Cybersecurity Operations Specialist
About the Role
We are seeking a hands-on Cybersecurity Operations Specialist to strengthen our security operations capability by proactively monitoring, detecting, investigating and responding to cybersecurity threats across the enterprise.
This role is ideal for a cybersecurity professional with strong operational experience in security monitoring, incident response, vulnerability management and endpoint security technologies. You will work closely with internal IT teams and security vendors to ensure the organisation maintains a robust security posture while continuously improving security operations.
Key Responsibilities
Security Operations & Incident Response
- Monitor enterprise security platforms and investigate security alerts, suspicious activities and potential threats.
- Perform daily security event triage, analysis and escalation of incidents based on severity.
- Support incident response activities including investigation, containment, eradication and recovery.
- Analyse logs and security telemetry from multiple security solutions to identify malicious activities and recommend remediation.
- Coordinate with internal IT teams and managed security service providers (MSSPs) to resolve security incidents promptly.
- Produce operational security metrics, threat reports and incident summaries.
Vulnerability & Threat Management
- Perform continuous vulnerability monitoring across servers, endpoints and infrastructure.
- Prioritise vulnerabilities based on business risk and coordinate remediation activities with infrastructure and application teams.
- Validate remediation efforts and track outstanding vulnerabilities until closure.
- Assist in conducting vulnerability assessments and penetration testing remediation activities.
Endpoint & Identity Security
- Administer and support endpoint security platforms such as Endpoint Detection & Response (EDR) solutions.
- Monitor endpoint health, investigate endpoint detections and fine-tune security policies where required.
- Support identity security through Microsoft Entra ID and related identity protection capabilities.
- Perform security reviews on privileged accounts and endpoint security configurations.
Security Platforms Administration
- Support daily operations of enterprise security technologies including:Endpoint Detection & Response (CrowdStrike or equivalent)Microsoft Entra IDSecure Email GatewaySecure Web GatewayData Loss Prevention (DLP)Firewall and network security technologies
- Troubleshoot security platform issues and optimise security policies to improve detection accuracy and reduce false positives.
- Assist with deployment, configuration and maintenance of cybersecurity solutions.
Phishing Defence & Security Awareness
- Execute phishing simulation campaigns and analyse campaign effectiveness.
- Investigate phishing reports submitted by users and coordinate appropriate response actions.
- Conduct cybersecurity awareness initiatives to strengthen organisational security culture.
- Prepare operational reports on phishing trends and emerging attack techniques.
Cybersecurity Projects & Continuous Improvement
- Support implementation and enhancement of cybersecurity technologies and operational processes.
- Participate in security tool deployments, upgrades and operational improvement initiatives.
- Coordinate testing, validation and rollout of new security capabilities.
- Maintain accurate operational documentation, playbooks and technical procedures.
Requirements
Required Qualifications
- Bachelor's Degree in Information Security, Computer Science, Information Technology or a related discipline.
- 3–5 years of hands-on experience in Cybersecurity Operations, Security Engineering, SOC or Incident Response.
- Experience investigating and responding to security alerts and incidents.
- Strong understanding of endpoint protection, identity security and vulnerability management.
- Experience working with SIEM, EDR and enterprise security monitoring platforms.
- Familiarity with Windows Server, Active Directory, Microsoft 365 and networking fundamentals.
- Ability to analyse security logs, identify threats and recommend remediation actions.
- Strong troubleshooting and analytical skills with a proactive approach to problem solving.
Preferred Skills
Experience with one or more of the following technologies:
- CrowdStrike Falcon
- Microsoft Defender Suite
- Microsoft Entra ID
- ManageEngine
- SIEM platforms (Microsoft Sentinel, Splunk, QRadar or equivalent)
- Secure Email Gateway solutions
- Secure Web Gateway
- Data Loss Prevention (DLP)
- Firewalls (Fortinet, Palo Alto, Check Point or equivalent)
- Vulnerability management tools such as Tenable, Qualys or Rapid7
Professional certifications such as Security+, CEH, CySA+, GIAC or CISSP will be advantageous.
Those who are keen for the role and would like to discuss the opportunity further, please click "Apply Now" or email Kin Long at [email protected] with your updated CV.
Only shortlisted candidates will be responded to, therefore if you do not receive a response within 14 days, please accept this as notification that you have not been shortlisted.
Quess Selection & Services Pte Ltd
EA Licence No: 23C2060 | EAP Registration No: R2095054
This is in partnership with the Employment and Employability Institute Pte Ltd (“e2i”).
e2i is the empowering network for workers and employers seeking employment and employability solutions. e2i serves as a bridge between workers and employers, connecting with workers to offer job security through job-matching, career guidance and skills upgrading services, and partnering employers to address their manpower needs through recruitment, training, and job redesign solutions. e2i is a tripartite initiative of the National Trades Union Congress set up to support nation-wide manpower and skills upgrading initiatives. By applying for this role, you consent to Quesscorp Singapore’s PDPA and e2i’s PDPA