Cyber Threat Intelligence & Incident Response Specialist
About this job
We are seeking an experienced and highly technical Cyber Threat Intelligence & Incident Response Specialist to strengthen our organisation’s threat detection, incident response, and cyber defence capabilities. This is a hands-on individual contributor role suited for a cybersecurity professional who is comfortable independently leading complex investigations from initial detection through containment, eradication, recovery, and post-incident improvement. The successful candidate will spend a significant portion of their time conducting real-world investigations, proactive threat hunting, developing and tuning detections, analysing threat intelligence, and improving security controls across enterprise, endpoint, identity, network, and cloud environments.
Key Responsibilities:
Threat Intelligence
- Collect, analyse, and operationalise cyber threat intelligence from OSINT, commercial threat feeds, ISACs, dark-web sources, and other relevant intelligence channels.
- Conduct adversary tracking, campaign analysis, infrastructure analysis, and mapping of attacker tactics, techniques, and procedures (TTPs) using frameworks such as MITRE ATT&CK.
- Translate threat intelligence into actionable detection rules, threat-hunting queries, indicators, and security use cases.
- Integrate threat intelligence into security platforms including SIEM, EDR, Threat Intelligence Platforms (TIPs), and CrowdStrike.
- Monitor emerging threats, zero-day vulnerabilities, active exploitation campaigns, and changes in adversary behaviour.
Incident Response
- Lead and execute end-to-end cybersecurity incident response activities including triage, investigation, containment, eradication, recovery, and post-incident analysis.
- Perform investigations across endpoint telemetry, security logs, network traffic, identity systems, and cloud environments.
- Use EDR platforms such as CrowdStrike for investigation, live response, forensic analysis, and threat hunting.
- Investigate malware activity, credential compromise, attacker persistence, command-and-control activity, privilege escalation, and lateral movement.
- Determine root cause, attack paths, affected systems, and overall business impact.
- Produce detailed incident reports with clear technical findings, root-cause analysis, remediation actions, and recommendations.
Threat Hunting & Detection Engineering
- Develop and execute structured threat-hunting activities across endpoint, identity, network, and cloud telemetry.
- Develop, test, tune, and maintain security detections using technologies and languages such as KQL, SPL, Sigma, SIEM and EDR query languages.
- Map detection coverage against adversary techniques using MITRE ATT&CK.
- Validate detection effectiveness through security testing, attack simulation, and adversary-emulation exercises.
- Identify detection gaps from incidents and threat-intelligence findings and implement improvements.
- Drive improvements in security metrics including Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR).
Cloud Security
- Investigate and respond to security threats affecting AWS, Microsoft Azure, and/or Google Cloud Platform (GCP) environments.
- Analyse cloud security telemetry including AWS CloudTrail, Microsoft Entra ID/Azure logs, and GCP audit logs.
- Identify suspicious authentication activity, privilege escalation, compromised credentials, identity-based attacks, and cloud misconfigurations.
- Work closely with infrastructure, cloud, and engineering teams to remediate identified security weaknesses.
Brand Protection & Digital Threats
- Investigate phishing campaigns, impersonation attempts, fraudulent websites, malicious domains, and other digital threats.
- Conduct technical analysis of phishing infrastructure, phishing kits, malicious payloads, URLs, and associated attacker infrastructure.
- Gather and document actionable evidence to support domain, website, or infrastructure takedown activities.
Vulnerability & Exposure Management
- Assess vulnerabilities in the context of real-world exploitation, threat intelligence, and organisational exposure.
- Correlate CVEs with active exploitation campaigns and internal technology assets.
- Validate vulnerabilities and assess exploitability where appropriate.
- Monitor and respond to zero-day vulnerabilities and emerging exploitation activity.
- Work with system owners and technical teams to prioritise and ensure timely remediation.
Security Control Improvement
- Identify security-control and detection gaps through incident investigations, threat hunting, and threat-intelligence analysis.
- Implement improvements across EDR, SIEM, cloud security, identity, and other security platforms.
- Develop automation scripts and workflows to improve investigation and incident-response efficiency.
- Contribute to the development and continuous improvement of incident-response playbooks, threat-hunting procedures, runbooks, and technical security standards.
- Support security improvements aligned with organisational and applicable regulatory requirements, including CSA and PDPC requirements where relevant.
Requirements
- 5–8+ years of relevant hands-on cybersecurity experience, particularly in Incident Response, Threat Hunting, Threat Intelligence, SOC operations, or Detection Engineering.
- Strong hands-on experience with EDR platforms such as CrowdStrike, including querying, investigation, threat hunting, and live-response capabilities.
- Demonstrated experience independently investigating and responding to complex real-world cybersecurity incidents.
- Experience developing and tuning detection logic using KQL, SPL, Sigma, or equivalent technologies.
- Strong understanding of attacker tactics and techniques including:
- Credential theft and abuse
- Persistence
- Privilege escalation
- Lateral movement
- Command and Control (C2)
- Defence evasion
- Data exfiltration
- Good knowledge of the MITRE ATT&CK framework and its application to threat intelligence, detection engineering, and threat hunting.
- Hands-on experience investigating security incidents within at least one major cloud platform such as AWS, Azure, or GCP.
- Strong understanding of endpoint, network, identity, authentication, and cloud-security concepts.
- Scripting or automation experience using Python, PowerShell, Bash, or equivalent technologies.
- Strong analytical and problem-solving skills with the ability to independently manage investigations from identification through resolution.
- Ability to clearly communicate complex technical findings to both technical and non-technical stakeholders.
Preferred Qualifications
- Hands-on experience with malware analysis, digital forensics, or forensic investigation tools.
- Experience with Threat Intelligence Platforms (TIPs), SOAR platforms, SIEM solutions, and security automation.
- Experience performing adversary emulation or attack simulation.
- Relevant professional certifications such as GCIH, GCFA, GNFA, GCTI, CISSP, or equivalent certifications.
- Previous experience working in regulated, financial services, critical infrastructure, government, or other high-risk environments.
Role Success Measures
- Success in this role will be demonstrated through measurable improvements in:
- Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR).
- Detection coverage across relevant MITRE ATT&CK techniques.
- Identification of previously undetected threats through proactive threat hunting.
- Effectiveness and accuracy of security detections.
- Reduction of recurring incidents through root-cause remediation.
- Continuous improvement of the organisation’s overall threat detection and incident-response capability.
To apply,simply click the "Apply" button or send your updated profile to [email protected]
EA Licence No.:18S9405 / EA Reg. No.:R1330864
Percept Solutions is expanding and actively seeking talented individuals. We encourage applicants to follow Percept Solutions on LinkedIn at https://www.linkedin.com/company/percept-solutions/to stay informed about new opportunities and events.
Market insight
11% above medianExplore related jobs
Similar jobs
See all similar jobsSenior Data Project Manager
Junior Data Project Manager
Junior PMO Analyst
Banking Business Analyst
Linux Platform Engineer
Cloud Engineer (AWS / DevOps / Linux / Kubernetes)
Frequently asked questions
What salary can I expect?
The employer lists 6 000 – 7 500 $ for this role at PERCEPT SOLUTIONS PTE. LTD. in Singapore. For comparison, the local market median is about 6 085 $ based on 26 065 similar offers.
How do I apply for this job?
Open the original source page and contact the employer there. Finder never charges job seekers.
Are these jobs up to date?
Yes. Finder regularly refreshes vacancies from public sources and removes closed offers.
Where can I see employment type and work format?
Key conditions are shown above the description. You can also open related listings for PERCEPT SOLUTIONS PTE. LTD. and Singapore.
