S

Senior Analyst, Threat Detection and Response

Singapore Singapore

4 days ago


Years of Experience

10 - 15 years

Workplace Type

On-site

Seniority Type

Associate

Industry

Airlines/Aviation


Analyse your salary

Want to know how much a Senior Analyst, Threat Detection and Response make in Singapore Singapore?

Get Salary insights for Senior Analyst, Threat Detection and Response in Singapore Singapore. Know how your salary compares to the industry average. Our AI analyzer uses other candidates' stated pay expectations to identify market trends.


Skills

Threat Detection & ResponseThreat HuntingSIEM & Detection ToolsIncident ResponseEndpoint & Network Security

Contact our TA to know more about the job

Pooja Shetty

Talent Advocate at WhiteCrow


Description

About our client

Our client is a globally recognized organization headquartered in Southeast Asia, specializing in aviation support services, air cargo handling, ground operations, and institutional food solutions. The company provides a wide range of services, including passenger assistance, ramp and baggage handling, aviation security, aircraft cleaning, and laundry operations for the aviation sector.

Beyond aviation services, the organization operates large-scale central kitchens and food production facilities, catering to airlines, corporate clients, and institutions across diverse cuisines and service formats. With a strong presence across Asia-Pacific, Europe, the Americas, the Middle East, and Africa, the company supports global travel, trade, and logistics through an extensive international network, further strengthened by strategic acquisitions in recent years.


Job description

Responsibilities:


  • Continuously monitor security consoles and dashboards (SIEM, EDR, etc.) for suspicious activity; triage alerts to identify valid security incidents versus false positives and prioritize response based on asset criticality and business risk.
  • Investigate suspicious activities and security events, determine the scope and severity of incidents, and gather relevant evidence. Perform root cause analysis to identify attack vectors and affected systems.
  • Execute incident response actions end-to-end – including timely containment of threats, eradication of malicious artifacts, and system recovery – following the organization’s incident response plan. Coordinate with IT infrastructure, application owners, and other stakeholders to ensure effective remediation of incidents.
  • Proactively hunt for indicators of compromise and hidden threats in logs, network traffic, and endpoint telemetry, even without specific alerts. Use hypothesis-driven techniques and knowledge of attacker TTPs to uncover stealthy or emerging threats that evaded initial detection.
  • Continuously tune SIEM/EDR detection rules, thresholds, and SOAR playbooks—automating repetitive response actions to reduce false positives and accelerate containment
  • Leverage internal and external threat intelligence sources to enrich analysis and response. Stay updated on new vulnerabilities and adversary tactics; incorporate this knowledge to adjust monitoring rules and incident response strategies. Map observed malicious activities to frameworks like MITRE ATT&CK for reporting and analysis.
  • Work closely with global SOC team members and escalate complex incidents to senior analysts or incident response leads when necessary. Collaborate with colleagues in other regions to ensure seamless coverage and knowledge sharing across the security team.
  • Document investigation steps, findings, and actions taken for each incident in a clear and concise manner. Prepare incident reports and contribute to post-incident review meetings, highlighting what occurred, how it was resolved, and recommendations to prevent future occurrences.
  • Assist in developing and updating incident response playbooks, standard operating procedures, and knowledge base documentation. Provide feedback and suggestions to improve security monitoring tools, analytics content (detection rules), and workflow automation (SOAR playbooks) for greater efficiency and effectiveness.
  • Share insights from incidents and trending threats with the broader team to enhance overall awareness. Mentor and guide junior analysts (Tier 1 SOC analysts) by sharing analysis techniques and best practices, elevating the team’s collective skill level.


Requirements:


  • Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, or equivalent threat management & incident response experience
  • Currently hold cybersecurity certifications such as GCIH, GCFA, GCIA, CEH, others
  • With 3 years or more, progressive experience in at least two of the following disciplines:
  • Threat Detection & Analysis (leveraging SIEM tools, IDS/IPS, endpoint detection, log analysis, etc.)
  • Incident Response & Management (developing response plans, executing playbooks, forensic investigations, root cause analysis)
  • Threat Hunting (identifying undetected threats through proactive analysis and hypothesis-driven investigation)
  • Cyber Threat Intelligence (gathering and analyzing threat intelligence to inform detection capabilities and preventive measures)
  • Network Security (TCP/IP protocols, firewalls, intrusion prevention systems, and network traffic analysis)
  • Securing and monitoring operating system and cloud environments (AWS, Azure, GCP), including analyzing cloud service logs and configurations for suspicious activities, and understanding cloud-native security controls and best practices
  • Demonstrated ability to:
  • Function as a Level 2 or 3 SOC Analyst (analyzing and responding to cybersecurity incidents)
  • Preferred Experience:
  • Experience with SOAR tools and some proficiency in scripting languages (e.g., Python, PowerShell) to automate repetitive tasks and streamline incident response workflows
  • Advanced understanding of emerging threats, zero-day vulnerabilities, and common attack vectors (phishing, malware, ransomware, lateral movement) with the ability to ensure rapid detection and response
  • Hands-on experience using SIEM and EDR platforms for centralized log analysis, real-time threat monitoring, and in-depth incident investigations
  • In-depth knowledge of the incident response lifecycle
  • Proven ability to conduct proactive threat hunting operations, leveraging the MITRE ATT&CK framework to map adversary tactics, techniques, and procedures (TTPs), uncover stealthy threats, and close gaps in detection coverage
  • Familiarity with cyber threat intelligence feeds and standards (e.g., STIX, TAXII), incorporating IOCs (Indicators of Compromise) and threat intel data into monitoring and investigations to enrich context and anticipate emerging threats
  • Understanding of key security frameworks and regulations (e.g., NIST CSF, ISO 27001, GDPR) and the ability to align threat detection and incident response processes with organizational policies and compliance requirements
  • Effective at coordinating with cross-functional teams (IT, DevOps, Business, etc.) during high-impact incidents and translating complex technical findings into clear, actionable insights for executive and non-technical stakeholders

Sign up to create profile

Fill in your details to create profile on WhiteCrow

Why get hired via WhiteCrow?

We take your privacy seriously

We take your privacy seriously

By default, your profile stays hidden from past & current employers. We only showcase your anonymous profile to employers and seek your permission before revealing your full profile.

Know more

Personal & Dedicated Talent Advocate

Personal & Dedicated Talent Advocate

Our Talent Advocates are here to help: from providing insider knowledge to guiding you through interviews to negotiations.

Know more

Exclusive Jobs from Top Companies

Exclusive Jobs from Top Companies

Gain access to mid to senior level executive job opportunities at more than 90 of the Fortune 500 companies globally on WhiteCrow.

Know more

Why get hired via WhiteCrow?

With our unique combination of AI matching technology and human expertise, WhiteCrow will help you get discovered for your unicorn role.

Know more

Contact our TA to know more about the job

Pooja Shetty

Talent Advocate at WhiteCrow


People also viewed

UAEN Senior Executive - Urban Planning

Dubai, United Arab Emirates

4 days ago


Solution Architect, Cargo Management Systems

Singapore, Singapore

4 days ago


AVP - Group Human Capital Solution Architect

Singapore, Singapore

4 days ago


L3 Production Support (AS400, RPG), Core Banking

Kuala Lumpur, Malaysia

6 days ago


Accounts Executive

Bang Hua Suea, Thailand

7 days ago


Sales Manager

Balikpapan, Indonesia

7 days ago


Application Developer - Fullstack Developer

Alabang, Philippines

12 days ago


TA Specialist

Chon Buri, Thailand

12 days ago


View more jobs

Sign up to create profile

Fill in your details to create profile on WhiteCrow