VP, Threat Detection Engineer

SGX Group

Singapore

On-site

SGD 250,000 - 360,000

Full time

25 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

SGX Group is seeking a Vice President, Information Security to lead the design, development, and optimization of advanced detection capabilities across SIEM, EDR, NDR, and cloud platforms. You will work with SOC, incident response, threat intelligence, and IT teams to strengthen threat hunting, detection tuning, and rapid incident response.

The role emphasizes strategic thinking, strong stakeholder management, and measurable improvements in control and risk mitigation within a fast‑paced

Qualifications

  • At least 10 to 15 years of relevant experience, preferably in financial services or asset management industries, with a minimum of 5 years in cybersecurity platforms.
  • In‑depth knowledge and experience in information security policy and principles.
  • Experience in MAS technology related guidelines such as Technology Risk Management Guidelines, Cyber Hygiene, Outsourcing guidelines etc.
  • Strong technical knowledge of common security tools (e.g., EDR, SIEM, SOAR, XDR, email security, vulnerability management, cloud security).
  • Experience tuning detection rules, configuring integrations, and conducting process enhancement.
  • Demonstrate ability to operate in diverse environments and cultures and enjoys working in challenging and fast‑paced environment.
  • Self‑initiated, meticulous, versatile, analytical and inquisitive.
  • Strong communication and presentation skills to wide and diverse audiences.

Responsibilities

  • Design, develop, and maintain security detection rules and use cases across SIEM, EDR, NDR, and cloud security platforms.
  • Create detection logic based on known threat actor tactics, techniques, and procedures (TTPs).
  • Develop behavioral analytics and anomaly detection models.
  • Map detections to MITRE ATT&CK | MITRE ATLAS framework techniques.
  • Continuously tune detection rules to improve effectiveness and reduce false positives.
  • Analyze emerging threats, vulnerabilities, and attack trends.
  • Translate threat intelligence into actionable detection content.
  • Assess detection coverage against evolving cyber threats.
  • Identify gaps in monitoring and recommend improvements.
  • Work with teams to develop hypotheses and supporting detection content.
  • Collaborate with threat hunters to identify previously unknown threats.
  • Convert successful threat‑hunting findings into permanent detections.
  • Improve event correlation and alerting strategies.

Skills

EDR
SIEM
SOAR
XDR
Cloud security
Threat intelligence
MITRE ATT&CK
Detection tuning
Threat hunting
Incident response

Tools

CISSP
CISM
GCIA
GSEC

Job description

At SGX Group, we create markets. We turn ideas into products and expand access to new opportunities. We are building the future of the exchange in‑house: from architecture and platforms to the critical systems that power markets. The biggest decisions are still open to people who join us now.

Job description:

BUILD MARKETS. SHAPE ECONOMIES.

At SGX Group, we create markets. We turn ideas into products and expand access to new opportunities. We are building the future of the exchange in‑house: from architecture and platforms to the critical systems that power markets. The biggest decisions are still open to people who join us now.

The opportunity

SGX is seeking Vice President (Information Security) lead and enhanced our detection capabilities. The Threat Detection Engineer is responsible for designing, developing, tuning, and maintaining cybersecurity detection capabilities across the organization’s technology landscape.

This role focuses on identifying malicious activity, improving detection coverage, reducing false positives, and enabling rapid incident response through the deployment of advanced detection rules, analytics, and threat‑hunting techniques. Working closely with Security Operations (SOC), Incident Response, Threat Intelligence, Security Engineering, and IT teams, the Threat Detection Engineer continuously enhances the organization’s ability to detect and respond to cyber threats.

The candidate will possess strong technical expertise in security detection, relevant platforms, hands‑on operational experience, and an engineering mindset focused on improving our speed to react. He/she must demonstrate ability to think strategically about SGX business and operations challenges and possess a keen eye for control improvement through innovative use of technology. The candidate also needs to manage both internal and external customers well, drive discussions with senior management, and have a sound process and technical background to engage the Technology teams.

