Cyber Threat Hunter & Incident Response Specialist
- Location
- Singapore
- Salary Package
- Negotiable
- Posted
- 20th Jul 2026
- Consultants
- Elmer Tan
We are looking for a hands-on Cyber Threat Hunter with strong incident response experience to join a growing security operations function. This role sits at the intersection of proactive threat detection and reactive incident handling - you'll be hunting for adversaries that evade automated defences, and leading the charge when something is actually found.
What You'll Do
- Conduct proactive, hypothesis-driven threat hunts across endpoints, network traffic, and cloud environments to uncover adversary activity that bypasses existing detection controls
- Develop and refine hunting hypotheses based on threat intelligence, MITRE ATT&CK mappings, and emerging attacker tradecraft
- Lead end-to-end incident response for confirmed security events - triage, containment, eradication, and recovery
- Perform root cause analysis and produce clear, actionable post-incident reports for technical and non-technical stakeholders
- Build and tune detection use cases, correlation rules, and hunting queries to close visibility gaps identified during hunts and investigations
- Analyse malware, forensic artefacts, and attacker techniques to understand scope, impact, and persistence mechanisms
- Collaborate with SOC analysts, threat intelligence, and engineering teams to strengthen detection coverage and reduce dwell time
- Maintain and evolve playbooks, runbooks, and standard operating procedures for both hunting and incident response
- Contribute to purple team exercises, validating detection efficacy against simulated adversary behaviour
- Stay current on emerging threat actor groups, TTPs, and tooling relevant to the organisation's risk profile
What You'll Bring
- Proven experience in threat hunting, digital forensics, and incident response (DFIR)
- Strong working knowledge of the MITRE ATT&CK framework and adversary emulation concepts
- Hands-on experience with EDR, SIEM, and network detection and response tooling
- Familiarity with scripting or query languages (e.g. Python, KQL, or similar) for hunt automation and log analysis
- Solid understanding of Windows, Linux, and cloud environments from a security operations perspective
- Experience handling live incidents under pressure, with clear and calm stakeholder communication
- A curious, adversarial mindset - comfortable thinking like an attacker to find what defences miss
EA Licence: 16S8091
EA Reg No.: R1656500