remediation guidance.
  • Prepare detailed incident reports and security documentation.
  • Develop incident response playbooks and SOC procedures.
  • Mentor SOC members and share knowledge to improve capabilities.
  • Participate in SOC meetings, training, and continuous improvement.
  • Stay updated on threats, vulnerabilities, and best practices.
  • Support rostered weekend/night operations as required.

Skills

Incident response
SIEM
Threat hunting
MITRE ATT&CK
Python/PowerShell
Log analysis
SOC operations
Security tooling

Education

Bachelor's degree in Cybersecurity or related field
Equivalent professional experience

Tools

ELK stack
LogRhythm
Splunk
EDR/XDR tools

Job description

Roles & Responsibilities:
  • Continuously monitor and analyse security events and alerts from various sources, including SIEM, EDR/XDR, firewalls, IDS/IPS, endpoint security, network security, and other security infrastructure.
  • Investigate and respond to security incidents, including complex and high-severity cybersecurity events.
  • Conduct detailed analysis of security events, logs, network traffic, endpoint activities, and other relevant security data to determine the severity, impact, scope, and root cause of incidents.
  • Perform advanced incident investigation and determine appropriate containment, eradication, recovery, and remediation actions.
  • Conduct threat hunting activities to proactively identify suspicious activities, indicators of compromise (IOCs), attacker behaviours, and potential security threats.
  • Develop and utilize threat-hunting queries and techniques to identify emerging threats and malicious activities.
  • Analyse and correlate information from multiple security sources to identify attack patterns, anomalies, and potential security incidents.
  • Perform analysis of malware, suspicious files, URLs, domains, IP addresses, and other indicators of compromise where required.
  • Analyse threat intelligence and security research to identify emerging cybersecurity threats, vulnerabilities, attack techniques, and indicators that may affect the organisation or its customers.
  • Apply recognised cybersecurity frameworks and methodologies, including MITRE ATT&CK, during security investigations and threat analysis.
  • Develop, maintain, and improve SIEM correlation rules, detection rules, dashboards, alerts, and security monitoring use cases.
  • Assist in tuning and optimizing security tools and detection mechanisms to improve detection accuracy, reduce false positives, and enhance overall SOC capabilities.
  • Identify gaps in existing security monitoring and recommend improvements to security tools, processes, procedures, and detection capabilities.
  • Coordinate with IT, network, infrastructure, application, and other technical teams to facilitate timely investigation, containment, and remediation of security incidents.
  • Participate in the management and response of major or critical security incidents and provide technical recommendations to relevant stakeholders.
  • Conduct root cause analysis and post-incident reviews and provide recommendations to prevent recurrence of security incidents.
  • Prepare and maintain detailed incident reports, investigation findings, root cause analysis, remediation recommendations, and other security documentation.
  • Develop and maintain incident response procedures, playbooks, investigation guides, and SOC operational documentation.
  • Provide technical guidance and knowledge sharing to SOC team members to improve investigation and incident-handling capabilities.
  • Participate in regular SOC meetings, cybersecurity training, tabletop exercises, knowledge-sharing sessions, and continuous improvement initiatives.
  • Maintain up-to-date knowledge of cybersecurity threats, vulnerabilities, attack techniques, security technologies, and industry best practices.
  • Perform other cybersecurity and SOC-related duties and responsibilities as assigned by management.
Key Requirements:
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Security, or a related field, or equivalent professional experience.
  • Candidate MUST have 7 or more years of experience on overall cybersecurity incident response with 4+ years specifically on security usecase design, development, coding.
  • Experience in SIEM on ELK(Elastic Logstash Kibana) stack is a plus
  • Professional credentials in one of the relevant IT Security disciplines is a plus (SANS / CISSP / OSCP)
  • Experience in common scripting languages such as Python, PowerShell, Bash, SQL is a plus
  • Experience with Security Operations Centre (SOC) structure and incident response lifecycle
    (detection → analysis → containment → recovery → reporting)
  • Hands‑on experience with SIEM tools (e.g., LogRhythm, ELK, Splunk equivalent) – log monitoring, alert review, dashboard usage
  • Experience in log analysis and threat detection concepts (Windows logs, firewall logs, authentication logs, etc.)
  • Cybersecurity technologies such as PAM, EDR, XDR, SOAR, IDS/IPS, WAF, DLP (conceptual knowledge acceptable)
  • Networking fundamentals (TCP/IP, DNS, HTTP, ports, firewalls)
  • Exposure to cloud or platform security concepts (AWS/Azure/GCP basics acceptable)
  • Ability to perform research on cybersecurity best practices and produce process/procedural documentation
  • Willingness to support rostered weekend/night operations

Savita Rai

EA REG NO: R1873418

EA License No:23C2060

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Security Resident Engineer
Cyber Security Resident Engineer

Ensign InfoSecurity • Singapore

On-site
SGD 70,000 - 100,000
Cyber Security Resident Engineer - Incident Response & SIEM
Cyber Security Resident Engineer - Incident Response & SIEM

Ensign InfoSecurity • Singapore

On-site
SGD 70,000 - 100,000
Senior Security Analyst
Senior Security Analyst

CrimsonLogic Pte Ltd • Singapore

On-site
SGD 60,000 - 90,000
Senior Analyst, Threat Detection and Response
Senior Analyst, Threat Detection and Response

WhiteCrow Research • Singapore

On-site
SGD 120,000 - 180,000
Senior Incident Response Specialist
Senior Incident Response Specialist

StarHub • Singapore

On-site
SGD 120,000 - 180,000
Cybersecurity Engineer
Cybersecurity Engineer

Alliance Healthcare Group Limited • Singapore

On-site
SGD 60,000 - 100,000
Senior Cyber Security Consultant
Senior Cyber Security Consultant

Singtel • Singapore

On-site
Confidential
Security Engineer
Security Engineer

NCS Group • Singapore

On-site
SGD 60,000 - 90,000
Security Delivery Consultant
Security Delivery Consultant

ABPGROUP PTE. LTD. • Singapore

On-site
SGD 70,000 - 120,000
Senior Analyst, Threat Detection and Response
Senior Analyst, Threat Detection and Response

SATS Ltd. • Singapore

On-site
SGD 90,000 - 150,000