
Senior Security Operations Engineer, AIDC
BitDeer Technologies Group4 months ago
Singapore, SingaporeSenior
Responsibilities
- Monitor, triage, and respond to security alerts and L2/L3 incidents for Asian AI data centers, including participation in a 7×24 on-call rotation.
- Execute incident forensics, containment, recovery, post-incident reviews, root-cause analysis, remediation tracking, and regional playbook maintenance.
- Operate SIEM and HIDS platforms, including detection-rule tuning, false-positive suppression, log-source onboarding, agent coverage, policy maintenance, and health monitoring.
- Write and maintain detection rules for GPU cloud, Kubernetes, SSH, container, InfiniBand/RoCE, and BMC attack vectors, and participate in threat hunting using the MITRE ATT&CK Cloud Matrix.
- Harden Linux AIDC servers, standardize auditd, strengthen SSH and privileged access controls, track infrastructure CVEs, and support vulnerability assessment and patch deployment.
- Support IAM and privileged access operations, including jump-host user management, just-in-time access approvals, and privileged-session audit reviews.
- Maintain firewall, IPS/WAF, InfiniBand/RoCE, DDoS, and network traffic security operations, including NetFlow/IPFIX analysis.
- Develop security automation for alert aggregation, forensic collection, IOC checks, log parsing, and anomaly tagging.
- Coordinate security event handoffs with Americas and European teams, support customer incident response, and assist with SOC 2 and ISO 27001 evidence collection.
- Write security operations documentation and maintain the SOC knowledge base.
Requirements
- Bachelor’s degree or higher in Computer Science, Cybersecurity, Computer Engineering, or a related field.
- At least 5 years of hands-on information security experience, including at least 3 years focused on cloud infrastructure, IaaS, or data center security operations.
- Independent L2/L3 incident response experience, including intrusion detection, malware analysis, and forensics.
- Strong Linux administration and hardening skills, including CIS Benchmark configuration, auditd setup, iptables/nftables rules, and system log analysis.
- Hands-on experience with Wazuh, Splunk, Elastic SIEM, or an equivalent SIEM, including independently writing detection rules and tuning alerts.
- Container and Kubernetes security knowledge, including Pod Security Policies, RBAC, network policies, and image security scanning.
- Strong Python and Shell scripting skills for developing security automation tools.
- Network security fundamentals involving TCP/IP, firewalls, IPS/IDS, VPNs, tcpdump, Wireshark, and traffic analysis.
- Familiarity with the MITRE ATT&CK Framework and its application to detection and response.
- Professional fluency in English and Mandarin Chinese for documentation, incident reporting, technical discussions, and management communication.
- Willingness to work irregular hours, participate in major-incident on-call coverage, and conduct cross-time-zone handoffs.
- Preferred: security operations experience in GPU cloud, supercomputing, HPC, AIDC, major cloud provider, or large internet-company environments.
- Preferred: experience with NVIDIA GPU clusters, InfiniBand, BMC out-of-band management, eBPF tools, KVM/QEMU virtualization security, detection-as-code, SIGMA, large-scale HIDS, threat hunting, bug bounties, CTFs, or open-source security projects.
Benefits
- Training, mentoring, and developmental opportunities.
- Inclusive workplace that values authenticity and diverse perspectives.
- Opportunity to contribute to new projects, processes, and systems in a fast-growing digital asset and AI cloud company.
- Autonomy, personal accountability, learning opportunities, and direct impact on the company’s technology.
- The role includes 7×24 on-call participation, irregular working hours during major incidents, and cross-time-zone coordination with Americas and European teams.