Cyber Threat Management Senior/Security Engineer
Summary
Senior Security Engineer role focused on cyber threat management within a supply chain and logistics organization, leading threat intelligence, vulnerability management, attack surface monitoring, and incident response while mentoring analysts and maturing security operations through automation and AI-driven tooling.
About the Role
We are looking for an experienced Security Engineer to join a growing Information Security Operations team within a well-established organization in the supply chain and logistics sector. This is a critical role focused on strengthening the organization's cyber defence capabilities through threat detection, intelligence-led analysis, and proactive vulnerability and risk management. The successful candidate will bring strong technical depth alongside the leadership skills needed to guide a team and continuously mature the organisation's overall security posture.
Key Responsibilities
Threat Intelligence & Detection
- Drive the organization's threat intelligence capability, helping to identify emerging threats and attack patterns before they materialise into incidents
- Take ownership of threat hunting activities, including the investigation of advanced and persistent threats
- Partner with internal teams and external intelligence sources to keep threat feeds relevant and contextualized to the organisation's risk landscape
Vulnerability & Risk Management
- Manage vulnerabilities end-to-end — from discovery and risk assessment through to prioritization, remediation, and reporting
- Continuously improve the tools and processes used for vulnerability scanning across the environment
Attack Surface & Network Security
- Monitor the organization's external-facing footprint to identify exposed systems, misconfigurations, and potential entry points for attackers
- Assess network exposure at the port and protocol level, and contribute to reviewing firewall rules, network segmentation, and access policies
- Build out processes to continuously discover and secure internet-facing assets
- Support incident response and containment efforts when issues are identified
Team Leadership & Process
- Guide and mentor a team of security analysts, helping to build technical capability across the group
- Develop and maintain playbooks and SOPs covering threat hunting, vulnerability remediation, and incident response
- Champion the use of automation — and increasingly, AI-driven tools — to make security operations more efficient
Reporting & Governance
- Build reporting mechanisms that give real-time visibility into compliance status and remediation progress
- Support audit readiness by ensuring security data is accurate and well-integrated with GRC and ITSM systems
- Stay ahead of regulatory changes and evolving threat trends to keep security practices current
What We're Looking For
- Degree in Information Security, IT, or a related field
- 3+ years of experience in Information Security Operations, with hands-on vulnerability management exposure
- Strong understanding of network security protocols and common ports/services
- Experience leading or contributing to security automation initiatives, with some team mentoring exposure
- Familiarity with threat intelligence and vulnerability management platforms (e.g. SIEM, EASM tools, endpoint/vulnerability scanning solutions)
- Strong stakeholder communication skills and the ability to manage multiple priorities under pressure
Good to Have
- Experience applying the MITRE ATT&CK framework or structured threat modeling
- Broader security domain knowledge — networking, IAM, endpoint, cloud/IoT, application security
- Relevant certifications such as CISSP, CISM, GIAC, CEH, or OSCP
- Experience running security awareness training or tabletop exercises
- Familiarity with ISO and/or NIST security frameworks
Lin Wee
License No. 22C1076 | EA Reg: R1878551