Overview
We are seeking a highly technical, hands-on cybersecurityprofessional to drive Threat Intelligence, Incident Response, and advancedthreat detection. This role is suited for an experienced individual contributorwho actively performs investigations, threat hunting, and security engineering,while contributing to continuous improvement of security controls.
This role is suited for a senior individual contributor whois comfortable operating independently and leading complex investigationsend-to-end.
Role Focus & Success Outcomes
● This is a hands-on, incident response anddetection-focused role, where the majority of time will be spent on real-worldinvestigations, threat hunting, and improving detection capabilities acrossenterprise and cloud environments.
● Act as a key technical contributor to strengthening theorganisation’s end-to-end detection and response capability, from threatidentification to containment and recovery.
● Drive measurable improvements in: ○ Mean Time to Detect(MTTD) and Mean Time to Respond (MTTR)
○ Detection coverage across key adversary techniques (e.g.mapped to MITRE ATT&CK)
○ Proactive threat discovery through structured huntingactivities
● Contribute to building a resilient security posturealigned with organisational and regulatory expectations (e.g. CSA, PDPC whereapplicable)
Key Responsibilities
Threat Intelligence
• Actively collect, analyse, and operationalise intelligencefrom OSINT, dark web, commercial feeds, and ISACs
• Perform hands-on adversary tracking, campaign analysis,and TTP mapping (MITRE ATT&CK)
• Translate intelligence into detection rules, huntingqueries, and actionable use cases
• Integrate intelligence into security tooling, includingCrowdStrike, SIEM, and TIP platforms
Incident Response
• Lead and execute end-to-end incident response activities(triage, containment, eradication, recovery)
• Perform hands-on investigations across endpoints, logs,network traffic, and cloud environments
• Use EDR tools (e.g., CrowdStrike) for live response,forensic analysis, and threat hunting
• Analyse malware behaviour, attacker persistencemechanisms, and lateral movement techniques
• Produce detailed technical reports with clear root causeand remediation actions
Threat Hunting & Detection Engineering
• Develop and execute proactive threat hunting acrossendpoint, identity, and cloud telemetry
• Write and tune detection rules (SIEM, EDR, Sigma, KQL,Splunk, etc.)
• Validate detections through simulation and adversaryemulation
• Continuously improve detection coverage based onintelligence and incident learnings
Cloud Security (Hands-On)
• Investigate and respond to threats in AWS, Azure, and GCPenvironments
• Analyse cloud logs (CloudTrail, Azure AD, GCP logs) forsuspicious activity
• Identify misconfigurations, privilege escalation paths,and identity-based attacks
• Work directly with engineers to remediate security gaps
Brand Protection & Digital Threats
• Investigate phishing campaigns, malicious domains, andimpersonation attempts
• Perform technical analysis of phishing kits, payloads, andinfrastructure
• Support takedown operations with actionable evidence
Vulnerability & Exposure Management
• Correlate CVEs with real-world exploitation and internalexposure
• Validate vulnerabilities (where applicable) and assessexploitability
• Track and respond to zero-days and active exploitationcampaigns
• Work closely with system owners to ensure remediation
Security Control Improvement
• Identify detection and response gaps through realincidents and hunting activities
• Implement improvements across EDR, SIEM, and cloudsecurity controls
• Build automation scripts and workflows to improve responseefficiency
• Contribute directly to playbooks, runbooks, and technicalstandards
Requirements
• Hands-on experience in Incident Response, Threat Hunting,or Threat Intelligence
• experience with EDR platforms such as CrowdStrike(querying, investigation, live response)
• Proven ability to independently investigate and respond toreal-world cyber incidents
• Experience writing detection logic (KQL, SPL, Sigma, etc.)
• Solid understanding of attacker techniques (lateralmovement, persistence, C2, credential abuse)
• Hands-on experience in cloud security investigations (AWS,Azure, or GCP)
• Scripting skills (Python, PowerShell, or Bash)
---------------------------
Please refer to U3’s Privacy Notice for JobApplicants/Seekers at https://u3infotech.com/privacy-notice-job-applicants/. When youapply, you voluntarily consent to the collection, use and disclosure of yourpersonal data for recruitment/employment and related purposes.
U3 INFOTECH PTE. LTD.
U3 INFOTECH PTE. LTD. U3 INFOTECH (U3) offers a complete range of Software Services, Business Solutions and Project Management Outsourcing and Project Management Training. We have an excellent domain expertise in business verticals such as Banking and Financial Services, Insurance, Semiconductors...
Read more about the companyCopyright © 2026 Grabjobs Pte.Ltd. All Rights Reserved.