A complete application in a minute — tailored resume and cover letter, ready to send.
Newbridge in Singapore seeks a senior hands-on defender who lives in the trenches. Not a manager, not a coordinator - a technical owner who can hunt, investigate, detect, and build. If you enjoy taking a security capability from zero to mature and then keeping it sharp, this is for you.
You will be the technical authority for our detection and response stack. You decide what we need, you build it, you run it, you break it to make it better.
We need a senior hands-on defender who lives in the trenches. Not a manager, not a coordinator - a technical owner who can hunt, investigate, detect, and build. If you enjoy taking a security capability from zero to mature and then keeping it sharp, this is for you.
You will be the technical authority for our detection and response stack. You decide what we need, you build it, you run it, you break it to make it better.
This is a full-lifecycle ownership role. You are responsible for the health, effectiveness, and evolution of the tools and processes that let us find and stop attackers - from selection and deployment to tuning, integration, and eventual decommissioning.
Turn outside noise into inside defence. You'll track adversaries, follow campaigns, and understand how they operate. Your job is to make sure what we learn about attackers actually shows up in our controls the same day.
When something happens, you lead the technical response. You'll dig through EDR telemetry, logs, network and cloud traces to figure out what happened, how they got in, what they touched, and how to kick them out for good. You'll document it properly so we learn from it.
You won't wait for a SIEM alert. You'll proactively look for attacker behaviors that our tools missed across endpoints, identities, and cloud. You'll write the detections yourself, test them like an attacker would, and close the gaps you find.
You'll investigate threats natively in AWS / Azure / GCP. This means knowing where to look in CloudTrail, Entra ID, GCP audit logs, spotting risky permissions, identity abuse, and helping engineering fix it at the root.
Takedown phishing, fake domains, impersonation, malicious infra. You'll reverse the kits and payloads and build the evidence packs needed to take it down.
We don't just patch CVEs. You'll connect external exploit chatter with our actual exposure, prioritize what is truly weaponized, help validate what matters, and drive closure on zero-days that pose real risk.
Every incident is a product feedback loop. You'll harden EDR/SIEM/cloud controls, automate repetitive response steps, and write the playbooks that make the whole team faster next time.