Senior Security Lead
Singapore, Central Singapore, Singapore
Sopra Steria I2S
Sopra Steria, a European Tech leader recognised for its consulting, digital services and software development, helps its clients drive their digital transformation to obtain tangible and sustainable benefits.Sopra Steria is a listed European tech leader specializes in Consulting, Digital Service, and Software. We have 50,000 employees worldwide located in different regions (Europe, North America and Asia), whereby Singapore is the HQ for APAC. EvaGroup Asia Pacific is part of Sopra Steria, in charge of Infrastructure, Cloud and Cybersecurity services in APAC.
We are looking for a Cybersecurity expert in Detection Engineering & Security Investigation areas, part of Production SOC & Security Investigation & Incident Response team.
Your role will be to:
- Act as reference point in team of experts on Security Incident Response activities, Anti-Malware/Defense activities and Security Detection activities,
- Oversee the detection capabilities for the 24/7 regional IT Production SOC which handles the IT Production security alerts for the APAC region,
- Contribute to the enhancement of SIEM and SOAR capabilities,
- Strengthen the detection capabilities in APAC and be member of the Global Use Case committee for a worldwide alignment of the security use cases.
- Participate to the global continuous improvement of the framework of tools and processes for Security Incident Management, Anti-Malware/Defense and Security Detection,
- Collaborate with the APAC Business CSIRT, accountable for the Security Incident practice in APAC, to strengthen the extended security monitoring setup between Business Information Security and IT Production Security.
Requirements
Direct Responsibilities:
- Hands on experience for SIEM, security incident analysis, Incident response (IR) Malware analysis, and threat hunting
- Knowledge of MITRE or similar framework
- Lead technical activities (definition, R&D/threat hunting) in the team of IT Production Security Investigation & Incident Response and oversee the detection capabilities of the 24/7 regional IT Production SOC
- Be responsible for the security monitoring and security incident response for the regional IT production
- Partner with global, regional and local stakeholders to ensure organizational and procedural efficiency and readiness for detection of suspicious events and reaction upon security incident
- Continuously improve the processes to strengthen the current SOC framework via review of policies and operational playbooks
- Steer the regional threat modeling, identification of threat vectors and development of related security monitoring capabilities
- Participate in the Use Case Committee factory to improve the detection capabilities
- Report to global regional and local stakeholders on the strategic and operational aspects of these activities
Contributing Responsibilities
- Partner with the APAC Business CSIRT for integrated security monitoring and alert/incident handling operations
- Contribute to local security incident response outside the direct scope of responsibilities (i.e., local IT production in some APAC business entities)
- Contribute to the Bank compliance with regulatory requirements and internal policies
- Contribute to the reporting of all incidents according to the Incident Management System
- Contribute to the control frameworks in day‐to‐day business activities, such as Control Plan; Participate to Audit interview and provide the require evidence
Competencies:
- Requires a minimum of 8+ years of experience as security professional
- Excellent interpersonal and communication skills; ability to influence and motivate
- Ability to handle high pressure situations with key stakeholders to collaborate and communicate effectively and respectfully with both business-oriented executives and technology-oriented personnel in teams across the organization
- Experience of performing security monitoring and incident response activities in an advanced Security Operation Centers (SOC) environment (log analysis, event analysis, incident investigation, reporting)
- Experience and knowledge in investigating incidents, remediation, tracking and follow-up for incident closure with concerned teams, stakeholders.
- Exhaustive technical knowledge and hands on experience in several security domains
- Thorough understanding of technologies and security concepts, with knowledge & hands on experience in SIEM Product and Security Incident Management
- Program and project management expertise
- Taking initiative; be proactive and run decision-making processes autonomously
Specific Qualifications:
- Successful people management experience
- Professional credentials in one of the relevant IT Security disciplines is a plus (CISSP / OSCP / SANS)
- Experience in common scripting languages such as Python, PowerShell, Bash is a plus
- Experience in SIEM on ELK(Elastic Logstash Kibana) stack is a plus
Benefits
- Regular team buildings
- 18 leave days / Year
- Health Insurance: GP, Life Insurance, Dental Insurance and Optical insurance
- Annual bonus
- Working hours: from 9am to 6pm, Monday to Friday
- E-learning and certifications paths
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Bash CISSP Cloud Compliance CSIRT ELK Incident response Log analysis Malware Monitoring OSCP PowerShell Python R&D SANS Scripting SIEM SOAR SOC
Perks/benefits: Career development Health care Salary bonus Team events
More jobs like this
Explore more InfoSec / Cybersecurity career opportunities
Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.
- Open Information Security Specialist jobs
- Open Consultant infrastructure sécurité H/F jobs
- Open Senior Information Security Analyst jobs
- Open IT Security Analyst jobs
- Open Consultant SOC / CERT H/F jobs
- Open Senior Information Security Engineer jobs
- Open Information Security Officer jobs
- Open Staff Security Engineer jobs
- Open Security Operations Engineer jobs
- Open Analyste CERT / Incident Responder junior (H/F) jobs
- Open Ingénieur DevSecops H/F jobs
- Open Cybersecurity Consultant jobs
- Open Senior Security Architect jobs
- Open Chief Information Security Officer jobs
- Open Analyste CERT / Incident Responder senior (H/F) jobs
- Open Information Systems Security Officer (ISSO) jobs
- Open Senior Security Analyst jobs
- Open o365 Security Architect jobs
- Open Principal Security Engineer jobs
- Open Senior Cyber Security Engineer jobs
- Open Staff Product Security Engineer jobs
- Open Electronic Warfare Advanced Tactical Trainer jobs
- Open Product Security Engineer jobs
- Open Security Researcher jobs
- Open Cyber Security Architect jobs
- Open SOC-related jobs
- Open GCP-related jobs
- Open Risk assessment-related jobs
- Open Governance-related jobs
- Open Network security-related jobs
- Open Pentesting-related jobs
- Open ISO 27001-related jobs
- Open CISM-related jobs
- Open Analytics-related jobs
- Open SaaS-related jobs
- Open Threat intelligence-related jobs
- Open IAM-related jobs
- Open Malware-related jobs
- Open Security Clearance-related jobs
- Open Vulnerability management-related jobs
- Open Java-related jobs
- Open CISA-related jobs
- Open Security assessment-related jobs
- Open Kubernetes-related jobs
- Open DevOps-related jobs
- Open Forensics-related jobs
- Open APIs-related jobs
- Open DoD-related jobs
- Open IDS-related jobs
- Open SQL-related jobs