📢 New: get today's jobs on our WhatsApp Channel
Jobiglo

No results.

Lead Security Engineer, IT Security Operations

Sea · Singapour

New
🇬🇧 English
SIEM Elastic log ingestion pipeline development alerting rule tuning EDR/XDR security automation orchestration tools security data pipelines anomaly detection alert enrichment behavioural analytics incident response threat investigation detection tuning

Job description

About the role

The Lead Security Engineer will join the Corporate IT Security Operations team to support the IT Security Operations Manager in engineering, operating, and continuously improving enterprise security platforms. This role focuses on modernising SIEM, managing EDR/XDR solutions, automating security workflows, and exploring AI‑enabled SecOps capabilities.

Key responsibilities

  • Engineer, operate, and enhance SIEM, EDR/XDR, security automation/orchestration tools, and security data pipelines.
  • Lead the migration of the SIEM environment to Elastic on Google Cloud Platform, handling log ingestion, pipeline development, dashboards, alerting, rule tuning, and platform optimisation.
  • Build and maintain data pipelines for logs from corporate IT systems, networks, endpoints, identity platforms, cloud services, applications, and security tools.
  • Improve alert enrichment, investigation workflows, case routing, ticketing integration, operational dashboards, and reporting.
  • Support security monitoring, alert triage, threat investigation, incident response, detection tuning, and mitigation activities.
  • Translate SecOps pain points into engineering improvements such as better detections, false‑positive reduction, automation playbooks, and runbooks.
  • Explore AI‑enabled use cases including anomaly detection, alert enrichment, investigation assistance, behavioural analytics, and automation of repetitive SOC workflows.
  • Partner with infrastructure, network, cloud, endpoint, identity, application, and cybersecurity teams to enhance security visibility and operational effectiveness.
  • Provide coaching, technical guidance, solution reviews, and knowledge sharing to team members.
  • Maintain technical documentation, operational runbooks, security playbooks, platform standards, and handover materials.

Required profile

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology or a related field.
  • Hands‑on experience in security engineering, investigations, SIEM/EDR operations, and security automation.
  • Proven ability to improve detection quality, reduce false positives, and develop automation playbooks.
  • Experience translating operational challenges into practical engineering solutions.

Required skills

  • SIEM platforms (Elastic, log ingestion, pipeline development, dashboard creation, alerting, rule tuning).
  • EDR/XDR solutions.
  • Security automation/orchestration tools.
  • Security data pipelines and log management.
  • Google Cloud Platform (GCP) environment.
  • AI/ML concepts applied to SecOps (anomaly detection, alert enrichment, behavioural analytics).
  • Incident response, threat investigation, and detection tuning.

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec Sea.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.

Why are you reporting this job?

Thank you for your report. We will review this job.

Explore further

Salaries, guides and searches in Singapore.

Apply in 30 seconds

Enter your email to apply. An account will be created automatically.

By continuing, you accept our terms of use.

Already have an account? Login

💬 Chat with us on Telegram Chat on WhatsApp

Published 1 day ago

Expires 1 month from now

8 views · 0 interested

Boost your chances

Upload your CV — we will match you with relevant openings.

Analyzing your CV...

Sea

Singapour