Job is active

Detection Engineer – EASM / ASM / Cyber Threat Intelligence (CTI)

5 500 – 10 600 $
Full time1–3 yearsOn-siteSingapore

Location

RAFFLES PLACE, REPUBLIC PLAZA

Open in maps

About this job

Detection Engineer – Security Exposure & Third-Party Cyber Assurance

Role Overview

We are looking for a Detection Engineer to support the build-out and operations of the Security Exposure and Third-Party Cyber Assurance Centre of Excellence, under Cybersecurity Assurance and Defense (CASD) – External Threat Operations.

The role will provide hands-on technical and operational support across two key areas:

  • Security Exposure Management (SEM): Continuous, outside-in monitoring of the organisation and its portfolio companies’ internet-facing attack surface.
  • Third-Party Cyber Assurance (TPCA): Cybersecurity due diligence and continuous assurance across third parties and the broader supply chain.

The successful candidate will operate continuous monitoring platforms, conduct third-party cyber assessments, validate active and emerging threats, and coordinate remediation to reduce the time between exposure identification and potential exploitation.

Key Responsibilities

  • Operate and maintain always-on security exposure and external threat monitoring platforms.
  • Monitor the organisation, portfolio companies, and third parties for internet-facing vulnerabilities, exposures, and emerging cyber threats.
  • Perform Attack Surface Management (ASM/EASM) activities to identify, assess, validate, and prioritise external security exposures.
  • Conduct third-party/vendor cybersecurity assessments, including security questionnaires and due diligence activities such as VDD, ODD, and SIG.
  • Assess third-party security controls against established frameworks including NIST, ISO 27001, and CIS Controls.
  • Leverage Cyber Threat Intelligence (CTI), digital risk, and dark-web monitoring to identify and validate relevant threats.
  • Investigate and validate high-risk or imminent security threats and coordinate appropriate remediation with relevant stakeholders.
  • Analyse third- and fourth-party cyber risks and their potential impact across the organisation and supply chain.
  • Develop scripts and automation using Python, PowerShell, or Bash to streamline monitoring, analysis, reporting, and operational activities.
  • Build and maintain operational dashboards, reporting capabilities, and cyber posture metrics using data lake platforms.
  • Document findings, processes, assessments, and remediation actions clearly for both technical and business stakeholders.
  • Support continuous improvement of detection logic, control baselines, monitoring processes, and exposure management capabilities.

Requirements

  • Degree in Computer Science, Information Technology, or a related discipline.
  • 3–5 years of hands-on cybersecurity experience, preferably within cybersecurity operations, attack surface/exposure management, third-party cyber risk assessment, or data lake environments.
  • Practical experience conducting third-party/vendor security assessments and questionnaires, including VDD, ODD, and SIG.
  • Good knowledge of cybersecurity frameworks such as NIST, ISO 27001, and CIS Controls.
  • Hands-on experience with ASM/EASM, cyber exposure management, digital risk monitoring, dark-web monitoring, and/or Cyber Threat Intelligence (CTI) platforms.
  • Strong scripting capabilities using Python, PowerShell, or Bash, particularly for automation and reporting.
  • Strong understanding of TCP/IP, DNS, HTTP/S, and common security exposures across AWS, Azure, and GCP.
  • Understanding of third- and fourth-party cyber risk and how security exposure can propagate through the supply chain.
  • Strong analytical and documentation skills, with the ability to handle sensitive security findings appropriately.
  • Good communication and stakeholder management skills across technical and business teams.
  • Collaborative, adaptable, and comfortable working in a fast-evolving cybersecurity environment.

Good to Have

  • Certifications such as Security+, CEH, GIAC (GSEC/GCIH), CompTIA CySA+, or equivalent.
  • CISSP Associate or CISM candidature.
  • Experience developing cyber posture scorecards and operational security dashboards.
  • Familiarity with detection engineering, including tuning detection logic and refining security control baselines as capabilities mature.

SEM | TPCA | ASM/EASM | CTI | Third-Party Cyber Risk | VDD/ODD | SIG | NIST | ISO 27001 | CIS Controls | Digital Risk & Dark-Web Monitoring | Python | PowerShell | Bash | TCP/IP | DNS | HTTP/S | AWS | Azure | GCP | Data Lakes | Detection Engineering

Market insight

68% above median
4 800 $

Based on 75 102 offers with salary for this country

Full salary breakdown

Similar jobs

ASTEK SINGAPORE INNOVATION TECHNOLOGY PTE. LTD. Singapore ·

Cybersecurity Detection Engineer

8 500 – 11 000 $
Full time1–3 yearsOn-siteSingapore
ASTEK SINGAPORE INNOVATION TECHNOLOGY PTE. LTD. Singapore ·

Business Analyst - Gov Portal

5 000 – 11 000 $
Full time3–6 yearsOn-siteSingapore
ASTEK SINGAPORE INNOVATION TECHNOLOGY PTE. LTD. Singapore ·

Senior Out Systems Developer

7 800 – 9 000 $
Full time3–6 yearsOn-siteSingapore

Frequently asked questions

What salary can I expect?

The employer lists 5 500 – 10 600 $ for this role at ASTEK SINGAPORE INNOVATION TECHNOLOGY PTE. LTD. in Singapore. For comparison, the local market median is about 4 800 $ based on 75 102 similar offers.

How do I apply for this job?

Open the original source page and contact the employer there. Finder never charges job seekers.

Are these jobs up to date?

Yes. Finder regularly refreshes vacancies from public sources and removes closed offers.

Where can I see employment type and work format?

Key conditions are shown above the description. You can also open related listings for ASTEK SINGAPORE INNOVATION TECHNOLOGY PTE. LTD. and Singapore.

Apply