Jobiglo

No results.

Security Engineer – Detection & Security Operations

Reap · Singapour

New Remote
Remote 🇬🇧 English
Microsoft Sentinel Splunk Elastic KQL SPL MITRE ATT&CK AWS CloudTrail Okta CrowdStrike Falcon Python Sentinel Playbooks Splunk SOAR

Job description

About the role

You will lead the creation of Reap's detection capability, turning known threat actor tactics into robust, automated controls. Partnering with engineering, risk and operations, you will ensure the company can move value safely 24/7 across a global payment platform.

Key responsibilities

  • Own the SIEM platform from evaluation to production, selecting the solution and driving ingestion from CrowdStrike, AWS CloudTrail, Okta, M365 and SaaS applications.
  • Write and maintain detection rule libraries targeting known TTPs such as Lazarus Group C2 beaconing, credential harvesting, lateral movement and AI data exfiltration.
  • Define alert triage and escalation processes, set SLAs, reduce false positives and handoff confirmed incidents to the Crypto/IR Security Engineer.
  • Operationalise threat intelligence feeds, extract IOCs/TTPs and translate them into detection rules on a regular cadence.
  • Build security metrics dashboards and automated reports for the CISO board pack (mean detection time, mean response time, alert volume, coverage gaps).

Required profile

  • Proven experience building detection rules from scratch and deploying SIEM platforms such as Microsoft Sentinel, Splunk or Elastic.
  • Hands‑on integration of log sources including AWS CloudTrail, Okta, CrowdStrike Falcon and Microsoft 365 audit logs.
  • Strong understanding of MITRE ATT&CK and ability to convert threat‑actor profiles into actionable detection logic.
  • Experience in alert triage, investigation and refining detection efficacy.
  • Python programming for security automation, log parsing and response workflows.

Required skills

  • SIEM platforms: Microsoft Sentinel, Splunk, Elastic
  • KQL or SPL query languages
  • AWS CloudTrail, Okta, CrowdStrike Falcon, Microsoft 365 audit logs
  • MITRE ATT&CK framework
  • Python scripting
  • SOAR tools: Sentinel Playbooks, Splunk SOAR (optional)

What we offer

  • Remote‑first work model with APAC‑friendly hours
  • Inclusive and vibrant company culture
  • Annual leave plus public holidays
  • Health insurance budget
  • Home office equipment budget and corporate Reap Card
  • Opportunity to build detection capability from the ground up alongside CISO and crypto security engineers

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec Reap.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.

Why are you reporting this job?

Thank you for your report. We will review this job.

Explore further

Salaries, guides and searches in Singapore.

Apply in 30 seconds

Enter your email to apply. An account will be created automatically.

Apply now →

By continuing, you accept our terms of use.

Already have an account? Login

A question about this job?

Ask it here: you will get the full job summary by e-mail, right away.

💬 Chat with us on Telegram

Published 5 hours ago

Expires 1 month from now

8 views · 0 interested

Boost your chances

Upload your CV — we will match you with relevant openings.

Analyzing your CV...

Reap

Singapour