← Sottava, jobs the hour they open
1 mo agofound 5 d ago
Cybersecurity Engineer (Detection Engineering)
What the posting is about
Develop and implement security detection rules using Sigma, KQL, SPL, EQL, or YARA. Analyze security logs and alerts to differentiate true threats. Collaborate with security analysts and engineers to improve detection capabilities and integrate systems.
Read out of the posting
Levelmid
Experience asked3+ years
EmploymentContract
LocationSingapore
RemoteNot stated
Visa sponsorshipNot stated
SalaryNot published, and most postings do not
Posted2026-09-02
Found viaworkable, direct from their system
We saw it 28 days after it went up.
The posting, as the company wrote it
Employment: Contract
Experience: Mid-Senior level
Assurity Trusted Solutions (ATS) is a wholly owned subsidiary of the Government Technology Agency (GovTech). As a Trusted Partner over the last decade, ATS offers a comprehensive suite of products and services ranging from infrastructure and operational services, authentication services, governance and assurance services as well as managed processes. In a dynamic digital and cyber landscape, where trust & collaboration are key, ATS continues to drive mutually beneficial business outcomes through collaboration with GovTech, government agencies and commercial partners to mitigate cyber risks and bolster security postures.
We are looking for a Cybersecurity Engineer with a background in detection engineering to join us!
Responsibilities:
Develop, implement, and document effective security detection rules — using languages/frameworks such as Sigma, KQL, SPL, EQL, or YARA as applicable to the deployed SIEM platforms — and playbooks to identify potential threats and malicious activity targeting government systems in on-premises and cloud environments.
Conduct comprehensive and in-depth analysis of security logs and alerts from security monitoring (e.g. SIEM) and detection systems (e.g. EDR) deployed within the government environment, to differentiate true treats from benign activity and reduce false positives across network, endpoint, and cloud security domains
Continuously improve detection capabilities through in-depth research on threats targeting government networks, endpoints, and cloud environments, to write and tune detection rules (e.g. Sigma rules, KQL/SPL queries, YARA signatures) for enhanced threat detection while reducing benign alerts, leveraging automation for enhanced efficiency.
Collaborate with security analysts and incident responders on government specific incident response protocols and investigation activities, with a focus on operationalising detection rules for accurate alert escalation.
Collaborate with security engineers to drive integration of detection systems used within the government environment, by providing detection requirements and defining problem areas to streamline workflows and optimise tool usage.
Maintain a comprehensive understanding of the evolving threat landscape, including the latest tactics, techniques, and procedures (TTPs) used to target government networks, as well as the latest security trends and best practices in detection developme
Requirements
Degree in Cybersecurity, Information Security, Computer Science or a related field.
Relevant cybersecurity certifications from OffSec, SANS, GIAC or related institution in cloud security, detection engineering, incident response, malware analysis, or security penetration testing domain. A minimum of 3 years’ experience in security operations, incident response or related cybersecurity fields, demonstrating a proven track record in threat detection and analysis, preferably within an enterprise or government environment.
Understand security concepts and cybersecurity frameworks such as MITRE ATT&ACK, including commonly used attacker TTPs and their detection.
Demonstrate strong technical foundation, preferably with hands-on experience in security technologies (e.g. SIEM, EDR, SOAR), scripting languages (e.g. Python, PowerShell) and automation tools to facilitate the development and tuning of detection rules. Working knowledge of one or more detection rule languages such as Sigma, YARA-L, Splunk SPL, Microsoft KQL, or Elastic EQL, with the ability to translate threat intelligence and attacker TTPs into structured, testable detection logic.
Experience with version control process and tools and detections as code workflow (e.g. peer review, testing of detection logic against sample log data)
Excellent analytical and problem-solving skills, ability to prioritise tasks, as well as willing to learn new technology and approaches.
Strong communication and collaboration skills to work effectively on intra team and inter-team tasks.
Join us and discover a meaningful and exciting career with Assurity Trusted Solutions!
The remuneration package will commensurate with your qualifications and experience. Interested applicants, please click "Apply Now".
We thank you for your interest and please note that only shortlisted candidates will be notified.
By submitting your application, you agree that your personal data may be collected, used and disclosed by Assurity Trusted Solutions Pte. Ltd. (ATS), GovTech and their service providers and agents in accordance with ATS’s privacy statement which can be found at: or such other successor site.
Benefits
A wholly-owned subsidiary of GovTech.
We promote a learning culture and encourage you to grow and learn.
Also open at Assurity Trusted Solutions
Workplace Network Engineer5 d agoData Engineer (Familiar with LLM, ML or GenAI apps)7 d agoTriage Specialist, Vulnerability Discovery Programme14 d agoThreat Risk Cybersecurity Trainer17 d agoCybersecurity Engineer (IT Security Operations) - Multiple Headcounts17 d agoCloud Infrastructure Engineer (Familiar with Sharepoint Development)18 d ago
Why this page exists
We read companies’ own hiring systems every hour, 1,123 of them, and show a job the hour it opens instead of when a job board gets around to indexing it. We saw it 28 days after it went up.
The feed is free. No card, no trial to expire.