Skip to content
Applying is always free. We will NEVER ask for your Singpass password or bank log-in. ScamShield 1799 (opens in new tab)
Applying on WorkJio is always free. WorkJio and its verified employers will NEVER ask job seekers to pay, transfer money, or disclose bank log-in or Singpass passwords. Call the 24/7 ScamShield ↗ (opens in new tab) Helpline at 1799 if you are unsure whether something is a scam.
Applying is always free. We will NEVER ask for your Singpass password or bank log-in. ScamShield 1799 (opens in new tab)
Applying on WorkJio is always free. WorkJio and its verified employers will NEVER ask job seekers to pay, transfer money, or disclose bank log-in or Singpass passwords. Call the 24/7 ScamShield ↗ (opens in new tab) Helpline at 1799 if you are unsure whether something is a scam.
A Singapore job board for part-time, gig and full-time work, from verified employers and companies’ own careers pages. Every listing is scam-checked, and applications made on WorkJio get a status update.
Senior Cyber Threat Intelligence & Incident Response Specialist job at SPH Media, Singapore | WorkJio
Full-time Tech & engineering · Posted 29 Sept
Senior Cyber Threat Intelligence & Incident Response Specialist S SPH Media Apply on company site
Salary
Not stated by the company
Start Not stated
Work mode On-site
Experience Experienced About the role This is a senior hands-on cybersecurity position focused on threat intelligence, incident response, threat hunting and detection engineering. The role sits within a security team in Singapore and suits an experienced technical individual contributor who takes end-to-end ownership of security products and capabilities. You will also manage the security technology lifecycle from identifying requirements through implementation, optimisation, renewal and retirement.
What you'll do Collect, analyse and operationalise intelligence from OSINT, dark web, commercial feeds and ISACs Perform adversary tracking, campaign analysis and TTP mapping using MITRE ATT&CK Know someone for this? Share it
Turn intelligence into detection rules, hunting queries and actionable use cases
Integrate intelligence into security tooling such as CrowdStrike, SIEM and TIP platforms
Lead and execute end-to-end incident response including triage, containment, eradication and recovery
Investigate across endpoints, logs, network traffic and cloud environments
Use EDR tools such as CrowdStrike for live response, forensic analysis and threat hunting
Analyse malware behaviour, attacker persistence mechanisms and lateral movement techniques
Produce detailed technical reports with root cause and remediation actions
Develop and execute proactive threat hunting across endpoint, identity and cloud telemetry
Write and tune detection rules for SIEM, EDR, Sigma, KQL and Splunk
Validate detections through simulation and adversary emulation
Improve detection coverage based on intelligence and incident learnings
Investigate and respond to threats in AWS, Azure and GCP environments
Analyse cloud logs such as CloudTrail, Azure AD and GCP logs for suspicious activity
Identify misconfigurations, privilege escalation paths and identity-based attacks
Work with engineers to remediate security gaps
Investigate phishing campaigns, malicious domains and impersonation attempts
Perform technical analysis of phishing kits, payloads and infrastructure
Support takedown operations with actionable evidence
Correlate CVEs with real-world exploitation and internal exposure
Validate vulnerabilities and assess exploitability
Track and respond to zero-days and active exploitation campaigns
Work with system owners to ensure remediation
Identify detection and response gaps through incidents and hunting activities
Implement improvements across EDR, SIEM and cloud security controls
Build automation scripts and workflows to improve response efficiency
Contribute to playbooks, runbooks and technical standards Requirements 5–8+ years of hands-on experience in Incident Response, Threat Hunting or Threat Intelligence Strong experience with EDR platforms such as CrowdStrike (querying, investigation, live response) Proven ability to independently investigate and respond to real-world cyber incidents Experience writing detection logic (KQL, SPL, Sigma, etc.) Solid understanding of attacker techniques (lateral movement, persistence, C2, credential abuse) Hands-on experience in cloud security investigations (AWS, Azure or GCP) Apply on the company website
You will leave WorkJio. Never pay a fee or share your Singpass password, OTP or bank log-ins to apply.
Open application Listing ID 7413 · Report this listing
More jobs like this Want tech & engineering jobs like this sent to you?
Jio sends new ones each evening on Telegram. Free, stop any time.
Get them from Jio