
Senior Detection Engineer, Director (Assistant VP)
Marks & Spencer Group plc1 hour ago
Singapore, SingaporeStaff+
Responsibilities
- Design, develop, test, tune, and maintain detection logic across endpoint, network, identity, application, and enterprise telemetry sources.
- Hunt adversary infrastructure, tooling, command-and-control patterns, phishing infrastructure, staging infrastructure, and attacker abuse of legitimate services.
- Translate threat hunting, malware analysis, reverse engineering, and investigative findings into scalable detection strategies and proactive surveillance capabilities.
- Use Python to automate analysis, enrich security data, integrate APIs, and build investigative workflows and security tooling.
- Build and maintain tools for processing large datasets, identifying infrastructure and tooling patterns, validating detection ideas, and accelerating investigations.
- Analyze security telemetry and suspicious activity to understand attacker behavior, validate detection quality, identify coverage gaps, and recommend improvements.
- Collaborate with threat intelligence, incident response, and purple-team stakeholders on high-fidelity detections and threat-informed defense.
- Provide technical guidance to junior team members through reviews, investigation support, documentation, and knowledge sharing.
Requirements
- At least 7 years of related hands-on experience in detection engineering, threat hunting, security engineering, incident response, blue teaming, malware analysis and reverse engineering, security operations engineering, or a related cybersecurity field.
- Strong knowledge of adversary tactics, techniques, and procedures, enterprise attack paths, post-exploitation behavior, malware, command-and-control patterns, identity abuse, endpoint activity, network behavior, and security telemetry.
- Demonstrated experience in adversary infrastructure hunting, malware analysis and reverse engineering, command-and-control infrastructure analysis, phishing infrastructure analysis, botnet infrastructure hunting, tooling fingerprinting, or attacker abuse of legitimate services.
- Strong Python development skills, including maintainable code, API integration, structured and unstructured data processing, workflow automation, troubleshooting, and tool development.
- Practical experience building automation or tooling for security analysis, detection engineering, threat hunting, incident investigation, data enrichment, infrastructure hunting, reverse engineering workflows, or operational efficiency.
- Experience analyzing large volumes of security data, logs, alerts, indicators, telemetry, infrastructure patterns, or tool behaviors.
- Strong understanding of detection design, rule tuning, alert quality, coverage analysis, false-positive reduction, detection validation, and lifecycle management.
- Ability to convert technical findings and stakeholder requirements into detection logic, hunting opportunities, surveillance strategies, and practical technical solutions.
- Strong written and verbal communication skills for explaining technical findings, detection logic, and engineering tradeoffs to technical and non-technical stakeholders.
- Preferred qualifications include exposure to adversary emulation, purple-team exercises, red-team collaboration, threat-informed defense, security dashboards, notebooks, data pipelines, enrichment services, internal analyst tools, or relevant cybersecurity certifications.
Benefits
- Comprehensive employee benefits and perks supporting employees and their families throughout their work-life journey.
- Opportunity to work with collaborative teams and pursue internal mobility across the business.
- The position is based with the global team in Singapore.
- Morgan Stanley is committed to diversity, inclusion, equal opportunity, and employee development.