
Detection Engineer, Associate/Director (Assistant VP)
Marks & Spencer Group plc1 hour ago
Singapore, SingaporeStaff+
Responsibilities
- Develop, test, tune, and maintain detection logic across endpoint, network, identity, application, and other enterprise telemetry sources.
- Translate adversary behavior, threat intelligence, and hunt hypotheses into practical detection strategies and measurable coverage.
- Use Python to automate workflows, parse and enrich security data, and improve threat hunting and detection tools.
- Investigate security signals and suspicious activity to understand attacker behavior, validate detections, and reduce false positives.
- Research malware behavior, command-and-control patterns, adversary infrastructure, and campaigns relevant to the firm’s threat landscape.
- Map detection and hunting activities to adversary tactics, techniques, and procedures using frameworks such as MITRE ATT&CK.
- Contribute to peer reviews, detection-as-code practices, testing processes, documentation, and engineering standards.
- Collaborate with threat intelligence, incident response, purple team, and platform engineering stakeholders.
Requirements
- At least 3 years of hands-on experience in cybersecurity, threat intelligence, threat hunting, detection engineering, security engineering, security-focused software engineering, incident response, blue teaming, or a related field.
- Strong Python development skills, including maintainable code, API usage, structured and unstructured data processing, workflow automation, and troubleshooting.
- Practical experience analyzing security data, logs, alerts, or telemetry to identify suspicious activity or understand adversary behavior.
- Working knowledge of detection logic, rule tuning, alert quality, false-positive reduction, and detection validation.
- Knowledge of adversary tactics, techniques, and procedures and how to convert attacker behavior into detection opportunities.
- Experience with technologies such as Elasticsearch, Sigma, YARA, Git, SIEM platforms, EDR telemetry, or threat intelligence platforms.
- Ability to interpret threat intelligence reporting and translate behaviors, indicators, and infrastructure patterns into hunting or detection opportunities.
- Strong analytical, communication, and stakeholder-requirement gathering skills.
- Preferred qualifications include experience with detections as code, threat hunting, cyber threat intelligence, malware analysis, adversary emulation, purple-team exercises, threat-informed defense, adversary infrastructure hunting, cloud platforms, or relevant cybersecurity certifications.
Benefits
- Singapore-based role within Morgan Stanley’s global team, with a collaborative work environment and advanced technology infrastructure.
- Training, development, and global collaboration opportunities.
- Comprehensive employee benefits and perks supporting employees and their families.
- Equal opportunity workplace committed to diversity, inclusion, and career development.