Marks & Spencer Group plc

Detection Engineer, Associate/Director (Assistant VP)

Marks & Spencer Group plc
Apply
1 hour ago
Singapore, SingaporeStaff+

Responsibilities

  • Develop, test, tune, and maintain detection logic across endpoint, network, identity, application, and other enterprise telemetry sources.
  • Translate adversary behavior, threat intelligence, and hunt hypotheses into practical detection strategies and measurable coverage.
  • Use Python to automate workflows, parse and enrich security data, and improve threat hunting and detection tools.
  • Investigate security signals and suspicious activity to understand attacker behavior, validate detections, and reduce false positives.
  • Research malware behavior, command-and-control patterns, adversary infrastructure, and campaigns relevant to the firm’s threat landscape.
  • Map detection and hunting activities to adversary tactics, techniques, and procedures using frameworks such as MITRE ATT&CK.
  • Contribute to peer reviews, detection-as-code practices, testing processes, documentation, and engineering standards.
  • Collaborate with threat intelligence, incident response, purple team, and platform engineering stakeholders.

Requirements

  • At least 3 years of hands-on experience in cybersecurity, threat intelligence, threat hunting, detection engineering, security engineering, security-focused software engineering, incident response, blue teaming, or a related field.
  • Strong Python development skills, including maintainable code, API usage, structured and unstructured data processing, workflow automation, and troubleshooting.
  • Practical experience analyzing security data, logs, alerts, or telemetry to identify suspicious activity or understand adversary behavior.
  • Working knowledge of detection logic, rule tuning, alert quality, false-positive reduction, and detection validation.
  • Knowledge of adversary tactics, techniques, and procedures and how to convert attacker behavior into detection opportunities.
  • Experience with technologies such as Elasticsearch, Sigma, YARA, Git, SIEM platforms, EDR telemetry, or threat intelligence platforms.
  • Ability to interpret threat intelligence reporting and translate behaviors, indicators, and infrastructure patterns into hunting or detection opportunities.
  • Strong analytical, communication, and stakeholder-requirement gathering skills.
  • Preferred qualifications include experience with detections as code, threat hunting, cyber threat intelligence, malware analysis, adversary emulation, purple-team exercises, threat-informed defense, adversary infrastructure hunting, cloud platforms, or relevant cybersecurity certifications.

Benefits

  • Singapore-based role within Morgan Stanley’s global team, with a collaborative work environment and advanced technology infrastructure.
  • Training, development, and global collaboration opportunities.
  • Comprehensive employee benefits and perks supporting employees and their families.
  • Equal opportunity workplace committed to diversity, inclusion, and career development.

Categories

Marks & Spencer Group plc

About Marks & Spencer Group plc

10,000+ employees
Contact me