Security Analyst L2

Ensign InfoSecurity

Singapore

Hybrid

SGD 100,000 - 150,000

Full time

4 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Ensign InfoSecurity in Singapore is seeking an experienced Security Operations professional to join our SOC team. You will monitor client environments, triage threats, and respond to incidents following SOPs and industry best practices.

The role involves deep-dive log analysis across Windows, Linux, and networks, mapping TTPs to MITRE ATT&CK, IOC-based hunts, and coordinating with vendors and CERTs. 12-hour shifts are required.

Responsibilities

  • Monitor client environments using SIEM platforms to detect, triage, and respond to cybersecurity threats in accordance with agreed SOPs and industry best practices
  • Analyse and investigate security alerts; perform deep-dive log analysis across system and OS layers to establish baselines and identify anomalous behaviour
  • Map threat tactics, techniques, and procedures (TTPs) to the MITRE ATT&CK framework and construct plausible attack-path hypotheses to inform containment actions
  • Produce escalation reports and notes; manage triage workflow and identify improvements to automation playbooks
  • Conduct IOC-based reactive threat hunts against limited TTPs
  • Operate SIEM, SOAR, EDR, and wider security tooling within the scope of the service engagement
  • Perform indicator of compromise (IOC) searches and triage incoming threat intelligence to assess relevance to client assets
  • Coordinate with vendors, external CERTs, and internal business stakeholders during incident response activities
  • Manage detection use cases, dashboards, and SOAR playbooks: author and tune detection rules, validate existing content, and implement automation to streamline triage and response
  • Manage the full incident ticket lifecycle, including creation, updates, closure, hygiene, and MITRE ATT&CK mapping
  • Respond to incidents and critical alerts outside of office hours when required
  • Any other tasks as assigned

Job description

Ensign is hiring !**Responsibilities*** Monitor client environments using SIEM platforms to detect, triage, and respond to cybersecurity threats in accordance with agreed SOPs and industry best practices* Analyse and investigate security alerts; perform deep-dive log analysis across system and OS layers to establish baselines and identify anomalous behaviour* Map threat tactics, techniques, and procedures (TTPs) to the MITRE ATT&CK framework and construct plausible attack-path hypotheses to inform containment actions* Produce escalation reports and notes; manage triage workflow and identify improvements to automation playbooks* Conduct IOC-based reactive threat hunts against limited TTPs* Operate SIEM, SOAR, EDR, and wider security tooling within the scope of the service engagement* Perform indicator of compromise (IOC) searches and triage incoming threat intelligence to assess relevance to client assets* Coordinate with vendors, external CERTs, and internal business stakeholders during incident response activities* Manage detection use cases, dashboards, and SOAR playbooks: author and tune detection rules, validate existing content, and implement automation to streamline triage and response* Manage the full incident ticket lifecycle, including creation, updates, closure, hygiene, and MITRE ATT&CK mapping* Respond to incidents and critical alerts outside of office hours when required* Any other tasks as assigned**Requirements*** Degree in Computer Science, Information Security, or a related discipline* Minimum 6 years of experience in cybersecurity operations or a Security Operations Centre (SOC) environment* Hands-on experience with SIEM platforms and solid understanding of network, Windows, and Linux infrastructure* Hands-on experience with EDR platforms for endpoint detection, investigation, and response* Demonstrated ability to triage, investigate, and respond to security incidents independently, with accurate escalation judgement* Experience mapping threats to MITRE ATT&CK and conducting IOC-based threat hunts* Clear written and verbal communication; able to produce structured escalation reports and brief senior stakeholders* GIAC Certified Incident Handler (GCIH), EC-Council ECIH, or equivalent incident handling certification required**Preferred Skills / Qualities*** Experience with SOAR platforms, playbook development, or automation scripting* Knowledge of cloud infrastructure security (AWS, Azure, or GCP)* Familiarity with Threat Intelligence Platforms and IOC management workflows* Experience with next-generation SIEM, NDR, or ITSM/incident management platforms* Exposure to OT security monitoring or regulatory frameworks such as NIST CSF, ISO 27001, or GDPR* CrowdStrike certifications (e.g., CCFA, CCFR) or other vendor product certifications are a plus**Other Special Working Conditions*** Able to perform 12-hour shift duties (2 days' work with 2 off-days). Working hours: AM - 7:30am to 7:30pm; PM - 7:30pm to 7:30am. Shift patterns and duration may vary from time to time**About Ensign InfoSecurity**Ensign InfoSecurity is the largest pure-play cybersecurity service provider in Asia. The company is headquartered in Singapore. We specialise in the provision of these services; cybersecurity advisory and assurance, implementation and management of advanced cybersecurity controls, cybersecurity monitoring, threat hunting, and incident response. Underpinning these competencies is in-house research and development in cybersecurity.We are a technology company with warmth and soul. We are ambitious, propelled by our vision to be the cyber defender of choice, and fueled by the dedication and camaraderie of individuals who are eager to make a difference, and leave their footprints in the industry.If you are a self-motivated curious go-getter, we want You! Join Us!
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cybersecurity Consultant (IAM)
Senior Cybersecurity Consultant (IAM)

Ensign InfoSecurity • Singapore

Hybrid
SGD 120,000 - 180,000
Intern, Threat Hunt and Response
Intern, Threat Hunt and Response

Ensign InfoSecurity • Singapore

Hybrid
SGD 21,000 - 41,000
Platform and Data Engineer
Platform and Data Engineer

Ensign InfoSecurity • Singapore

Hybrid
SGD 90,000 - 150,000
Team Lead, Vulnerability Assessment and Penetration Testing
Team Lead, Vulnerability Assessment and Penetration Testing

Ensign InfoSecurity • Singapore

Hybrid
SGD 120,000 - 180,000
Cyber Security Resident Engineer - Incident Response & SIEM
Cyber Security Resident Engineer - Incident Response & SIEM

Ensign InfoSecurity • Singapore

On-site
SGD 70,000 - 100,000
Senior Machine Learning Ops Engineer
Senior Machine Learning Ops Engineer

Ensign InfoSecurity • Singapore

Hybrid
SGD 120,000 - 180,000
Senior Security Analyst L2: Threat Hunting & SOC Automation
Senior Security Analyst L2: Threat Hunting & SOC Automation

Ensign InfoSecurity • Singapore

Hybrid
SGD 100,000 - 150,000
Cyber Security Resident Engineer
Cyber Security Resident Engineer

Ensign InfoSecurity • Singapore

On-site
SGD 70,000 - 100,000
Associate Software Engineer (AI Engineering)
Associate Software Engineer (AI Engineering)

Ensign InfoSecurity • Singapore

On-site
SGD 90,000 - 130,000
Cyber Vulnerability Researcher
Cyber Vulnerability Researcher

Ensign InfoSecurity • Singapore

Hybrid
SGD 120,000 - 180,000