Senior Cyber Defence Engineer [Threat Intel & Response]

NEWBRIDGE ALLIANCE PTE. LTD.

Singapore

On-site

SGD 120,000 - 180,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

NEWBRIDGE ALLIANCE PTE. LTD. seeks a senior, hands-on defender who will own the detection and response stack, hunt attackers, investigate incidents, and drive improvements.

This role emphasizes technical ownership over management, with a focus on building mature security capabilities and keeping them sharp. You will be the technical authority responsible for end-to-end incident response, from tool selection and deployment to tuning, integration, and decommissioning, including proactive hunting

Qualifications

  • 5 to 8 years minimum doing IR, Threat Hunting, or Cyber Threat Intelligence.
  • Deep, hands-on experience with modern EDR (CrowdStrike preferred).
  • Has handled real incidents solo, not just as part of a queue.
  • Can write detections - KQL / SPL / Sigma or similar.
  • Understands attacker techniques - persistence, movement, credential theft, C2.
  • Experience in cloud threats beyond on-premise.
  • Can script solutions - Python, PowerShell, or Bash.

Responsibilities

  • Own the full lifecycle of detection and response tools and processes.
  • Act as the technical authority for the detection and response stack.
  • Lead end-to-end incident investigations and containment.
  • Hunt for attacker behaviors before alerts fire across endpoints, identities, and cloud.
  • Secure and defend cloud environments (AWS/Azure/GCP) and fix root causes.
  • Defeat phishing, fake domains, and impersonation affecting the brand.
  • Harden controls and automate response playbooks to accelerate the team.

Skills

5-8 years exp IR/Threat Hunting/CTI
EDR experience (CrowdStrike)
Incidents handled solo
Detections in KQL/SPL/Sigma
Cloud security understanding
Scripting (Python/PowerShell/Bash)

Tools

CrowdStrike EDR

Job description

The Opportunity:

We need a senior hands-on defender who lives in the trenches. Not a manager, not a coordinator - a technical owner who can hunt, investigate, detect, and build. If you enjoy taking a security capability from zero to mature and then keeping it sharp, this is for you.

You will be the technical authority for our detection and response stack. You decide what we need, you build it, you run it, you break it to make it better.

What You'll Own:

This is a full-lifecycle ownership role. You are responsible for the health, effectiveness, and evolution of the tools and processes that let us find and stop attackers - from selection and deployment to tuning, integration, and eventual decommissioning.

Your Focus Areas:
  1. Make Intelligence Actionable

    Turn outside noise into inside defence. You'll track adversaries, follow campaigns, and understand how they operate. Your job is to make sure what we learn about attackers actually shows up in our controls the same day.

  2. Own Incidents End-to-End

    When something happens, you lead the technical response. You'll dig through EDR telemetry, logs, network and cloud traces to figure out what happened, how they got in, what they touched, and how to kick them out for good. You'll document it properly so we learn from it.

  3. Hunt Before The Alert Fires

    You won't wait for a SIEM alert. You'll proactively look for attacker behaviors that our tools missed across endpoints, identities, and cloud. You'll write the detections yourself, test them like an attacker would, and close the gaps you find.

  4. Secure & Defend The Cloud

    You'll investigate threats natively in AWS / Azure / GCP. This means knowing where to look in CloudTrail, Entra ID, GCP audit logs, spotting risky permissions, identity abuse, and helping engineering fix it at the root.

  5. Protect The Brand Outside The Perimeter

    Takedown phishing, fake domains, impersonation, malicious infra. You'll reverse the kits and payloads and build the evidence packs needed to take it down.

  6. Make Vulnerabilities Mean Something

    We don't just patch CVEs. You'll connect external exploit chatter with our actual exposure, prioritize what is truly weaponized, help validate what matters, and drive closure on zero-days that pose real risk.

  7. Leave The Environment Better Than You Found It

    Every incident is a product feedback loop. You'll harden EDR/SIEM/cloud controls, automate repetitive response steps, and write the playbooks that make the whole team faster next time.

What You Bring:
  • 5 to 8 years minimum doing the actual work in IR, Threat Hunting, or Cyber Threat Intelligence.
  • Deep, hands-on experience with modern EDR - CrowdStrike preferred - you can query, investigate, and do live response in your sleep.
  • You have handled real incidents solo, not just as part of a queue.
  • You can write good detections - KQL / SPL / Sigma or similar - and you know how to tune out noise without losing signal.
  • You understand how attackers really operate - how they persist, move, steal creds, and hide C2.
  • You've chased threats in the cloud, not just on-prem.
  • You can script your way out of problems - Python, PowerShell, or Bash.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cyber Defence Engineer
Senior Cyber Defence Engineer

Newbridge • Singapore

On-site
SGD 180,000 - 280,000
Senior Cyber Defence Engineer
Senior Cyber Defence Engineer

newbridge alliance pte. ltd. • Singapore

On-site
SGD 150,000 - 190,000
Senior Cyber Threat Intelligence & Incident Response Specialist
Senior Cyber Threat Intelligence & Incident Response Specialist

SPH Media • Singapore

On-site
SGD 120,000 - 180,000
Cyber Threat Intelligence & Incident Response Specialist
Cyber Threat Intelligence & Incident Response Specialist

Base Camp Recruitment Pte Ltd • Singapore

On-site
SGD 140,000 - 210,000
Cyber Threat Intelligence & Incident Response Specialist
Cyber Threat Intelligence & Incident Response Specialist

PERCEPT SOLUTIONS PTE. LTD. • Singapore

On-site
SGD 180,000 - 260,000
Senior Cyber Security Consultant
Senior Cyber Security Consultant

Singtel • Singapore

On-site
Confidential
Cyber Threat Intelligence & Incident Response
Cyber Threat Intelligence & Incident Response

Forensic Focus Limited • Singapore

On-site
SGD 180,000 - 240,000
Senior Threat Hunter & Incident Response Lead
Senior Threat Hunter & Incident Response Lead

Forensic Focus Limited • Singapore

On-site
SGD 180,000 - 240,000
Senior Threat Hunter - Defensive
Senior Threat Hunter - Defensive

Planet Nine • Singapore

On-site
SGD 90,000 - 120,000
Senior Lead Cyber Detection Engineer
Senior Lead Cyber Detection Engineer

NETS • Singapore

On-site
SGD 180,000 - 280,000