Cyber Security Analyst (SOC | Min 3-5yrs | 24/7 shift work)
Must-have:PythonAWSAzureGoogle CloudCloudAIHealthTechSecurityJunior
Employment Type: 1-Year Contract (Renewable) Location: Braddell House, Singapore Working Hours: 24x7 (Shift Work)
Role Summary
We are looking for a Cyber Security Analyst to join a 24x7 Security Operations Center (SOC) team. The role will be responsible for security monitoring, incident investigation and response, threat detection, SIEM use-case optimization, and continuous improvement of SOC operations.
Key Responsibilities
Security Monitoring & Incident Response
- Monitor security alerts and events in real time using SIEM, EDR, IDS/IPS and other security tools.
- Triage, investigate and escalate security incidents according to defined severity levels and response procedures.
- Perform detailed analysis of alerts, logs and telemetry to determine root cause, impact and remediation actions.
- Execute incident response playbooks for security threats including phishing, malware, ransomware and unauthorized access.
- Document investigation steps, findings and actions taken accurately in case management or ticketing systems.
- Coordinate incident response activities with internal teams and external stakeholders when required.
- Ensure incidents are handled according to defined SLAs, playbooks and regulatory requirements.
Threat Detection & SIEM
- Tune and optimize SIEM detection rules to reduce false positives and improve threat detection effectiveness.
- Analyse security logs from firewalls, EDR, IDS/IPS, cloud platforms and operating systems.
SOC Improvement
- Contribute to the development and refinement of SOC processes, runbooks and incident response playbooks.
- Identify opportunities to improve SOC efficiency through automation, SOAR and AI-driven capabilities.
- Support SOC transformation and continuous improvement initiatives.
Team Support
- Provide guidance and knowledge sharing to junior analysts.
- Act as an escalation point for complex investigations and technical challenges.
- Support training and continuous skills development within the SOC team.
Requirements
- 3–5 years of experience in Cyber Security Operations, SOC or Incident Response roles.
- Strong hands-on experience with SIEM platforms such as Splunk, Elasticsearch or Palo Alto Cortex .
- Good understanding of network, endpoint, identity and cloud security concepts.
- Experience analysing logs from firewalls, EDR, IDS/IPS, cloud platforms and operating systems.
- Familiarity with incident response methodologies and digital forensics fundamentals.
- Proven experience handling medium to high-severity security incidents independently.
- Strong analytical and problem-solving skills.
- Calm and structured approach when handling security incidents under pressure.
- Strong sense of ownership, accountability and attention to detail.
- Comfortable working in a 24x7 shift environment .
Preferred Skills
- Experience with SOAR platforms and security automation.
- Cloud security experience with AWS, Azure or GCP.
- Scripting or query skills such as SPL, KQL, SQL or Python .
- Experience in SOC transformation or SIEM migration projects.
- Experience working in regulated environments such as financial services, government or healthcare.
- Security certifications such as GCIA, GCIH, GCED , or vendor-specific certifications from Microsoft, Splunk or Palo Alto.