Cybersecurity Detection Engineer - Security Exposure & Third-Party Risk
Employment Details
- Employment Type: Contract
- Contract Duration: 12 months, renewable
- Work Location: Singapore
We are looking for a Cybersecurity Detection Engineer to support Security Exposure Management and Third-Party Cyber Assurance initiatives. The role will focus on identifying external cyber exposures, assessing third-party security risks, validating emerging threats, and working with stakeholders to drive remediation.
Key Responsibilities
- Perform Security Exposure Management and External Attack Surface Management (EASM) activities across internet-facing assets and services.
- Identify, assess and prioritise vulnerabilities, misconfigurations and external cyber exposures.
- Conduct cybersecurity assessments of third-party vendors and service providers.
- Perform vendor security due diligence, security questionnaire and evidence reviews, risk assessments and remediation tracking.
- Support continuous cyber assurance and monitoring of critical third parties and supply-chain dependencies.
- Assess third-party, fourth-party and nth-party cybersecurity risks.
- Monitor cyber threats, vulnerabilities and threat intelligence to identify potential exposure to the organisation and its third parties.
- Validate high-risk or actively exploited vulnerabilities and support risk-based remediation.
- Develop security dashboards, cyber posture metrics, reports and management updates.
- Use Python, PowerShell or Bash to automate security monitoring, assessment, reporting or data-processing activities.
- Collaborate with security, technology, risk, infrastructure and business stakeholders to manage identified cyber risks.
- Support refinement of security controls, detection logic and cyber-risk baselines.
Requirements
- Degree in Computer Science, Information Technology, Cybersecurity or a related discipline.
- 3-5 years of relevant hands-on cybersecurity experience.
- Experience in one or more areas such as Security Exposure Management, EASM, cyber risk, third-party cyber risk, vulnerability management, threat intelligence or security operations.
- Practical experience conducting third-party/vendor cybersecurity assessments, security due diligence or security questionnaires.
- Knowledge of cybersecurity frameworks such as NIST, ISO 27001 and CIS Controls.
- Good understanding of TCP/IP, DNS, HTTP/HTTPS, internet-facing infrastructure and common security vulnerabilities.
- Exposure to AWS, Azure and/or GCP security environments.
- Experience with vulnerability, attack-surface, threat-intelligence, digital-risk or security monitoring tools.
- Scripting or automation experience using Python, PowerShell and/or Bash.
- Strong analytical, documentation, communication and stakeholder-management skills.
Good to Have
- Experience with SIG, CAIQ or similar third-party security assessment frameworks.
- Experience with EASM, Digital Risk Protection, cyber exposure or threat-intelligence platforms.
- Experience developing cybersecurity dashboards or cyber posture scorecards.
- Security certifications such as Security+, CEH, CySA+, GSEC, GCIH, CISSP or CISM.
- Experience within financial services or other highly regulated environments.
Interested candidates are kindly requested to email their CV with their experience to [Confidential Information]
We look forward to your application!