Senior Lead Cyber Detection Engineer

NETS

Singapore

On-site

SGD 180,000 - 280,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

NETS is seeking a seasoned Detection Engineer to lead the design and execution of high‑fidelity detection use cases across SIEM, EDR, NDR, and cloud platforms. You will drive Detection‑as‑Code practices, mentor SOC analysts, and collaborate with IR to convert hunts into incidents.

You will utilize MITRE ATT&CK as the framework for coverage, reduce dwell time and false positives, and champion telemetry expansion across the enterprise.

Qualifications

  • 10–15+ years of cybersecurity experience with 5+ years in detection engineering / threat hunting / SOC engineering.
  • 3+ years in a lead or senior technical role.
  • Deep understanding of MITRE ATT&CK framework and adversary TTPs.

Responsibilities

  • Design, develop, and tune high-fidelity detection use cases across SIEM, EDR, NDR, and cloud platforms.
  • Build detection logic mapped to MITRE ATT&CK, reducing dwell time and false positives.
  • Drive Detection-as-Code with automation, version control, and CI/CD pipelines.
  • Lead proactive threat hunting campaigns across endpoints, network, cloud, and identity systems.
  • Collaborate with Incident Response to translate hunts into incidents and improvements.
  • Operationalize threat intelligence into actionable detection use cases.

Skills

Leadership
Mentoring
Analytical mindset
Stakeholder management

Tools

SIEM platforms
EDR/XDR
Threat hunting tooling
Agentic AI / LLM
MITRE ATT&CK
Python
PowerShell

Job description

Key Responsibilities

Detection Engineering & Security Monitoring

Design, develop, and tune high-fidelity detection use cases across SIEM, EDR, NDR, and cloud security platforms.

Build detection logic mapped to MITRE ATT&CK, focusing on reducing dwell time and false positives.

Drive Detection-as-Code practices, leveraging automation, version control, and CI/CD pipelines.

Continuously improve use-case coverage based on threat intelligence, incidents, and red/purple team outcomes.

Evaluate and onboard new security telemetry sources to enhance visibility.

Threat Hunting

Lead proactive, hypothesis-driven threat hunting campaigns across endpoints, network, cloud, and identity systems.

Investigate anomalous behaviors and identify stealthy adversary activities that bypass automated detections.

Develop reusable hunting playbooks and analytics.

Collaborate with Incident Response to transition hunts into confirmed incidents and detection improvements.

Threat Intelligence

Operationalize threat intelligence (strategic, tactical, and operational) into actionable detection use cases.

Track and profile threat actors targeting financial services / payment ecosystems.

Integrate intelligence feeds into detection pipelines and SOC workflows.

Produce intelligence-driven insights and advisories for stakeholders.

Leadership & Technical Oversight

Serve as a technical lead and mentor for SOC analysts and junior detection engineers.

Set standards for detection quality, triage effectiveness, and threat coverage.

Partner with Red Team/Purple Team to validate detection capabilities.

Act as an escalation point for complex investigations and advanced threat scenarios.

Automation & Engineering

Develop scripts and tooling (Python, PowerShell, etc.) to automate detection, enrichment, and response workflows.

Integrate with SOAR platforms to improve SOC efficiency.

Drive telemetry normalization and data quality improvements.

Stakeholder Engagement

Work closely with IT, Cloud, DevOps, Fraud, and Risk teams to improve enterprise visibility.

Provide clear technical reporting and metrics to leadership.

Support regulatory and audit requirements relevant to security monitoring.

Required Qualifications & Experience

10–15+ years of cybersecurity experience, with at least:

  • 5+ years in detection engineering / threat hunting / SOC engineering
  • 3+ years in a lead or senior technical role
Strong experience with:
  • SIEM platforms
  • EDR/XDR solutions
  • Threat hunting methodologies and tooling
  • Agentic AI, LLM
Deep understanding of:
  • MITRE ATT&CK framework
  • Adversary tactics, techniques, and procedures (TTPs)
Experience with:
  • Cloud security monitoring (AWS, Azure, GCP)
  • Identity threat detection (e.g., Azure AD, IAM abuse)
  • Detection & Alerting Use Case Management
Strong scripting/programming skills:
  • Python, PowerShell, or equivalent

Experience in financial services, fintech, or payment environments is highly preferred

Familiarity with:
  • Detection engineering lifecycle
  • Data analytics and log pipelines
  • SOAR and automation frameworks
Preferred Certifications
  • GIAC (GCFA, GCDA, GCTI, GPEN)
  • CISSP, CISM
  • Microsoft SC-200 / Azure security certifications
  • Elastic(or equivalent SIEM certifications)
Key Competencies
  • Deep technical expertise with hands-on capability
  • Analytical and investigative mindset
  • Strong leadership and mentoring skills
  • Ability to translate intelligence into actionable detection
  • Strong communication and stakeholder management
  • Continuous improvement and engineering mindset
What Success Looks Like
  • Measurable reduction in MTTD and false positives
  • Increased detection coverage aligned to MITRE ATT&CK
  • Proactive identification of previously unknown threats
  • Mature, scalable Detection Engineering program
  • Strong collaboration across SOC, IR, and Red Team functions
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Threat Intelligence & Incident Response Specialist
Cyber Threat Intelligence & Incident Response Specialist

PERCEPT SOLUTIONS PTE. LTD. • Singapore

On-site
SGD 180,000 - 260,000
Senior Cyber Threat Intelligence & Incident Response Specialist
Senior Cyber Threat Intelligence & Incident Response Specialist

SPH Media • Singapore

On-site
SGD 120,000 - 180,000
Senior Cyber Defence Engineer
Senior Cyber Defence Engineer

Newbridge • Singapore

On-site
SGD 180,000 - 280,000
Senior Cyber Defence Engineer
Senior Cyber Defence Engineer

newbridge alliance pte. ltd. • Singapore

On-site
SGD 150,000 - 190,000
Detection Engineer – EASM / ASM / Cyber Threat Intelligence (CTI)
Detection Engineer – EASM / ASM / Cyber Threat Intelligence (CTI)

ASTEK SINGAPORE INNOVATION TECHNOLOGY PTE. LTD. • Singapore

On-site
SGD 90,000 - 150,000
Lead Detection Engineer: MITRE-Driven Threat Hunting
Lead Detection Engineer: MITRE-Driven Threat Hunting

NETS • Singapore

On-site
SGD 180,000 - 280,000
Cybersecurity Engineer – Detection Engineering
Cybersecurity Engineer – Detection Engineering

Jobtailor • Singapore

On-site
SGD 70,000 - 120,000
Senior Cyber Security Consultant
Senior Cyber Security Consultant

Singtel • Singapore

On-site
Confidential
Senior Cyber Defence Engineer [Threat Intel & Response]
Senior Cyber Defence Engineer [Threat Intel & Response]

NEWBRIDGE ALLIANCE PTE. LTD. • Singapore

On-site
SGD 120,000 - 180,000
Senior Consultant, Incident Response and Threat Hunting
Senior Consultant, Incident Response and Threat Hunting

Ensign InfoSecurity • Singapore

On-site
SGD 120,000 - 190,000