jobs in Astek

Astek Hiring! Full Time Cyber Security Engineer in - Ricebowl

Cyber Security Engineer

Astek

Singapore

Share
Save

Working Location

  • Singapore

Job Description

Responsibilities

Detection Engineer – Security Exposure & Third-Party Cyber Assurance


Role Overview

We are looking for a Detection Engineer to support the build-out and operations of the Security Exposure and Third-Party Cyber Assurance Centre of Excellence, under Cybersecurity Assurance and Defense (CASD) – External Threat Operations.

The role will provide hands-on technical and operational support across two key areas:

  • Security Exposure Management (SEM): Continuous, outside-in monitoring of the organisation and its portfolio companies’ internet-facing attack surface.
  • Third-Party Cyber Assurance (TPCA): Cybersecurity due diligence and continuous assurance across third parties and the broader supply chain.


The successful candidate will operate continuous monitoring platforms, conduct third-party cyber assessments, validate active and emerging threats, and coordinate remediation to reduce the time between exposure identification and potential exploitation.


Key Responsibilities

  • Operate and maintain always-on security exposure and external threat monitoring platforms.
  • Monitor the organisation, portfolio companies, and third parties for internet-facing vulnerabilities, exposures, and emerging cyber threats.
  • Perform Attack Surface Management (ASM/EASM) activities to identify, assess, validate, and prioritise external security exposures.
  • Conduct third-party/vendor cybersecurity assessments, including security questionnaires and due diligence activities such as VDD, ODD, and SIG.
  • Assess third-party security controls against established frameworks including NIST, ISO 27001, and CIS Controls.
  • Leverage Cyber Threat Intelligence (CTI), digital risk, and dark-web monitoring to identify and validate relevant threats.
  • Investigate and validate high-risk or imminent security threats and coordinate appropriate remediation with relevant stakeholders.
  • Analyse third- and fourth-party cyber risks and their potential impact across the organisation and supply chain.
  • Develop scripts and automation using Python, PowerShell, or Bash to streamline monitoring, analysis, reporting, and operational activities.
  • Build and maintain operational dashboards, reporting capabilities, and cyber posture metrics using data lake platforms.
  • Document findings, processes, assessments, and remediation actions clearly for both technical and business stakeholders.
  • Support continuous improvement of detection logic, control baselines, monitoring processes, and exposure management capabilities.


Requirements

  • Degree in Computer Science, Information Technology, or a related discipline.
  • 3–5 years of hands-on cybersecurity experience, preferably within cybersecurity operations, attack surface/exposure management, third-party cyber risk assessment, or data lake environments.
  • Practical experience conducting third-party/vendor security assessments and questionnaires, including VDD, ODD, and SIG.
  • Good knowledge of cybersecurity frameworks such as NIST, ISO 27001, and CIS Controls.
  • Hands-on experience with ASM/EASM, cyber exposure management, digital risk monitoring, dark-web monitoring, and/or Cyber Threat Intelligence (CTI) platforms.
  • Strong scripting capabilities using Python, PowerShell, or Bash, particularly for automation and reporting.
  • Strong understanding of TCP/IP, DNS, HTTP/S, and common security exposures across AWS, Azure, and GCP.
  • Understanding of third- and fourth-party cyber risk and how security exposure can propagate through the supply chain.
  • Strong analytical and documentation skills, with the ability to handle sensitive security findings appropriately.
  • Good communication and stakeholder management skills across technical and business teams.
  • Collaborative, adaptable, and comfortable working in a fast-evolving cybersecurity environment.


Good to Have

  • Certifications such as Security+, CEH, GIAC (GSEC/GCIH), CompTIA CySA+, or equivalent.
  • CISSP Associate or CISM candidature.
  • Experience developing cyber posture scorecards and operational security dashboards.
  • Familiarity with detection engineering, including tuning detection logic and refining security control baselines as capabilities mature.


Key Skills / Technologies

SEM | TPCA | ASM/EASM | CTI | Third-Party Cyber Risk | VDD/ODD | SIG | NIST | ISO 27001 | CIS Controls | Digital Risk & Dark-Web Monitoring | Python | PowerShell | Bash | TCP/IP | DNS | HTTP/S | AWS | Azure | GCP | Data Lakes | Detection Engineering

Important Information

Never provide your bank or credit card details when applying for jobs. Do not transfer any money or complete unrelated online surveys. If you see something suspicious, Report this Job ad.

Learn More