What you will do
Detection Engineering
  • Design, develop, and maintain security detection rules and use cases across and not limited to SIEM, EDR, NDR, and cloud security platforms.
  • Create detection logic based on known threat actor tactics, techniques, and procedures (TTPs).
  • Develop behavioral analytics and anomaly detection models.
  • Map detections to MITRE ATT&CK | MITRE ATLAS framework techniques.
  • Continuously tune detection rules to improve effectiveness and reduce false positives.
  • Analyze emerging threats, vulnerabilities, and attack trends.
  • Translate threat intelligence into actionable detection content.
  • Assess detection coverage against evolving cyber threats.
  • Identify gaps in monitoring and recommend improvements.
  • Work with respective team to develop hypotheses and supporting detection content.
  • Collaborate with threat hunters to identify previously unknown threats.
  • Convert successful threat‑hunting findings into permanent detections.
  • Improve event correlation and alerting strategies.
Security Automation
  • Develop automated detection workflows using SOAR platforms.
  • Integrate detection content across multiple security controls.
  • Automate enrichment, triage, and response activities.
Detection validation
  • Perform adversary emulation and detection testing.
  • Conduct purple‑team exercises with offensive security teams.
  • Validate detection effectiveness through attack simulation.
  • Measure detection coverage and effectiveness metrics.
Integration & Engineering
  • Integrate security tools with other systems (e.g., SIEM, ticketing platforms, CMDB, SOAR) to enable automation and improve operational synergy.
  • Direct, drive process and documentation improvement in platform operations, escalation procedures, and workflows.
  • Work closely with Engineering, Infrastructure, Cloud, and SOC teams to ensure deployment of detection logics.
Vendor & Stakeholder Collaboration
  • Work with internal stakeholders to ensure tools outputs support detection use cases, incident response, audits, and compliance programs.
Expectations:
  • Sense of urgency for all urgent and important matters and accountable to decision made
  • Clear vision in mind to innovate and streamline the operations processes and detection ability defined by the organisation.
  • Passion to deliver sustainable solutions and continued improvement in control and risk mitigation.
  • Good discipline in timely submission and reporting key metrics and status.
What we are looking for
Essentials
  • At least 10 to 15 years of relevant experience, preferably in financial services or asset management industries, with a minimum of 5 years in cybersecurity platforms.
  • In‑depth knowledge and experience in information security policy and principles.
  • Experience in MAS technology related guidelines such as Technology Risk Management Guidelines, Cyber Hygiene, Outsourcing guidelines etc.
  • Strong technical knowledge of common security tools (e.g., EDR, SIEM, SOAR, XDR, email security, vulnerability management, cloud security).
  • Experience tuning detection rules, configuring integrations, and conducting process enhancement.
  • Demonstrate ability to operate in diverse environments and cultures and enjoys working in challenging and fast‑paced environment.
  • Self‑initiated, meticulous, versatile, analytical and inquisitive.
  • Strong communication and presentation skills to wide and diverse audiences.
What may set you apart
  • Certifications such as CISSP, CISM, GIAC GCIA/GSEC, Microsoft Security certifications, or equivalent.
  • Experience with security platforms, Endpoint security, Cloud security, detection technologies, analytics & query languages, operating systems and security frameworks (e.g. MITRE ATT&ACK, NIST).
About SGX Group

SGX Group is one of the world’s most trusted international marketplaces, known for its stability and openness. Anchored in Singapore, we enable price discovery, capital formation and risk management across asset classes, supported by resilient infrastructure and robust clearing. We convene issuers, investors and intermediaries to create and grow markets that stand the test of time. Find out more at www.SGXGroup.com.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Vice President, Senior Cyber Threat Analyst (Threat Hunting & Incident Response)
Vice President, Senior Cyber Threat Analyst (Threat Hunting & Incident Response)

SGX Group • Singapore

On-site
SGD 120,000 - 210,000
SA/AVP/VP - Software Engineer
SA/AVP/VP - Software Engineer

SGX Group • Singapore

On-site
SGD 120,000 - 180,000
Vice President, Cyber Threat Analyst
Vice President, Cyber Threat Analyst

Singapore Exchange Limited • Singapore

On-site
SGD 120,000 - 170,000
Chief Cyber Threat Architect & Threat Hunting Lead
Chief Cyber Threat Architect & Threat Hunting Lead

SGX Group • Singapore

On-site
SGD 120,000 - 210,000
VP - Deployed AI Engineer
VP - Deployed AI Engineer

SGX Group • Singapore

On-site
SGD 120,000 - 190,000
ED, Site Reliability Engineer
ED, Site Reliability Engineer

SGX Group • Singapore

On-site
SGD 250,000 - 400,000
SVP - Site Reliability Engineer
SVP - Site Reliability Engineer

SGX Group • Singapore

On-site
SGD 320,000 - 520,000
AVP/VP - Test Engineer
AVP/VP - Test Engineer

SGX Group • Singapore

On-site
SGD 140,000 - 210,000
AVP, Technology Assurance
AVP, Technology Assurance

SGX Group • Singapore

On-site
SGD 120,000 - 160,000
Cyber Threat Management Senior/Security Engineer
Cyber Threat Management Senior/Security Engineer

INTELLIPRO SINGAPORE PTE. LTD. • Singapore

On-site
SGD 90,000 - 130,000