Security Analyst L2

Ensign InfoSecurity

Singapore

On-site

SGD 90,000 - 150,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Ensign InfoSecurity in Singapore is seeking a seasoned Cyber Security Operations professional to lead detection, analysis, and response for client environments using SIEM, EDR, and SOAR.

You will map threats to MITRE ATT&CK, drive containment actions, and produce escalation reports for senior stakeholders.

Requirements include a degree in Computer Science or Information Security, at least 6 years in a SOC, and certifications such as GCIH or ECIH. This is a full-time, on-site role.

Qualifications

  • Degree in Computer Science or Information Security required.
  • Minimum 6 years of experience in cybersecurity operations or SOC.
  • Hands-on SIEM/EDR experience and strong network/OS knowledge.
  • Certification: GCIH, ECIH or equivalent required.

Responsibilities

  • Monitor client environments using SIEM platforms to detect, triage, and respond to cybersecurity threats.
  • Analyse and investigate security alerts; perform deep-dive log analysis across system and OS layers.
  • Map threat tactics, techniques, and procedures to MITRE ATT&CK and inform containment actions.
  • Produce escalation reports; manage triage workflow and automation playbooks.
  • Coordinate with vendors, CERTs, and stakeholders during incident response.
  • Manage incident ticket lifecycle including creation, updates, and closure.

Skills

SIEM operations
Incident response
Threat hunting
MITRE ATT&CK mapping
Stakeholder communication

Education

Bachelor's degree in Computer Science or Information Security

Tools

EDR
SOAR
Threat intelligence platforms

Job description

Ensign is hiring !

Responsibilities
  • Monitor client environments using SIEM platforms to detect, triage, and respond to cybersecurity threats in accordance with agreed SOPs and industry best practices
  • Analyse and investigate security alerts; perform deep-dive log analysis across system and OS layers to establish baselines and identify anomalous behaviour
  • Map threat tactics, techniques, and procedures (TTPs) to the MIT&CK framework and construct plausible attack-path hypotheses to inform containment actions
  • Produce escalation reports and notes; manage triage workflow and identify improvements to automation playbooks
  • Conduct IOC-based reactive threat hunts against limited TTPs
  • Operate SIEM, SOAR, EDR, and wider security tooling within the scope of the service engagement
  • Perform indicator of compromise (IOC) searches and triage incoming threat intelligence to assess relevance to client assets
  • Coordinate with vendors, external CERTs, and internal business stakeholders during incident response activities
  • Manage detection use cases, dashboards, and SOAR playbooks: author and tune detection rules, validate existing content, and implement automation to streamline triage and response
  • Manage the full incident ticket lifecycle, including creation, updates, closure, hygiene, and MIT&CK mapping
  • Respond to incidents and critical alerts outside of office hours when required
  • Any other tasks as assigned
Requirements
  • Degree in Computer Science, Information Security, or a related discipline
  • Minimum 6 years of experience in cybersecurity operations or a Security Operations Centre (SOC) environment
  • Hands-on experience with SIEM platforms and solid understanding of network, Windows, and Linux infrastructure
  • Hands-on experience with EDR platforms for endpoint detection, investigation, and response
  • Demonstrated ability to triage, investigate, and respond to security incidents independently, with accurate escalation judgement
  • Experience mapping threats to MIT&CK and conducting IOC-based threat hunts
  • Clear written and verbal communication; able to produce structured escalation reports and brief senior stakeholders
  • GIAC Certified Incident Handler (GCIH), EC-Council ECIH, or equivalent incident handling certification required
Preferred Skills / Qualities
  • Experience with SOAR platforms, playbook development, or automation scripting
  • Knowledge of cloud infrastructure security (AWS, Azure, or GCP)
  • Familiarity with Threat Intelligence Platforms and IOC management workflows
  • Experience with next-generation SIEM, NDR, or ITSM/incident management platforms
  • Exposure to OT security monitoring or regulatory frameworks such as NIST CSF, ISO 27001, or GDPR
  • CrowdStrike certifications (e.g., CCFA, CCFR) or other vendor product certifications are a plus
Other Special Working Conditions

Able to perform 12-hour shift duties (2 days’ work with 2 off-days). Working hours: AM - 8:30am to 8:30pm; PM - 8:30pm to 8:30am. Shift patterns and duration may vary from time to time

About Ensign InfoSecurity

Ensign InfoSecurity is the largest pure-play cybersecurity service provider in Asia. The company is headquartered in Singapore. We specialise in the provision of these services; cybersecurity advisory and assurance, implementation and management of advanced cybersecurity controls, cybersecurity monitoring, threat hunting, and incident response. Underpinning these competencies is in-house research and development in cybersecurity. What Makes Ensign Special? We are a technology company with warmth and soul. We are ambitious, propelled by our vision to be the cyber defender of choice, and fueled by the dedication and camaraderie of individuals who are eager to make a difference, and leave their footprints in the industry. If you are a self-motivated curious go-getter, we want You! Join Us!

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer
Security Engineer

Ensign InfoSecurity • Singapore

On-site
SGD 80,000 - 120,000
Cyber Security Resident Engineer - Incident Response & SIEM
Cyber Security Resident Engineer - Incident Response & SIEM

Ensign InfoSecurity • Singapore

On-site
SGD 70,000 - 100,000
Cyber Security Resident Engineer
Cyber Security Resident Engineer

Ensign InfoSecurity • Singapore

On-site
SGD 70,000 - 100,000
Senior Marketing Manager
Senior Marketing Manager

Ensign InfoSecurity • Singapore

On-site
SGD 110,000 - 150,000
Security Analyst L2
Security Analyst L2

ENSIGN INFOSECURITY (CYBERSECURITY) PTE. LTD. • Singapore

On-site
SGD 70,000 - 95,000
Associate SOC Analyst
Associate SOC Analyst

Ensign InfoSecurity • Singapore

On-site
SGD 40,000 - 70,000
Senior SOC Analyst — MITRE ATT&CK Driven Detection
Senior SOC Analyst — MITRE ATT&CK Driven Detection

ENSIGN INFOSECURITY (CYBERSECURITY) PTE. LTD. • Singapore

On-site
SGD 70,000 - 95,000
Security Engineer
Security Engineer

CodSec • Singapore

On-site
SGD 90,000 - 150,000
Lead Security Engineer, IT Security Operations Engineering and Technology Singapore Experienced[...]
Lead Security Engineer, IT Security Operations Engineering and Technology Singapore Experienced[...]

SEA Singapore • Singapore

On-site
SGD 120,000 - 180,000
IT Security Lead | Risk, Compliance & Incident Response
IT Security Lead | Risk, Compliance & Incident Response

Ensign InfoSecurity (Singapore) Pte. Ltd. • Singapore

On-site
SGD 110,000 - 190,000