Senior Analyst, Threat Detection and Response

WhiteCrow Research

Singapore

On-site

SGD 120,000 - 180,000

Full time

25 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

WhiteCrow Research in Singapore is seeking a Senior Analyst, Threat Detection and Response to monitor security consoles, triage alerts, and coordinate incident response across regions. The role emphasizes proactive threat hunting, rule tuning, collaboration with global SOC, and documenting investigations.

The ideal candidate has a cybersecurity degree and relevant certifications, with 3+ years in incident response, threat hunting, or related fields.

Qualifications

  • Bachelor’s degree required in cybersecurity, CS, information systems, or equivalent.
  • Certifications such as GCIH, GCFA, GCIA, CEH or similar preferred.
  • 3+ years in at least two areas: incident response, threat hunting, cyber threat intelligence, network security, or cloud security.

Responsibilities

  • Monitor security consoles and dashboards (SIEM, EDR) for suspicious activity and triage alerts.
  • Investigate security events, determine scope/severity, gather evidence, and perform root cause analysis.
  • Execute end-to-end incident response: containment, eradication, and recovery per IR playbooks.
  • Hunt for indicators of compromise using logs and endpoint telemetry; map to MITRE ATT&CK.
  • Tune detection rules, thresholds, and SOAR playbooks; automate repetitive responses to reduce false positives.
  • Coordinate with global SOC and IT teams to ensure effective remediation and knowledge sharing.
  • Document investigations and prepare incident reports; contribute to post-incident reviews and playbook updates.
  • Mentor junior analysts and contribute to threat intelligence enrichment and training.

Skills

Incident Detection
Threat Hunting
SIEM/EDR
SOAR
MITRE ATT&CK
SOC Analysis
Python scripting

Education

Bachelor’s degree in Cybersecurity/CS/IS

Tools

SIEM platforms
EDR platforms
SOAR tools
Cloud logs
Python

Job description

We are global talent research, insight, and sourcing specialists with offices in the UK, USA, Singapore, Malaysia, Hong Kong, Dubai, and India. Our international reach has helped us to understand and penetrate specialist markets at a global level. In addition to this, our service is also extended to complement our client’s in-house talent acquisition teams.

About our client

Our client is a globally recognized organization headquartered in Southeast Asia, specializing in aviation support services, air cargo handling, ground operations, and institutional food solutions. The company provides a wide range of services, including passenger assistance, ramp and baggage handling, aviation security, aircraft cleaning, and laundry operations for the aviation sector.

Beyond aviation services, the organization operates large-scale central kitchens and food production facilities, catering to airlines, corporate clients, and institutions across diverse cuisines and service formats. With a strong presence across Asia-Pacific, Europe, the Americas, the Middle East, and Africa, the company supports global travel, trade, and logistics through an extensive international network, further strengthened by strategic acquisitions in recent years.

As a Senior Analyst, Threat Detection and Response, you will be responsible for...

  • Continuously monitoring security consoles and dashboards (SIEM, EDR, etc.) for suspicious activity; triaging alerts to identify valid security incidents versus false positives and prioritizing response based on asset criticality and business risk.
  • Investigating suspicious activities and security events, determining the scope and severity of incidents, and gathering relevant evidence. Performing root cause analysis to identify attack vectors and affected systems.
  • Executing incident response actions end-to-end, including timely containment of threats, eradication of malicious artifacts, and system recovery, while following the organization’s incident response plan. Coordinating with IT infrastructure, application owners, and other stakeholders to ensure effective incident remediation.
  • Proactively hunting for indicators of compromise and hidden threats in logs, network traffic, and endpoint telemetry, even without specific alerts. Using hypothesis-driven techniques and knowledge of attacker TTPs to uncover stealthy or emerging threats that have evaded initial detection.
  • Continuously tuning SIEM/EDR detection rules, thresholds, and SOAR playbooks, while automating repetitive response actions to reduce false positives and accelerate containment.
  • Leveraging internal and external threat intelligence sources to enrich analysis and response. Staying updated on new vulnerabilities and adversary tactics and incorporating this knowledge to adjust monitoring rules and incident response strategies. Mapping observed malicious activities to frameworks such as MITRE ATT&CK for reporting and analysis.
  • Working closely with global SOC team members and escalating complex incidents to senior analysts or incident response leads when necessary. Collaborating with colleagues across regions to ensure seamless coverage and knowledge sharing across the security team.
  • Documenting investigation steps, findings, and actions taken for each incident in a clear and concise manner. Preparing incident reports and contributing to post-incident review meetings, highlighting what occurred, how it was resolved, and recommendations for preventing future occurrences.
  • Assisting in developing and updating incident response playbooks, standard operating procedures, and knowledge base documentation. Providing feedback and suggestions to improve security monitoring tools, analytics content (detection rules), and workflow automation (SOAR playbooks) for greater efficiency and effectiveness.
  • Sharing insights from incidents and trending threats with the broader team to enhance overall security awareness. Mentoring and guiding junior analysts (Tier 1 SOC analysts) by sharing analysis techniques and best practices, elevating the team’s collective skill level.

