About the role
This role is part of the Cyber Fusion Center’s SOC team, responsible for advanced monitoring, investigation, and response to security incidents across client environments. Acting as the escalation point for L1 analysts, the role plays acritical part in enhancing detection capabilities and strengthening incident response processes.
In addition, the position ensures the successful delivery and continuous optimization of managed security services. It combines deep technical expertise with client-facing responsibilities, ensuring alignment with service-level agreements (SLAs), improving clients’ security posture, and driving ongoing service enhancements.
Key Responsibilities:
Security Monitoring & Incident Response
Perform advanced analysis and investigation of security alerts from SIEM platforms(e.g. Google SecOps).
Act as escalation point for L1 analysts for complex incidents.
Lead incident response activities including triage, containment, eradication, and recovery.
Conduct threat hunting and proactive detection using threat intelligence and behavioral analytics.
Detection Engineering &Continuous Improvement
Tune and enhance SIEM rules, use cases, and detection logic.
Support onboarding and validation of log sources and assets.
Develop and maintain SOC playbooks and response procedures.
Continuously improve detection coverage aligned with frameworks (e.g., MITRE ATT&CK).
Service Delivery & Client Engagement
Serve as a key point of contact for client security operations matters.
Ensure SOC services are delivered in accordance with SLAs and KPIs.
Conduct regular reporting and service review sessions with clients.
Provide actionable security recommendations based on findings and threat landscape.
Validate onboarding of client infrastructure (log sources, assets, integrations).
Ensure visibility across tools (SIEM, SOAR, EDR, Threat Intel).
Reporting & Governance
Produce detailed incident reports, executive summaries monthly reporting, and service metrics.
Track SLA performance, incident trends, and operational KPIs.
Support compliance, audit, and governance requirements
Candidate requirements:
3 – 6 years of experience in SOC operations, cybersecurity, or managed security services.
Hands-on experience with SIEM (Google Chronicle/SecOps preferred).
Strong knowledge of:
Incident response and threat analysis
Network, endpoint, and cloud security
MITRE ATT&CK framework
Experience in client-facing or service delivery roles is highly preferred.
Familiarity with tools such as EDR/XDR (e.g. Crowdstrike, MS defender), TI (e.g. Cyble, GTI), JumpCloud, and cloud platforms.
Relevant certifications (preferred):
CompTIA Security+, CySA+
CEH, GCIA, GCIH
CISSP or CISM
ABP Group is Asia’s leading Cybersecurity technology provider focusing on delivering the best-of-breed security solutions for today’s cybersecurity challenges. Founded in 2014 with its headquarter in Singapore, ABPGroup endeavours to pioneer the market through the development, distribution and integration of reliable and avant-garde technologies. Customers trust us in delivering cutting edge solutions for the elimination and mitigation of cybersecurity risks while achieving high returns on investment for their core businesses.
Our businesses include:
Sunnic, a technology firm that provides comprehensive digital data security solutions to regional banks and government agencies. Sunnic's flagship security solutions are Total Data Protection, which secures data during transmission, processing, and storage, and Secure Payment, which provides strict point-to-point encryption as well as credit card encryption technology. Sunnic has worked with a number of reputable and well-known institutions in the region.
ABPCyber, a trusted partner for customers in leading enterprises, financial institutions, educational institutions, and government sectors. Based in Singapore, APBCyber specializes in cybersecurity consultancy and advisory, architecture design and integrations, managed operations, and managed security services for advanced threat detection and response.
ABPSecurite, a leading value-added distributor of Cybersecurity and Network Performance (VAD). ABPSecurite offers three main service suites: Professional Services, Maintenance and Support Services, Cloud Management Services. Professional services include consulting and installation to help companies perfectly implement their needs. ABPSecurite offers 24/7 breakfix and phone support for various technology portfolios. Cloud management services help businesses harness the computing power of the cloud and enable businesses to effectively and efficiently outsource cloud deployment, operations, and management.