HK Senior Detection and Response Engineer
Core
Lead technical activities in security usecase definition, design, implementation, and enrichment for IT Production Security Investigation & Incident Response based on real-world attack scenarios and MITRE ATT&CK frameworks.
Role type
Senior IC detection and response engineer (security operations)
Builds
Robust security detection posture across various layers for a leading investment bank
Domain
Cybersecurity / Financial Services
Deliverable
production ML models | product features | dashboards & analysis | client delivery
Required skills
Security usecase design and development, Threat hunting, Incident investigation and remediation, SIEM product expertise, Large data set analysis and automation, Process improvement and playbook development
Preferred skills
Java programming, Linux administration (RedHat/Ubuntu), ELK stack (Elastic Logstash Kibana), Professional security certifications (SANS/CISSP/OSCP)
Technologies
MITRE ATT&CK, SIEM, ELK stack, Python, PowerShell, Bash, SQL, Linux
Responsibilities
Define, design, and implement security usecases; oversee detection capabilities of the 24/7 regional IT Production SOC; respond to cyber/IT security incidents and evaluate severity; identify recurring security issues and develop mitigation plans; partner with stakeholders to ensure procedural efficiency; continuously improve SOC frameworks via policy and playbook reviews; contribute to APAC Business CSIRT operations and local incident response; support regulatory compliance and audit interviews
Seniority
Senior, hands-on IC