What you already have...

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, or equivalent threat management & incident response experience
  • Currently hold cybersecurity certifications such as GCIH, GCFA, GCIA, CEH, others
  • With 3 years or more, progressive experience in at least two of the following disciplines:
  • Incident Response & Management (developing response plans, executing playbooks, forensic investigations, root cause analysis)
  • Threat Hunting (identifying undetected threats through proactive analysis and hypothesis-driven investigation)
  • Cyber Threat Intelligence (gathering and analyzing threat intelligence to inform detection capabilities and preventive measures)
  • Network Security (TCP/IP protocols, firewalls, intrusion prevention systems, and network traffic analysis)
  • Securing and monitoring operating system and cloud environments (AWS, Azure, GCP), including analyzing cloud service logs and configurations for suspicious activities, and understanding cloud-native security controls and best practices
  • Demonstrated ability to:
  • Function as a Level 2 or 3 SOC Analyst (analyzing and responding to cybersecurity incidents)
  • Preferred Experience:
  • Experience with SOAR tools and some proficiency in scripting languages (e.g., Python, PowerShell) to automate repetitive tasks and streamline incident response workflows
  • Advanced understanding of emerging threats, zero-day vulnerabilities, and common attack vectors (phishing, malware, ransomware, lateral movement) with the ability to ensure rapid detection and response
  • Hands-on experience using SIEM and EDR platforms for centralized log analysis, real-time threat monitoring, and in-depth incident investigations
  • In-depth knowledge of the incident response lifecycle
  • Proven ability to conduct proactive threat hunting operations, leveraging the MITRE ATT&CK framework to map adversary tactics, techniques, and procedures (TTPs), uncover stealthy threats, and close gaps in detection coverage
  • Familiarity with cyber threat intelligence feeds and standards (e.g., STIX, TAXII), incorporating IOCs (Indicators of Compromise) and threat intel data into monitoring and investigations to enrich context and anticipate emerging threats
  • Understanding of key security frameworks and regulations (e.g., NIST CSF, ISO 27001, GDPR) and the ability to align threat detection and incident response processes with organizational policies and compliance requirements
  • Effective at coordinating with cross-functional teams (IT, DevOps, Business, etc.) during high-impact incidents and translating complex technical findings into clear, actionable insights for executive and non-technical stakeholders
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Analyst, Threat Detection and Response
Senior Analyst, Threat Detection and Response

SATS Ltd. • Singapore

On-site
SGD 90,000 - 150,000
Senior Analyst, Threat Detection and Response
Senior Analyst, Threat Detection and Response

SATS Ltd • Singapore

On-site
SGD 70,000 - 120,000
Senior Cyber Security Consultant
Senior Cyber Security Consultant

Singtel • Singapore

On-site
Confidential
Analyst, Threat Detection and Response
Analyst, Threat Detection and Response

SATS Ltd. • Singapore

On-site
SGD 65,000 - 90,000
Cyber Threat Intelligence & Incident Response Specialist
Cyber Threat Intelligence & Incident Response Specialist

Base Camp Recruitment Pte Ltd • Singapore

On-site
SGD 140,000 - 210,000
Senior Cyber Threat Intelligence & Incident Response Specialist
Senior Cyber Threat Intelligence & Incident Response Specialist

SPH Media • Singapore

On-site
SGD 120,000 - 180,000
Cybersecurity SOC Manager
Cybersecurity SOC Manager

NETWORK FOR ELECTRONIC TRANSFERS (SINGAPORE) PTE LTD • Singapore

On-site
SGD 120,000 - 180,000
Cyber Security Resident Engineer - Incident Response & SIEM
Cyber Security Resident Engineer - Incident Response & SIEM

Ensign InfoSecurity • Singapore

On-site
SGD 70,000 - 100,000
Cyber Threat Intelligence & Incident Response Specialist
Cyber Threat Intelligence & Incident Response Specialist

PERCEPT SOLUTIONS PTE. LTD. • Singapore

On-site
SGD 180,000 - 260,000
Cyber Incident Responder
Cyber Incident Responder

MIGSO-PCUBED • Singapore

Hybrid
SGD 120,000 - 180,000