The Correlation & Automation Lead is responsible for implementing and maintaining security monitoring use cases, creating and optimizing SIEM data sources and correlation rules, along with analyzing security events to enhance detection methods. This role involves collaborating with the security team and continuously improving operational practices.
Ensign is hiring !
Key Responsibilities
- Perform implementation, maintenance, support and operation of the project's security monitoring use cases
- Maintain understanding of the architecture and work with security team to understand the use cases to be created.
- Identity, evaluate and recommend new areas of improvements for the implementation.
- Adhere to established change management process and other service management process in day-to-day tasks
- Create, finetune and maintain SIEM data sources, use cases, correlation rules and security alerts classifications
- Review, propose and generate dashboards and reports to automate monitoring of systems and log and threat intelligence feed ingestion, and reduce low value event escalations
- Build rules and intelligence to detect threats in all monitored assets
- Implement and devise detection method of such threats in our security operations through SIEM use cases etc
- Perform periodic analysis of security events, network traffic, and logs to engineer new detection methods, or create efficiencies when available
- Review and update data enrichment, including use of threat intelligence to enhance fidelity of detection
- Review and maintain UEBA data sources and use cases
Requirements
- At least 3 years of experience in security operations in a SOC environment
- At least 2 years of experience in creating, finetuning and maintaining correlation rules and SIEM dashboards
- Working experience in Regex and/or scripting
- Strong critical thinking / contextual analysis abilities
- Strong investigative and analytical problem solving skills
- Stakeholder management
- Meticulous with an eye for details
- Product certification such as Splunk Enterprise Certified Administrator or equivalent
- Professional certification such as SANS (such as SANS GCDA, GCIA, GDSA, GMON) would be an advantage
- Good understanding of whole of government environment would be an advantage
Top Skills
Regex
Scripting
SIEM
Ensign InfoSecurity Singapore Office
30A Kallang Place, #08-01, Singapore, Singapore , Singapore, 339213
Similar Jobs
Artificial Intelligence • Cloud • Sales • Security • Software • Cybersecurity • Data Privacy
The Senior Solution Engineer will work with sales teams to support direct and indirect sales efforts, engaging with partners and customers to articulate the value of SailPoint solutions. This role requires expertise in identity management and excellent communication skills to understand customer requirements and demonstrate product capabilities. Achieving set milestones in the first year is essential for success.
Top Skills:
JavaLdapSQLXML
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
As a Cloud Incident Response Consultant at CrowdStrike, you will lead cloud incident response engagements, manage projects involving Azure, AWS, or GCP, and assist clients with threat actor activity. You'll perform forensic analysis, deliver technical assessments, and present findings to stakeholders. You should have expertise in cloud security and incident response methodologies, with strong communication skills to convey complex information effectively.
Top Skills:
AWSAzureGCP
Artificial Intelligence • Fintech • Other • Automation
Join Hudson River Trading as a Senior Security Operations Engineer responsible for designing, building, and supporting solutions to impact global cyber security systems. Key responsibilities include building and maintaining security detection and response programs, analyzing network activity, and fostering cross-functional relationships.
Top Skills:
Python
What you need to know about the Singapore Tech Scene
The digital revolution has driven a constant demand for tech professionals across industries like software development, data analytics and cybersecurity. In Singapore, one of the largest cities in Southeast Asia, the demand for tech talent is so high that the government continues to invest millions into programs designed to develop a talent pipeline directly from universities while also scaling efforts in pre-employment training and mid-career upskilling to expand and elevate its workforce.