Security Analyst L2

ENSIGN INFOSECURITY (CYBERSECURITY) PTE. LTD.

Singapore

On-site

SGD 70,000 - 95,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

ENSIGN INFOSECURITY (CYBERSECURITY) PTE. LTD. is seeking a Cybersecurity Operations Specialist in Singapore to monitor environments for threats. Responsibilities include incident response, analytical threat hunting, and managing detection cases. The ideal candidate has a computer science degree and at least 6 years of experience in a SOC, with a focus on SIEM and EDR platforms.

This role requires effective communication and the ability to produce reports for senior stakeholders. Candidates with GIAC or EC-Council certifications are preferred.

Qualifications

  • Minimum 6 years of experience in a SOC environment.
  • Hands-on experience with detection and incident handling.
  • Clear written and verbal communication skills.

Responsibilities

  • Monitor client environments for cybersecurity threats.
  • Analyse and investigate security alerts.
  • Produce escalation reports and manage triage workflow.

Skills

Cybersecurity operations
SIEM platforms
Incident response
Threat hunting
MITRE ATT&CK framework

Education

Degree in Computer Science or Information Security

Tools

SOAR platforms
EDR platforms
Threat Intelligence Platforms

Job description

Responsibilities
  • Monitor client environments using SIEM platforms to detect, triage, and respond to cybersecurity threats in accordance with agreed SOPs and industry best practices
  • Analyse and investigate security alerts; perform deep-dive log analysis across system and OS layers to establish baselines and identify anomalous behaviour
  • Map threat tactics, techniques, and procedures (TTPs) to the MITRE ATT&CK framework and construct plausible attack-path hypotheses to inform containment actions
  • Produce escalation reports and notes; manage triage workflow and identify improvements to automation playbooks
  • Conduct IOC‑based reactive threat hunts against limited TTPs
  • Operate SIEM, SOAR, EDR, and wider security tooling within the scope of the service engagement
  • Perform indicator of compromise (IOC) searches and triage incoming threat intelligence to assess relevance to client assets
  • Coordinate with vendors, external CERTs, and internal business stakeholders during incident response activities
  • Manage detection use cases, dashboards, and SOAR playbooks: author and tune detection rules, validate existing content, and implement automation to streamline triage and response
  • Manage the full incident ticket lifecycle, including creation, updates, closure, hygiene, and MITRE ATT&CK mapping
  • Respond to incidents and critical alerts outside of office hours when required
  • Any other tasks as assigned
Requirements
  • Degree in Computer Science, Information Security, or a related discipline
  • Minimum 6 years of experience in cybersecurity operations or a Security Operations Centre (SOC) environment
  • Hands‑on experience with SIEM platforms and solid understanding of network, Windows, and Linux infrastructure
  • Hands‑on experience with EDR platforms for endpoint detection, investigation, and response
  • Demonstrated ability to triage, investigate, and respond to security incidents independently, with accurate escalation judgement
  • Experience mapping threats to MITRE ATT&CK and conducting IOC‑based threat hunts
  • Clear written and verbal communication; able to produce structured escalation reports and brief senior stakeholders
  • GIAC Certified Incident Handler (GCIH), EC-Council ECIH, or equivalent incident handling certification required
Preferred Skills / Qualities
  • Experience with SOAR platforms, playbook development, or automation scripting
  • Knowledge of cloud infrastructure security (AWS, Azure, or GCP)
  • Familiarity with Threat Intelligence Platforms and IOC management workflows
  • Experience with next‑generation SIEM, NDR, or ITSM/incident management platforms
  • Exposure to OT security monitoring or regulatory frameworks such as NIST CSF, ISO 27001, or GDPR
  • CrowdStrike certifications (e.g., CCFA, CCFR) or other vendor product certifications are a plus
OtherSpecialWorkingConditions
  • Abletoperform12-hourshiftduties(2days’workwith2off-days).Workinghours:AM-8:30amto8:30pm;PM-8:30pmto8:30am.Shiftpatternsanddurationmayvaryfromtimetotime
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Resident Engineer
Cyber Security Resident Engineer

Ensign InfoSecurity • Singapore

On-site
SGD 70,000 - 100,000
L3 SOC analyst & SOC Manager
L3 SOC analyst & SOC Manager

INSYGHTS SECURITY PTE. LTD. • Singapore

On-site
SGD 120,000 - 160,000
Security Delivery Consultant
Security Delivery Consultant

ABPGROUP PTE. LTD. • Singapore

On-site
SGD 70,000 - 120,000
Senior Cyber Security Consultant
Senior Cyber Security Consultant

Singtel • Singapore

On-site
Confidential
Security Operations SOC Analyst
Security Operations SOC Analyst

Red Alpha Cybersecurity • Singapore

On-site
SGD 70,000 - 110,000
Cyber Security Resident Engineer - Incident Response & SIEM
Cyber Security Resident Engineer - Incident Response & SIEM

Ensign InfoSecurity • Singapore

On-site
SGD 70,000 - 100,000
Associate SOC Analyst
Associate SOC Analyst

Ensign InfoSecurity • Singapore

On-site
SGD 40,000 - 70,000
Senior Analyst, Threat Detection and Response
Senior Analyst, Threat Detection and Response

SATS Ltd. • Singapore

On-site
SGD 110,000 - 140,000
SOC Analyst
SOC Analyst

UNITED OVERSEAS BANK LIMITED • Singapore

On-site
SGD 45,000 - 65,000
Cybersecurity Support Engineer
Cybersecurity Support Engineer

THALES SOLUTIONS ASIA PTE. LTD. • Singapore

On-site
SGD 60,000 - 100,000