Cyber Threat Management Senior/Security Engineer

Summary

Senior Security Engineer role focused on cyber threat management within a supply chain and logistics organization, leading threat intelligence, vulnerability management, attack surface monitoring, and incident response while mentoring analysts and maturing security operations through automation and AI-driven tooling.

About the Role

We are looking for an experienced Security Engineer to join a growing Information Security Operations team within a well-established organization in the supply chain and logistics sector. This is a critical role focused on strengthening the organization's cyber defence capabilities through threat detection, intelligence-led analysis, and proactive vulnerability and risk management. The successful candidate will bring strong technical depth alongside the leadership skills needed to guide a team and continuously mature the organisation's overall security posture.

Key Responsibilities

Threat Intelligence & Detection

  • Drive the organization's threat intelligence capability, helping to identify emerging threats and attack patterns before they materialise into incidents
  • Take ownership of threat hunting activities, including the investigation of advanced and persistent threats
  • Partner with internal teams and external intelligence sources to keep threat feeds relevant and contextualized to the organisation's risk landscape

Vulnerability & Risk Management

  • Manage vulnerabilities end-to-end — from discovery and risk assessment through to prioritization, remediation, and reporting
  • Continuously improve the tools and processes used for vulnerability scanning across the environment

Attack Surface & Network Security

  • Monitor the organization's external-facing footprint to identify exposed systems, misconfigurations, and potential entry points for attackers
  • Assess network exposure at the port and protocol level, and contribute to reviewing firewall rules, network segmentation, and access policies
  • Build out processes to continuously discover and secure internet-facing assets
  • Support incident response and containment efforts when issues are identified

Team Leadership & Process

  • Guide and mentor a team of security analysts, helping to build technical capability across the group
  • Develop and maintain playbooks and SOPs covering threat hunting, vulnerability remediation, and incident response
  • Champion the use of automation — and increasingly, AI-driven tools — to make security operations more efficient

Reporting & Governance

  • Build reporting mechanisms that give real-time visibility into compliance status and remediation progress
  • Support audit readiness by ensuring security data is accurate and well-integrated with GRC and ITSM systems
  • Stay ahead of regulatory changes and evolving threat trends to keep security practices current

What We're Looking For

  • Degree in Information Security, IT, or a related field
  • 3+ years of experience in Information Security Operations, with hands-on vulnerability management exposure
  • Strong understanding of network security protocols and common ports/services
  • Experience leading or contributing to security automation initiatives, with some team mentoring exposure
  • Familiarity with threat intelligence and vulnerability management platforms (e.g. SIEM, EASM tools, endpoint/vulnerability scanning solutions)
  • Strong stakeholder communication skills and the ability to manage multiple priorities under pressure

Good to Have

  • Experience applying the MITRE ATT&CK framework or structured threat modeling
  • Broader security domain knowledge — networking, IAM, endpoint, cloud/IoT, application security
  • Relevant certifications such as CISSP, CISM, GIAC, CEH, or OSCP
  • Experience running security awareness training or tabletop exercises
  • Familiarity with ISO and/or NIST security frameworks


Lin Wee
License No. 22C1076 | EA Reg: R1878551

See also

要針對這個職缺調整履歷嗎?

目前無法檢查您與這個職缺的符合程度;請先將履歷加入個人檔案,下次即可查看。

A new version of freehire is available