About the role
We are hiring on behalf of a leading international financial institution operating across Asia Pacific. This is a key role within the regional Production Security team, embedded in a 24/7 SOC environment. You will strengthen detection capabilities across APAC and contribute to global security use case development and incident response operations.
What you'll do
- Lead the design, implementation, and enrichment of security use cases based on real-world attack scenarios and the MITRE ATT&CK framework
- Monitor ongoing threat intelligence and translate findings into actionable detection logic
- Respond to and investigate cyber/IT security incidents assess type and severity of events
- Oversee detection capabilities for the 24/7 regional IT Production SOC
- Drive continuous improvement of SIEM, SOAR, and operational playbooks
- Collaborate with regional and global stakeholders on security monitoring and alert handling
- Identify recurring security risks and develop mitigation and process improvement plans
- Conduct threat hunting and R&D activities to strengthen the security posture
Must-have requirements
- 7+ years of experience in cybersecurity incident response
- 4+ years specifically in security use case design, development, and coding
- Hands-on experience with SIEM platforms and security incident management
- Strong knowledge of MITRE ATT&CK framework
- Good working knowledge of Linux (RedHat/Ubuntu)
- Experience interpreting security logs and building threat models
- Strong English communication skills
Nice to have
- Experience with ELK/Elastic SIEM stack
- Scripting skills: Python, PowerShell, Bash, SQL
- Java programming knowledge
- Security certifications: CISSP, OSCP, SANS/GIAC
- Experience with SOAR platforms
- French language skills
- Prior experience in financial services or regulated industries
Seniority Level
Mid-Senior level
Industry
- Information Technology & Services
- Banking
Employment Type
Full-time
Job Functions
Skills
- Incident Response
- Cyber-security
- Security Information and Event Management (SIEM)
- Cybersecurity Incident Response
- Linux