Lead Security Systems Engineer (Microsoft Sentinel)
We are seeking a Security Operations Lead (Microsoft Sentinel) in Singapore. You will strengthen detection and incident response for a lean hedge fund environment, owning Sentinel tuning, triaging escalations and driving vendor-led SOC operations. You will turn alerts, vulnerabilities and posture data into clear actions and reporting that improves security outcomes.
Responsibilities
- Own Microsoft Sentinel detections including analytics rules, workbooks and Kusto Query Language (KQL) queries
- Lead day-to-day SOC and incident operations with an outsourced SOC/MDR vendor including SLAs, escalations and service reviews
- Validate log source coverage across endpoint, identity, network, cloud and critical business systems
- Triage and coordinate incident response from assessment through containment, remediation and closure in Jira Service Management
- Improve signal quality by reducing false positives and tracking Mean Time to Detect and Mean Time to Respond
- Run post-incident reviews and update detections, runbooks and incident response playbooks
- Own vulnerability scanning cadence, maintain a remediation register and track patching against agreed SLAs
- Mentor and support the Security Operations Analyst while building repeatable, audit-ready processes
Requirements
- Proven experience leading security operations in a hands-on capacity
- Strong background in Microsoft Sentinel including rule tuning, workbooks, hunting and detection engineering
- Hands-on experience with Microsoft Defender for Endpoint and Microsoft Defender for Cloud
- Demonstrated ability to manage an outsourced SOC/MDR service including escalations and performance governance
- Knowledge of incident response practices including severity assessment, coordination and post-incident reviews
- Experience with Jira Service Management and end-to-end ticket lifecycle ownership
- Strong understanding of Vulnerability Management including scanning, remediation tracking and patch governance
- Clear communication with confidence translating operational metrics into management-ready reporting
Nice to have
- Experience in a regulated environment such as financial services, asset management or a hedge fund
- Tenable Nessus or comparable vulnerability scanning tooling
- Darktrace or network anomaly detection tooling
Benefits
By choosing EPAM, you're getting a job at one of the most loved workplaces according to Newsweek 2021 & 2022&2023.
Employee ideas are the main driver of our business. We have a very supportive environment where your voice matters
You will be challenged while working side-by-side with the best talent globally. We work with top-notch technologies, constantly seeking new industry trends and best practices
We offer a transparent career path and an individual roadmap to engineer your future & accelerate your journey
At EPAM, you can find vast opportunities for self-development: online courses and libraries, mentoring programs, partial grants of certification, and experience exchange with colleagues around the world. You will learn, contribute, and grow with us