Role Responsibilities:
Security Automation & Engineering
- Develop automation scripts and workflows for security operations (Python / API / SOAR / SIEM integration).
- Automate log ingestion, parsing, enrichment, and alert generation.
- Build internal tools to reduce manual investigation effort.
- Integrate security tools across WAF, SIEM, EDR, NDR, application logs, and fraud systems.
- Support development of detection pipelines and response playbooks.
Cyber Security & Fraud Investigation Support
- Perform log analysis across WAF, application, cloud, endpoint, and network sources during incidents.
- Produce investigation reports, incident timelines, and root-cause findings.
- Support investigation of cybersecurity and fraud incidents, including:
- Insider threats
- External attacks
- Account abuse and suspicious activities
- Payment / wallet fraud
- Produce investigation reports and incident timelines
- Work closely with teams to close control gaps
Detection Engineering & Vulnerability Management
- Design and implement detection rules and correlation logic across application, WAF, cloud, endpoint, network, and fraud-related data sources.
- Improve alert quality to surface meaningful security signals.
- Build dashboards and investigation views to support security monitoring and incident analysis.
- Conduct vulnerability assessments across applications, systems, and cloud environments.
- Track, follow up, and drive remediation of identified vulnerabilities with relevant system owners.
- Track vulnerability status across infrastructure, systems, and applications, and provide reporting on remediation progress.
Role Requirements:
- Degree in Information Systems, Computer Science, Computer Engineering or equivalent qualification. OSCP certification a plus.
- Minimum 5-7 years of experience in Cyber Security, focusing in application security.
- Strong scripting and automation skills, Python preferred.
- Experience with SIEM (e.g., SLS, MaxCompute, Function Compute, API Gateway, CloudMonitor, etc.).
- Experience working with logs from WAF, applications, cloud, endpoints, or network devices.
- Understanding of fraud patterns in digital payment / wallet / app environments.
- Experience supporting incident investigation and root-cause analysis.
- Familiarity with APIs and system integrations.
- Knowledge of DLP, endpoint security, and monitoring concepts.