Lead Security Engineer, IT Security Operations
Sea · Singapour
Job description
About the role
The Lead Security Engineer will join the Corporate IT Security Operations team to support the IT Security Operations Manager in engineering, operating, and continuously improving enterprise security platforms. This role focuses on modernising SIEM, managing EDR/XDR solutions, automating security workflows, and exploring AI‑enabled SecOps capabilities.
Key responsibilities
- Engineer, operate, and enhance SIEM, EDR/XDR, security automation/orchestration tools, and security data pipelines.
- Lead the migration of the SIEM environment to Elastic on Google Cloud Platform, handling log ingestion, pipeline development, dashboards, alerting, rule tuning, and platform optimisation.
- Build and maintain data pipelines for logs from corporate IT systems, networks, endpoints, identity platforms, cloud services, applications, and security tools.
- Improve alert enrichment, investigation workflows, case routing, ticketing integration, operational dashboards, and reporting.
- Support security monitoring, alert triage, threat investigation, incident response, detection tuning, and mitigation activities.
- Translate SecOps pain points into engineering improvements such as better detections, false‑positive reduction, automation playbooks, and runbooks.
- Explore AI‑enabled use cases including anomaly detection, alert enrichment, investigation assistance, behavioural analytics, and automation of repetitive SOC workflows.
- Partner with infrastructure, network, cloud, endpoint, identity, application, and cybersecurity teams to enhance security visibility and operational effectiveness.
- Provide coaching, technical guidance, solution reviews, and knowledge sharing to team members.
- Maintain technical documentation, operational runbooks, security playbooks, platform standards, and handover materials.
Required profile
- Bachelor’s degree in Computer Science, Cybersecurity, Information Technology or a related field.
- Hands‑on experience in security engineering, investigations, SIEM/EDR operations, and security automation.
- Proven ability to improve detection quality, reduce false positives, and develop automation playbooks.
- Experience translating operational challenges into practical engineering solutions.
Required skills
- SIEM platforms (Elastic, log ingestion, pipeline development, dashboard creation, alerting, rule tuning).
- EDR/XDR solutions.
- Security automation/orchestration tools.
- Security data pipelines and log management.
- Google Cloud Platform (GCP) environment.
- AI/ML concepts applied to SecOps (anomaly detection, alert enrichment, behavioural analytics).
- Incident response, threat investigation, and detection tuning.
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in Singapore.
Salaries by job title
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
Published 1 day ago
Expires 1 month from now
8 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
Sea
Singapour
Related job offers
-
ServiceNow Solution Architect – Platform & AI Expert
Cognizant Singapour -
Project Manager – Cybersecurity Consulting
Sekuro Asia - An Insight Company Singapour -
Infrastructure Engineer
DXC Technology Singapour -
Senior VS Interface Manager (HTC)
HSBC BANK (SINGAPORE) LIMITED Singapore -
Senior Analyst, CRM Enterprise Application
KULICKE & SOFFA PTE. LTD. Singapore