Posted 4 months ago
Cybersecurity Incident Responder - (EL-FNP250819 008/01)
SingaporeOn-siteFull-time
AI Summary
Lead response to cybersecurity incidents, perform real-time and retrospective analysis, coordinate with SOC teams, develop incident response plans, conduct threat hunting and digital forensic analysis, and provide technical leadership to junior staff.
About this role
- Lead the response to cybersecurity incidents, including malware infections, data breaches, and insider threats.
- Perform real-time and retrospective analysis of security events to identify threats Coordinate with MSSP Security Operations Centre (SOC) teams for monitoring and alerting.
- Develop and document incident response plans and playbooks.
- Should be expertise on handling the incidents end to end.
- Conduct proactive threat hunting to identify unknown threats.
- Perform digital forensic analysis on compromised systems to determine root causes.
- Use forensic tools to collect and analyse logs, memory dumps, and disk images.
- Work with SIEM (Security Information and Event Management) tools to detect anomalous behaviour.
- Analyse logs from firewalls, intrusion detection/prevention systems (IDS/IPS), endpoint protection, and cloud security tools.
- Improve detection capabilities by tuning security alerts and developing new rules.
- Recommend and implement security controls to reduce exposure.
- Provide technical leadership to junior incident responders and security analysts
Requirements
- Strong expertise in incident response, threat hunting, and forensic analysis.
- Experience with SIEM tools (e.g., Elastic, Splunk).
- Proficiency in network security, malware analysis, and log analysis.
- Familiarity with cloud security (AWS, Azure, GCP) and container security.
- Experience with cloud security tools and AI-powered security analytics (AWS Guard Duty, Azure Sentinel, Google Chronicle).
- Familiarity with AI/ML-driven anomaly detection and behavioural analysis techniques.
- Knowledge of security solutions ( EDR,XDR,NDR,WAF,Proxy,Firewall,Email Security).
- Scripting and automation skills (Python, PowerShell, Bash).
- Deep understanding of MITRE ATT&CK framework, cyber kill chain, and machine learning models for cybersecurity applications.
- Excellent communication and report-writing skills and ability to work under pressure scenarios
Skills
AI/ML-driven Anomaly DetectionAWSAzureBashBehavioural AnalysisCloud SecurityContainer SecurityCyber Kill ChainDigital ForensicsEDRElasticEmail SecurityFirewallGCPIncident ResponseLog AnalysisMalware AnalysisMITRE ATT&CKNDRNetwork SecurityPowerShellProxyPythonSIEMSplunkThreat HuntingWAFXDR
Explore related jobs
More jobs at Xcellink Pte Ltd
- NOC Operators - ANC-SSMY260918 001/06Selangor, Selangor
- Account Delivery & Operations Manager (ADOM) - Network InfrastructureSingapore, South West
- Data Center Facility & Operations ManagerJohor Bahru, Johor
- Cloud Engineer (AL-FNC260602 001/02)Singapore, Singapore
- Endpoint Security Engineer, MS (AL-FNC260602 003/01)Singapore, Singapore
- Cloud Systems Engineer, Windows/Linux (AL-FNC260602 002/01)Singapore, Singapore
Similar AI/ML-driven Anomaly Detection jobs
Jobs in Singapore
- Manager, Business DevelopmentDelivery Hero · Singapore, Singapore
- Senior / Cloud Platform EngineerNCS · Singapore, Singapore
Internship Opportunity - SingaporeFrost & Sullivan · Singapore- Senior Executive, CommercialAECOM · Singapore, Singapore
Food & Beverage Attendant / CaptainAccorhotel · Singapore, Singapore- Senior Project ManagerKeppel Seghers Engineering Singapore Pte. Ltd. · Singapore
Browse these categories
Market data for this role
All reports →- SeriesRole reportsOne role family at a time: how many openings, what changed this week, who is hiring, what it pays.
- SeriesSalary reportsWhat employers publish in job postings, by level and workplace. Not self-reported pay.
- Market overviewState of tech hiring, September 2026: up 4.8%Tech hiring rose 4.8% month over month in September 2026, with 411,122 new listings. Customer support and account executive roles led the growth.