Security Operations / SOC Analyst

APAR TECHNOLOGIES PTE. LTD.

Singapore

On-site

SGD 67,000 - 100,000

Full time

4 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Apar Technologies Pte. Ltd. in Singapore is seeking an experienced SOC Security Analyst to monitor security alerts, investigate incidents and support containment actions. You will analyze events across SIEM, EDR/XDR and cloud tools, and work with cross‑functional teams during incidents.

The role requires handling escalated investigations, tuning detections, and contributing to runbooks and reports. You will rotate on‑call duties and help with client onboarding and knowledge sharing.

Qualifications

  • 3–5 years of experience in SOC, security operations or MDR environments.
  • Experience handling Level 2 or escalated security investigations.
  • Hands-on experience with at least one SIEM platform such as Splunk, Sentinel, Elastic, QRadar or FortiSIEM.
  • Familiarity with Sigma and MITRE ATT&CK.

Responsibilities

  • Monitor and investigate security alerts and incidents.
  • Analyse security events using SIEM, EDR/XDR, identity, email, cloud and network tools.
  • Investigate system logs, authentication activity, processes, DNS, proxy and email activity.
  • Handle escalated security investigations and determine the appropriate response.
  • Perform approved incident containment actions such as host isolation and account disablement.
  • Support incident response, evidence collection and recovery activities.
  • Develop and improve security detection rules using KQL, SPL, ES|QL, EQL or similar tools.
  • Identify and reduce false positives through detection tuning.
  • Participate in threat hunting and apply threat intelligence to investigations.
  • Maintain security runbooks, playbooks and investigation records.
  • Track remediation actions and verify that security issues have been resolved.
  • Prepare investigation updates and contribute to security reports.
  • Work closely with NOC, engineering and client teams during security incidents.
  • Participate in the rotating after-hours on-call roster.
  • Support continuous improvement, knowledge sharing and client onboarding activities.

Skills

SIEM experience
Threat detection
Incident response
EDR/XDR experience
Query languages

Tools

Splunk
Microsoft Sentinel
Elastic
QRadar
FortiSIEM

Job description

Key Responsibilities
  • Monitor and investigate security alerts and incidents.
  • Analyse security events using SIEM, EDR/XDR, identity, email, cloud and network tools.
  • Investigate system logs, authentication activity, processes, DNS, proxy and email activity.
  • Handle escalated security investigations and determine the appropriate response.
  • Perform approved incident containment actions such as host isolation and account disablement.
  • Support incident response, evidence collection and recovery activities.
  • Develop and improve security detection rules using KQL, SPL, ES|QL, EQL or similar tools.
  • Identify and reduce false positives through detection tuning.
  • Participate in threat hunting and apply threat intelligence to investigations.
  • Maintain security runbooks, playbooks and investigation records.
  • Track remediation actions and verify that security issues have been resolved.
  • Prepare investigation updates and contribute to security reports.
  • Work closely with NOC, engineering and client teams during security incidents.
  • Participate in the rotating after-hours on-call roster.
  • Support continuous improvement, knowledge sharing and client onboarding activities.
Requirements
  • 3-5 years of experience in SOC, security operations or MDR environments.
  • Experience handling Level 2 or escalated security investigations.
  • Hands-on experience with at least one SIEM platform such as Splunk, Microsoft Sentinel, Elastic, QRadar or FortiSIEM.
  • Experience with an EDR/XDR platform such as CrowdStrike, SentinelOne, Microsoft Defender or Cortex XDR.
  • Working knowledge of KQL, SPL, ES|QL, EQL or similar query languages.
  • Familiarity with Sigma and MITRE ATT&CK.
  • Good understanding of Windows, Linux, Active Directory and Microsoft 365/Azure security.
  • Good knowledge of TCP/IP, DNS, HTTP/TLS, firewalls, proxies and VPNs.
  • Experience using ITSM platforms such as ServiceNow or Jira Service Management.

EA Number: 11C4879

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Resident Engineer - Incident Response & SIEM
Cyber Security Resident Engineer - Incident Response & SIEM

Ensign InfoSecurity • Singapore

On-site
SGD 70,000 - 100,000
Cyber Security Resident Engineer
Cyber Security Resident Engineer

Ensign InfoSecurity • Singapore

On-site
SGD 70,000 - 100,000
SOC Analyst I
SOC Analyst I

UST • Singapore

On-site
SGD 60,000 - 90,000
Senior SOC Engineer, Digital Infrastructure
Senior SOC Engineer, Digital Infrastructure

Kerry Consulting • Singapore

On-site
SGD 110,000 - 180,000
Security Operations (SOC)
Security Operations (SOC)

RED ALPHA CYBERSECURITY PTE. LTD. • Singapore

On-site
SGD 60,000 - 80,000
Cybersecurity SOC Analyst (L2)
Cybersecurity SOC Analyst (L2)

SPADE CONSULTING AND SERVICES PTE. LTD. • Singapore

On-site
SGD 60,000 - 90,000
L3 SOC analyst & SOC Manager
L3 SOC analyst & SOC Manager

INSYGHTS SECURITY PTE. LTD. • Singapore

On-site
SGD 120,000 - 160,000
Senior Cyber Security Consultant
Senior Cyber Security Consultant

Singtel • Singapore

On-site
Confidential
Cybersecurity SOC Analyst
Cybersecurity SOC Analyst

SPADE CONSULTING AND SERVICES PTE. LTD. • Singapore

On-site
SGD 55,000 - 95,000
SOC Analyst
SOC Analyst

CAREER CONNEX PRIVATE LIMITED • Singapore

On-site
SGD 50,000 - 80,000