Senior Cyber Threat Intelligence & Incident Response Specialist

SPH Media

Singapore

On-site

SGD 120,000 - 180,000

Full time

6 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

SPH Media is seeking a highly technical cybersecurity professional to drive Threat Intelligence, Incident Response, and advanced threat detection. This senior individual contributor will own cybersecurity products and capabilities end-to-end.

The role covers Threat Hunting, Detection Engineering, cloud security across AWS/Azure/GCP, and lifecycle management of security tools. You will lead investigations, develop detections, and work closely with engineers to strengthen controls.

Qualifications

  • 5-8+ years of hands-on experience in Incident Response, Threat Hunting, or Threat Intelligence.
  • Strong experience with EDR platforms such as CrowdStrike (querying, investigation, live response).
  • Proven ability to independently investigate and respond to real-world cyber incidents.
  • Experience writing detection logic (KQL, SPL, Sigma, etc.).
  • Solid understanding of attacker techniques (lateral movement, persistence, C2, credential abuse).
  • Hands-on experience in cloud security investigations (AWS, Azure, or GCP).
  • Scripting skills (Python, PowerShell, or Bash).

Responsibilities

  • Actively collect, analyse, and operationalise intelligence from OSINT, dark web, commercial feeds, and ISACs.
  • Lead and execute end-to-end incident response activities (triage, containment, eradication, recovery).
  • Develop and execute proactive threat hunting across endpoint, identity, and cloud telemetry.
  • Investigate threats in AWS, Azure, and GCP environments, analyzing cloud logs for suspicious activity.
  • Identify phishing campaigns, malicious domains, and impersonation attempts; support takedown operations.

Skills

Threat Intelligence
Incident Response
Threat Hunting
Detection Engineering
Cloud Security
Scripting (Python)
MITRE ATT&CK
CrowdStrike
SIEM
KQL/Sigma

Tools

CrowdStrike Falcon
Splunk
KQL
Sigma

Job description

We are seeking a highly technical, hands-on cybersecurity professional to drive Threat Intelligence, Incident Response, and advanced threat detection. This role is suited for an experienced individual contributor who actively performs investigations, threat hunting, and security engineering, while contributing to continuous improvement of security controls.

As a senior technical individual contributor, the role is expected to take end-to-end technical ownership of the cybersecurity products and capabilities within its scope.

This role combines technical Incident Response, Threat Intelligence, Threat Hunting, Detection Engineering, and the ownership and continuous improvement of the security technologies required to support these capabilities.

The successful candidate is therefore also expected to manage the security technology lifecycle from identification of the requirement through to implementation, operational use, optimisation, renewal, replacement, and retirement; the individual is responsible for ensuring that the technology continues to meet the organisation’s technical and security requirements and for driving the relevant activities through to completion with the appropriate supporting functions.

Key Responsibilities
Threat Intelligence
  • Actively collect, analyse, and operationalise intelligence from OSINT, dark web, commercial feeds, and ISACs
  • Perform hands-on adversary tracking, campaign analysis, and TTP mapping (MITRE ATT&CK)
  • Translate intelligence into detection rules, hunting queries, and actionable use cases
  • Integrate intelligence into security tooling, including CrowdStrike, SIEM, and TIP platforms
Incident Response
  • Lead and execute end-to-end incident response activities (triage, containment, eradication, recovery)
  • Perform hands-on investigations across endpoints, logs, network traffic, and cloud environments
  • Use EDR tools (e.g., CrowdStrike) for live response, forensic analysis, and threat hunting
  • Analyse malware behaviour, attacker persistence mechanisms, and lateral movement techniques
  • Produce detailed technical reports with clear root cause and remediation actions
Threat Hunting & Detection Engineering
  • Develop and execute proactive threat hunting across endpoint, identity, and cloud telemetry
  • Write and tune detection rules (SIEM, EDR, Sigma, KQL, Splunk, etc.)
  • Validate detections through simulation and adversary emulation
  • Continuously improve detection coverage based on intelligence and incident learnings
Cloud Security (Hands-On)
  • Investigate and respond to threats in AWS, Azure, and GCP environments
  • Analyse cloud logs (CloudTrail, Azure AD, GCP logs) for suspicious activity
  • Identify misconfigurations, privilege escalation paths, and identity-based attacks
  • Work directly with engineers to remediate security gaps
Brand Protection & Digital Threats
  • Investigate phishing campaigns, malicious domains, and impersonation attempts
  • Perform technical analysis of phishing kits, payloads, and infrastructure
  • Support takedown operations with actionable evidence
Vulnerability & Exposure Management
  • Correlate CVEs with real-world exploitation and internal exposure
  • Validate vulnerabilities (where applicable) and assess exploitability
  • Track and respond to zero-days and active exploitation campaigns
  • Work closely with system owners to ensure remediation
Security Control Improvement
  • Identify detection and response gaps through real incidents and hunting activities
  • Implement improvements across EDR, SIEM, and cloud security controls
  • Build automation scripts and workflows to improve response efficiency
  • Contribute directly to playbooks, runbooks, and technical standards
Required Qualifications
  • 5-8+ years of hands-on experience in Incident Response, Threat Hunting, or Threat Intelligence
  • Strong experience with EDR platforms such as CrowdStrike (querying, investigation, live response)
  • Proven ability to independently investigate and respond to real-world cyber incidents
  • Experience writing detection logic (KQL, SPL, Sigma, etc.)
  • Solid understanding of attacker techniques (lateral movement, persistence, C2, credential abuse)
  • Hands-on experience in cloud security investigations (AWS, Azure, or GCP)
  • Scripting skills (Python, PowerShell, or Bash)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Threat Intelligence & Incident Response Specialist
Cyber Threat Intelligence & Incident Response Specialist

PERCEPT SOLUTIONS PTE. LTD. • Singapore

On-site
SGD 180,000 - 260,000
Senior Cyber Defence Engineer
Senior Cyber Defence Engineer

Newbridge • Singapore

On-site
SGD 180,000 - 280,000
Senior Cyber Defence Engineer
Senior Cyber Defence Engineer

newbridge alliance pte. ltd. • Singapore

On-site
SGD 150,000 - 190,000
Senior Cyber Defence Engineer [Threat Intel & Response]
Senior Cyber Defence Engineer [Threat Intel & Response]

NEWBRIDGE ALLIANCE PTE. LTD. • Singapore

On-site
SGD 120,000 - 180,000
Cyber Threat Intelligence & Incident Response
Cyber Threat Intelligence & Incident Response

Forensic Focus Limited • Singapore

On-site
SGD 180,000 - 240,000
Senior Consultant, Incident Response and Threat Hunting
Senior Consultant, Incident Response and Threat Hunting

Ensign InfoSecurity • Singapore

On-site
SGD 120,000 - 190,000
Senior Threat Hunter & Incident Response Lead
Senior Threat Hunter & Incident Response Lead

Forensic Focus Limited • Singapore

On-site
SGD 180,000 - 240,000
Senior Cyber Security Consultant
Senior Cyber Security Consultant

Singtel • Singapore

On-site
Confidential
Senior Lead Cyber Detection Engineer
Senior Lead Cyber Detection Engineer

NETS • Singapore

On-site
SGD 180,000 - 280,000
Senior Threat Intel & Incident Response Engineer
Senior Threat Intel & Incident Response Engineer

SPH Media • Singapore

On-site
SGD 120,000 - 180,000