Senior Lead Detection Engineer (Threat Hunting, Intel & Use Case Management)

NETS

Singapore

On-site

SGD 150,000 - 210,000

Full time

27 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

NETS in Singapore seeks a senior leader to design, build, and tune high-fidelity detections across SIEM, EDR, NDR and cloud platforms within a modern SOC.

You will lead proactive threat hunting campaigns, mentor analysts, partner with Red Team/Purple Team, and drive telemetry quality, incident response transitions, and governance across IT, Cloud, Fraud, and Risk teams.

Qualifications

  • 10–15+ years of cybersecurity experience.
  • 5+ years in detection engineering / threat hunting / SOC engineering
  • 3+ years in a lead or senior technical role
  • Strong experience with SIEM platforms, EDR/XDR, and threat hunting methodologies
  • Deep understanding of MITRE ATT&CK framework and adversary TTPs
  • Experience with Cloud security monitoring (AWS, Azure, GCP) and identity threat detection

Responsibilities

  • Lead Detection Engineering and security monitoring program across SIEM, EDR/XDR, and cloud platforms.
  • Coach and mentor SOC analysts and junior detection engineers.
  • Collaborate with Red Team and Incident Response to validate detections and improve coverage.
  • Translate threat intelligence into actionable detection use cases.
  • Integrate telemetry, data quality, and automation with SOAR and CI/CD workflows.

Skills

SIEM platforms
EDR/XDR solutions
Threat hunting methodologies
MITRE ATT&CK framework
Cloud security monitoring
Identity threat detection
Python
PowerShell
Leadership
Mentoring

Tools

SOAR platforms
Elastic SIEM
ELK stack

Job description

Detection Engineering & Security Monitoring

Design, develop, and tune high-fidelity detection use cases across SIEM, EDR, NDR, and cloud security platforms.

Build detection logic mapped to MITRE ATT&CK, focusing on reducing dwell time and false positives.

Drive Detection-as-Code practices, leveraging automation, version control, and CI/CD pipelines.

Continuously improve use-case coverage based on threat intelligence, incidents, and red/purple team outcomes.

Evaluate and onboard new security telemetry sources to enhance visibility.

Threat Hunting

Lead proactive, hypothesis-driven threat hunting campaigns across endpoints, network, cloud, and identity systems.

Investigate anomalous behaviors and identify stealthy adversary activities that bypass automated detections.

Develop reusable hunting playbooks and analytics.

Collaborate with Incident Response to transition hunts into confirmed incidents and detection improvements.

Operationalize threat intelligence (strategic, tactical, and operational) into actionable detection use cases.

Track and profile threat actors targeting financial services / payment ecosystems.

Integrate intelligence feeds into detection pipelines and SOC workflows.

Produce intelligence-driven insights and advisories for stakeholders.

Leadership & Technical Oversight

Serve as a technical lead and mentor for SOC analysts and junior detection engineers.

Set standards for detection quality, triage effectiveness, and threat coverage.

Partner with Red Team/Purple Team to validate detection capabilities.

Act as an escalation point for complex investigations and advanced threat scenarios.

Develop scripts and tooling (Python, PowerShell, etc.) to automate detection, enrichment, and response workflows.

Integrate with SOAR platforms to improve SOC efficiency.

Drive telemetry normalization and data quality improvements.

Stakeholder Engagement

Work closely with IT, Cloud, DevOps, Fraud, and Risk teams to improve enterprise visibility.

Provide clear technical reporting and metrics to leadership.

Support regulatory and audit requirements relevant to security monitoring.

Required Qualifications & Experience

10–15+ years of cybersecurity experience, with at least:

  • 5+ years in detection engineering / threat hunting / SOC engineering
  • 3+ years in a lead or senior technical role
Strong experience with:
  • SIEM platforms
  • EDR/XDR solutions
  • Threat hunting methodologies and tooling
  • Agentic AI, LLM
Deep understanding of:
  • MITRE ATT&CK framework
  • Adversary tactics, techniques, and procedures (TTPs)
Experience with:
  • Cloud security monitoring (AWS, Azure, GCP)
  • Identity threat detection (e.g., Azure AD, IAM abuse)
  • Detection & Alerting Use Case Management
  • Python, PowerShell, or equivalent
  • Experience in financial services, fintech, or payment environments is highly preferred
Familiarity with:
  • Data analytics and log pipelines
  • SOAR and automation frameworks
Preferred Certifications
  • GIAC (GCFA, GCDA, GCTI, GPEN)
  • CISSP, CISM
  • Microsoft SC-200 / Azure security certifications
  • Elastic(or equivalent SIEM certifications)
  • Deep technical expertise with hands-on capability
  • Analytical and investigative mindset
  • Strong leadership and mentoring skills
  • Ability to translate intelligence into actionable detection
  • Strong communication and stakeholder management
  • Continuous improvement and engineering mindset
What Success Looks Like
  • Measurable reduction in MTTD and false positives
  • Increased detection coverage aligned to MITRE ATT&CK
  • Proactive identification of previously unknown threats
  • Mature, scalable Detection Engineering program
  • Strong collaboration across SOC, IR, and Red Team functions
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Lead Cyber Detection Engineer
Senior Lead Cyber Detection Engineer

NETS • Singapore

On-site
SGD 180,000 - 280,000
Cyber Threat Intelligence & Incident Response Specialist
Cyber Threat Intelligence & Incident Response Specialist

PERCEPT SOLUTIONS PTE. LTD. • Singapore

On-site
SGD 180,000 - 260,000
Cyber Threat Intelligence & Incident Response Specialist
Cyber Threat Intelligence & Incident Response Specialist

Base Camp Recruitment Pte Ltd • Singapore

On-site
SGD 140,000 - 210,000
Senior Cyber Threat Intelligence & Incident Response Specialist
Senior Cyber Threat Intelligence & Incident Response Specialist

SPH Media • Singapore

On-site
SGD 120,000 - 180,000
Lead Detection Engineer: MITRE-Driven Threat Hunting
Lead Detection Engineer: MITRE-Driven Threat Hunting

NETS • Singapore

On-site
SGD 180,000 - 280,000
Senior Cyber Defence Engineer
Senior Cyber Defence Engineer

Newbridge • Singapore

On-site
SGD 180,000 - 280,000
Senior Cyber Defence Engineer
Senior Cyber Defence Engineer

newbridge alliance pte. ltd. • Singapore

On-site
SGD 150,000 - 190,000
Analyst, Threat Detection and Response
Analyst, Threat Detection and Response

SATS Ltd. • Singapore

On-site
SGD 65,000 - 90,000
Senior Analyst, Threat Detection and Response
Senior Analyst, Threat Detection and Response

WhiteCrow Research • Singapore

On-site
SGD 120,000 - 180,000
Detection Engineer – EASM / ASM / Cyber Threat Intelligence (CTI)
Detection Engineer – EASM / ASM / Cyber Threat Intelligence (CTI)

ASTEK SINGAPORE INNOVATION TECHNOLOGY PTE. LTD. • Singapore

On-site
SGD 90,000 - 150,000