Senior Lead Cyber Detection Engineer

NETWORK FOR ELECTRONIC TRANSFERS (SINGAPORE) PTE LTDSingaporemycareersfutureoffentliggjort 24.08.2026
Skal:PythonAWSAzureGoogle CloudCloudDevOpsCI/CDAIFinTechSecuritySeniorLeadJunior

Key Responsibilities

Detection Engineering & Security Monitoring

  • Design, develop, and tune high-fidelity detection use cases across SIEM, EDR, NDR, and cloud security platforms.
  • Build detection logic mapped to MITRE ATT&CK, focusing on reducing dwell time and false positives.
  • Drive Detection-as-Code practices, leveraging automation, version control, and CI/CD pipelines.
  • Continuously improve use-case coverage based on threat intelligence, incidents, and red/purple team outcomes.
  • Evaluate and onboard new security telemetry sources to enhance visibility.

Threat Hunting

  • Lead proactive, hypothesis-driven threat hunting campaigns across endpoints, network, cloud, and identity systems.
  • Investigate anomalous behaviors and identify stealthy adversary activities that bypass automated detections.
  • Develop reusable hunting playbooks and analytics.
  • Collaborate with Incident Response to transition hunts into confirmed incidents and detection improvements.

Threat Intelligence

  • Operationalize threat intelligence (strategic, tactical, and operational) into actionable detection use cases.
  • Track and profile threat actors targeting financial services / payment ecosystems.
  • Integrate intelligence feeds into detection pipelines and SOC workflows.
  • Produce intelligence-driven insights and advisories for stakeholders.

Leadership & Technical Oversight

  • Serve as a technical lead and mentor for SOC analysts and junior detection engineers.
  • Set standards for detection quality, triage effectiveness, and threat coverage.
  • Partner with Red Team/Purple Team to validate detection capabilities.
  • Act as an escalation point for complex investigations and advanced threat scenarios.

Automation & Engineering

  • Develop scripts and tooling (Python, PowerShell, etc.) to automate detection, enrichment, and response workflows.
  • Integrate with SOAR platforms to improve SOC efficiency.
  • Drive telemetry normalization and data quality improvements.

Stakeholder Engagement

  • Work closely with IT, Cloud, DevOps, Fraud, and Risk teams to improve enterprise visibility.
  • Provide clear technical reporting and metrics to leadership.
  • Support regulatory and audit requirements relevant to security monitoring.

Required Qualifications & Experience

10–15+ years of cybersecurity experience, with at least:

  • 5+ years in detection engineering / threat hunting / SOC engineering
  • 3+ years in a lead or senior technical role

Strong experience with:

  • SIEM platforms
  • EDR/XDR solutions
  • Threat hunting methodologies and tooling
  • Agentic AI, LLM

Deep understanding of:

  • MITRE ATT&CK framework
  • Adversary tactics, techniques, and procedures (TTPs)

Experience with:

  • Cloud security monitoring (AWS, Azure, GCP)
  • Identity threat detection (e.g., Azure AD, IAM abuse)
  • Detection & Alerting Use Case Management

Strong scripting/programming skills:

  • Python, PowerShell, or equivalent

Experience in financial services, fintech, or payment environments is highly preferred

Familiarity with:

  • Detection engineering lifecycle
  • Data analytics and log pipelines
  • SOAR and automation frameworks

Preferred Certifications

  • GIAC (GCFA, GCDA, GCTI, GPEN)
  • CISSP, CISM
  • Microsoft SC-200 / Azure security certifications
  • Elastic(or equivalent SIEM certifications)

Key Competencies

  • Deep technical expertise with hands-on capability
  • Analytical and investigative mindset
  • Strong leadership and mentoring skills
  • Ability to translate intelligence into actionable detection
  • Strong communication and stakeholder management
  • Continuous improvement and engineering mindset

What Success Looks Like

  • Measurable reduction in MTTD and false positives
  • Increased detection coverage aligned to MITRE ATT&CK
  • Proactive identification of previously unknown threats
  • Mature, scalable Detection Engineering program
  • Strong collaboration across SOC, IR, and Red Team functions