Security Engineer

Ensign InfoSecurity

Singapore

On-site

SGD 80,000 - 120,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Ensign InfoSecurity, headquartered in Singapore, seeks an experienced SIEM Engineer to configure and administer the SIEM, maintain health and uptime, perform patching, and integrate diverse log sources for thorough monitoring across on-prem and cloud. You will craft detection use cases, support SOC analysts, and coordinate with vendors to cover all security aspects.

The role requires hands-on experience in security operations (SIEM/EDR), cloud security, and secure software practices, with

Qualifications

  • Advanced knowledge and experience of Cyber Security with SIEM engineering.
  • Experience implementing use cases and operational models for SIEM.
  • Hands-on with multiple security domains: SIEM, EDR, cloud security.
  • Knowledge of networking and AWS/Azure Cloud Security practices.
  • SIEM administration certifications preferred.

Responsibilities

  • Configure and administer the SIEM to support SOC needs.
  • Maintain health and uptime of the SIEM platform; patch and upgrade.
  • Integrate log sources via parsers/forwarders for monitoring.
  • Develop and maintain detection capabilities for threats.
  • Coordinate data feeds into SIEM from on-prem and cloud devices.
  • Work with third-party consultants to cover security aspects.
  • Operate SIEM, PAM, EDR, IDS/IPS, WAF; ensure regulatory compliance.
  • Automate security processes using PowerShell, Python, Bash; explore SOAR.
  • Research leading cybersecurity products and cloud integrations.
  • Support SOC analysts with investigations and protective monitoring use cases.

Skills

SIEM administration
Cybersecurity knowledge
Networking basics
AWS/Azure security knowledge
Security use case development

Tools

Splunk
PAM
EDR
IDS/IPS
WAF

Job description

Ensign is hiring !

Responsibilities
  • Configure and administer the SIEM to support the needs of SOC.
  • Responsible for maintaining the health of the SIEM tool and ensuring agreed uptime of the respective platform.
  • Perform regular patching and version upgrades on the SIEM platform.
  • Configure respective parsers, forwarders (engage principal vendors if needed) to integrate various log sources with SIEM platform for log monitoring.
  • Research, build, and maintain detection capabilities for the latest threats across SIEM, log analytic, and security tool platforms.
  • Ensure real time data and Configuration replication between Primary and DR sites.
  • Integrate data feeds (logs) into SIEM/Splunk from on-premises and cloud deployed devices and applications.
  • Explore leading cybersecurity products.
  • Work with 3rd party security consultants and service providers to ensure all security aspects are covered.
  • Operate security solutions such as SIEM, PAM, EDR, IDS/IPS and Web Application Firewall while ensuring compliance to regulatory standards and procedures.
  • Security Automation: Automating processes using well-known frameworks such as PowerShell, Python, Bash, etc. As well as SOAR build out.
  • (look like using AWS lambda to integration (CloudFront/WAF/ALB) and automating your work.)
  • Continuous Monitoring: Management AWS Guard duty and intrusion detection, User Behavior, and other security monitoring.
  • Support the SOC Analysts in the use of the toolset and with investigations to establish the facts surrounding potential suspicious activities and to understand the impact and possible risks associated.
  • Creation, amendment, tuning and supporting the engineering of advanced or complex protective monitoring use cases.
  • Provide security consultancy to other internal teams for matters relating to the SIEM.
  • Troubleshooting complex issues that may occur within the SIEM and resolving them with the help of vendor support
  • Advise clients of security standards, best practice and solutions relating to SIEM and SOC solutions.
Requirements
  • Advanced knowledge and experience of Cyber Security and evidence of working as a SIEM Engineer with previous experience of the software, including architectural design, configuring, operating and problem-solving activities.
  • A good understanding of implementing use cases and operational models or specific security solutions to meet the customer’s requirement and understand how SIEM solution.
  • Hands-on experience in a two or more of the key security domains such as: security operations (SIEM, EDR, vulnerability management), Cloud security, Data security, Identity and access management, and secure software development lifecycle.
  • Knowledge of networking and AWS/Azure Cloud Security practices and tools.
  • SIEM related certifications for Administration, implementation, deployment, architecture.
About Ensign InfoSecurity

Ensign InfoSecurity is the largest pure-play cybersecurity service provider in Asia. The company is headquartered in Singapore. We specialise in the provision of these services; cybersecurity advisory and assurance, implementation and management of advanced cybersecurity controls, cybersecurity monitoring, threat hunting, and incident response. Underpinning these competencies is in-house research and development in cybersecurity.

What Makes Ensign Special?

We are a technology company with warmth and soul. We are ambitious, propelled by our vision to be the cyber defender of choice, and fueled by the dedication and camaraderie of individuals who are eager to make a difference, and leave their footprints in the industry.

If you are a self-motivated curious go-getter, we want You! Join Us!

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Resident Engineer - Incident Response & SIEM
Cyber Security Resident Engineer - Incident Response & SIEM

Ensign InfoSecurity • Singapore

On-site
SGD 70,000 - 100,000
SIEM & SOC Engineer - Cloud & Automation
SIEM & SOC Engineer - Cloud & Automation

Ensign InfoSecurity • Singapore

On-site
SGD 80,000 - 120,000
Security Engineer
Security Engineer

CodSec • Singapore

On-site
SGD 90,000 - 150,000
Cyber Security Resident Engineer
Cyber Security Resident Engineer

Ensign InfoSecurity • Singapore

On-site
SGD 70,000 - 100,000
Senior Marketing Manager
Senior Marketing Manager

Ensign InfoSecurity • Singapore

On-site
SGD 110,000 - 150,000
Lead Security Engineer, IT Security Operations Engineering and Technology Singapore Experienced[...]
Lead Security Engineer, IT Security Operations Engineering and Technology Singapore Experienced[...]

SEA Singapore • Singapore

On-site
SGD 120,000 - 180,000
Security Engineer
Security Engineer

HYPERSCAL SOLUTIONS PTE. LTD. • Singapore

On-site
SGD 90,000 - 140,000
Security Engineer (Contract)
Security Engineer (Contract)

CHARTERHOUSE PTE. LTD. • Singapore

On-site
SGD 120,000 - 180,000
Security Engineer (Contract)
Security Engineer (Contract)

Charterhouse Pte Ltd • Singapore

On-site
SGD 90,000 - 150,000
Security Operations Engineer — SIEM, SOAR & Cloud
Security Operations Engineer — SIEM, SOAR & Cloud

CodSec • Singapore

On-site
SGD 90,000 - 150,000