Senior Cybersecurity Incident & Threat Hunter

Singtel

Singapore

On-site

Confidential

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Singtel is seeking an Enterprise Cyber Security specialist to act as the technical focal point during cyber incidents, coordinating with SOC, CISO, infrastructure, network, cloud, and vendor teams. The role involves incident triage, investigation, containment, evidence gathering, remediation tracking, and post‑incident review.

The ideal candidate will conduct proactive threat hunting across enterprise infrastructure using telemetry from SIEM, EDR, NDR, vulnerability management tools, and asset

Qualifications

  • Bachelor’s degree or diploma in cybersecurity or related field.
  • Minimum 7 years of experience in cybersecurity operations, incident response, threat hunting, SOC operations, detection engineering, infrastructure security, or related roles.
  • Strong understanding of incident response lifecycle.
  • Hands-on experience with SIEM, EDR, NDR, vulnerability management, threat intelligence platforms, asset discovery tools, firewalls, and endpoint/network security controls.
  • Good understanding of network security, TCP/IP, routing, firewalls, VPNs, DNS, authentication, Windows/Linux, Active Directory, and cloud security fundamentals.
  • Experience analysing logs, alerts, network traffic, endpoint telemetry, user activity, and security events to identify threats or suspicious behaviours.
  • Familiarity with MITRE ATT&CK, Cyber Kill Chain, threat hunting methodologies, and common attacker tactics, techniques, and procedures.
  • Ability to work across multiple teams during incidents and security projects, including SOC, CISO, infrastructure, network, application, cloud, GRC, and vendor teams.
  • Strong analytical, troubleshooting, documentation, stakeholder management, and communication skills.

Responsibilities

  • Act as the Enterprise Cyber Security technical focal point during cyber incidents, working closely with SOC, CISO, infrastructure, network, cloud, application, and vendor teams.
  • Support cyber incident response activities including triage, investigation, containment coordination, evidence gathering, remediation tracking, and post incident review.
  • Conduct proactive threat hunting across Enterprise infrastructure using telemetry from SIEM, EDR, NDR, vulnerability management, asset discovery, and other security tools.
  • Identify suspicious behaviours, attack patterns, lateral movement indicators, privilege misuse, exposed services, anomalous access, and other signs of compromise.
  • Develop and enhance threat hunting hypotheses, detection use cases, investigation playbooks, response procedures, and escalation workflows.
  • Support improvement of security monitoring by identifying gaps in logs, telemetry, asset visibility, EDR/NDR/SIEM coverage, and detection rules.
  • Work with SOC and central security teams to improve alert quality, detection coverage, investigation context, and incident response readiness.
  • Support vulnerability management and risk‑based remediation by correlating vulnerabilities with asset criticality, exposure, threat intelligence, and compensating controls.
  • Support Enterprise cybersecurity initiatives including NDR deployment, asset discovery, micro‑segmentation, Zero Trust controls, PIAM/IAM adoption, and security tool integration.
  • Participate in security assessments, threat reviews, tabletop exercises, incident simulations, and lessons‑learned activities.
  • Support root cause analysis and ensure remediation actions from cyber incidents, audit findings, vulnerability reviews, and threat hunting activities are tracked to closure.
  • Prepare management reports, investigation summaries, threat hunting findings, risk updates, incident dashboards, and security posture metrics.
  • Support cybersecurity audits, regulatory requests, internal governance activities, and evidence collection where related to incident response, monitoring, and security controls.
  • Maintain and improve technical documentation including incident response runbooks, threat hunting procedures, SOPs, escalation guides, and operational checklists.
  • Provide guidance to internal teams on security best practices, incident handling, evidence preservation, secure configuration, and remediation actions.

Skills

Incident response
Threat hunting
SOC operations
Detection engineering
Infrastructure security
Security monitoring
Log analysis
Communication

Education

Bachelor's degree or diploma in Cybersecurity/IT/CS

Tools

SIEM
EDR
NDR
Vulnerability management
Threat intelligence platforms
Asset discovery tools
Firewalls
Endpoint security controls
Cloud security platforms

Job description

Singtel is seeking an Enterprise Cyber Security specialist to act as the technical focal point during cyber incidents, coordinating with SOC, CISO, infrastructure, network, cloud, and vendor teams. The role involves incident triage, investigation, containment, evidence gathering, remediation tracking, and post‑incident review.

The ideal candidate will conduct proactive threat hunting across enterprise infrastructure using telemetry from SIEM, EDR, NDR, vulnerability management tools, and asset

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cyber Security Incident Response Lead
Senior Cyber Security Incident Response Lead

Singtel Group • Singapore

On-site
SGD 120,000 - 180,000
Senior Cyber Security Consultant
Senior Cyber Security Consultant

Singtel Group • Singapore

On-site
SGD 120,000 - 180,000
Senior Cyber Threat Hunter & Incident Response Lead
Senior Cyber Threat Hunter & Incident Response Lead

Singapore Exchange Limited • Singapore

On-site
SGD 120,000 - 170,000
Senior Cybersecurity & Network Security Consultant
Senior Cybersecurity & Network Security Consultant

Singtel Group • Singapore

On-site
SGD 75,000 - 95,000
Senior Threat Hunting & Incident Response Leader
Senior Threat Hunting & Incident Response Leader

Singapore Exchange Limited • Singapore

On-site
SGD 90,000 - 140,000
Senior Incident Response & Threat Hunting Lead
Senior Incident Response & Threat Hunting Lead

Forensic Focus Limited • Singapore

On-site
SGD 138,000 - 158,000
Senior Cyber Incident Responder – SOC & Threat Hunting
Senior Cyber Incident Responder – SOC & Threat Hunting

Keyrus • Singapore

On-site
SGD 120,000 - 180,000
Threat Hunter - Proactive Cyber Defense & CTI
Threat Hunter - Proactive Cyber Defense & CTI

OCBC (Singapore) • Singapore

On-site
SGD 120,000 - 180,000
Senior Cybersecurity Consultant: Network & Cloud Security
Senior Cybersecurity Consultant: Network & Cloud Security

Singtel • Singapore

On-site
Confidential
Chief Cyber Threat Architect & Threat Hunting Lead
Chief Cyber Threat Architect & Threat Hunting Lead

SGX Group • Singapore

On-site
SGD 120,000 - 210,000