Proven experience in incident response and security operations, including triaging security alerts, conducting investigations, and leading response efforts
Strong background in detection engineering, including developing, tuning, and maintaining security detection rules and alerts
Hands-on experience with SIEM Infrastructure, specifically with Google SecOps (Chronicle). This includes data onboarding, parsing, rule creation, and dashboarding
Proficiency in security monitoring across various platforms, including JAMF MDM for macOS endpoints, Google Workspace, Okta and general SaaS applications
Experience with cloud security monitoring, particularly in Google Cloud (GCP) with familiarity in GCP Security Command Center (SCC)
Solid scripting skills (e.g., Python, Bash) for automating detection and response tasks, data parsing, and security tooling integration
Deep understanding of common attack techniques, threat intelligence, and the ability to translate them into actionable detections
Familiarity with security frameworks and best practices (e.g., MITRE ATT&CK, NIST Cybersecurity Framework)
Excellent analytical and problem-solving skills, with a keen eye for detail and the ability to connect disparate pieces of information during investigations
LOCATION
This role is remote, so it can be executed from anywhere in the APAC region with the ability to operate in [GMT+10] timezones. We’re particularly looking for candidates based in Singapore, Australia or the Philippines