Job Title: Senior IT Security Engineer
Reports to: Senior IT Security Manager
Employment Type: Full-time
Location: Singapore
Key Responsibilities:
Threat Detection and Analysis
- Lead threat hunting initiatives by combining intelligence-driven research with proactive hypothesis testing.
- Analyze network traffic, logs, and endpoint data to uncover malicious activities and identify attack vectors.
- Develop, maintain, and optimize a comprehensive set of Endpoint Detection and Response (EDR) detection rules tailored to the organization's environment.
- Correlate EDR alerts with data from other security tools to reconstruct attack timelines and enhance detection capabilities.
Security Solution Integration and Maintenance
- Integrate and maintain security solutions across the organization’s infrastructure, ensuring seamless operation and enhanced protection.
- Normalize and standardize logs from diverse sources to ensure consistency and improve the efficiency of security monitoring and analysis.
- Continuously evaluate and update security solutions to stay ahead of emerging threats and vulnerabilities.
- Ensure all security solutions are properly maintained, patched, and configured to meet the organization’s security policies and standards.
- Collaborate with other teams to ensure security solutions are effectively integrated with existing systems and processes.
Incident Response and Remediation
- Conduct in-depth forensic analysis of compromised systems and incident logs to identify the root cause of security breaches.
- Perform reverse engineering on identified threats to understand their functionality and enhance detection and prevention strategies.
- Lead investigations into data leakage incidents, from initial alert through full resolution, including root cause analysis and implementation of preventative measures.
- Develop and deploy custom scripts to automate remediation tasks, such as malware removal, file restoration, and password resets.
Qualifications:
Experience: Proven experience in integrating and maintaining security solutions within complex IT environments.
Technical Skills: Strong proficiency in log normalization, security information and event management (SIEM) systems, and EDR tools.
Scripting: Familiarity with scripting languages (e.g., PowerShell, Python) for automation and custom security solution development.
Analytical Skills: Strong analytical and problem-solving skills, with the ability to conduct in-depth forensic analysis and threat detection.
Knowledge: Up-to-date knowledge of current security threats, vulnerabilities, and attack vectors.
Collaboration: Ability to work effectively with cross-functional teams, ensuring security solutions are seamlessly integrated with existing systems.
Preferred Skills:
- Security Frameworks: Experience with security frameworks and standards (e.g., MITRE ATT&CK, NIST, ISO 27001).
- Reverse Engineering: Background in reverse engineering malware and understanding threat actor tactics, techniques, and procedures (TTPs).
- Incident Response: Demonstrated experience in leading incident response efforts, including root cause analysis and post-incident reviews.
- Continuous Learning: Commitment to continuous learning and staying current with emerging security trends, tools, and best practices.