Responsibilities
- Design and manage comprehensive detection strategies across cloud platforms, identity providers, endpoints, SaaS applications, and AI model pipelines, including protections against prompt injection, model abuse, retrieval-augmented generation poisoning, and unauthorized tool usage.
- Lead full lifecycle incident response, including triage, containment, eradication, recovery, stakeholder communication, and post-mortem analysis to reduce future incident impact.
- Conduct proactive threat hunting across critical assets such as infrastructure, identity systems, source code repositories, secrets management, and AI workflows.
- Optimize and maintain security tooling including SIEM, EDR, CSPM, and SOAR platforms by reducing alert noise and automating decisions to preserve human judgment for high-severity events.
- Develop automation in Python and SOAR playbooks to enhance alert enrichment, response actions, evidence collection, ticketing workflows, and customer notifications.
- Manage end-to-end vulnerability operations including risk-based prioritization, patching timelines, exception tracking, and remediation validation, ensuring engineering teams address critical risks.
- Lead identity threat detection and response efforts, identifying suspicious sessions, OAuth exploitation, MFA bypass attempts, and misuse of AI agents or service account tokens.
- Participate in and lead on-call rotations, incident simulations, tabletop exercises, and operational readiness drills to maintain team responsiveness.
- Collaborate with platform, infrastructure, and AI engineering teams to secure model interfaces, agent logic, and tool integrations against emerging attack patterns.
- Convert operational insights into improved security controls, detection rules, and policy enhancements, and provide auditable evidence for compliance and customer trust initiatives.
- Leverage artificial intelligence to improve detection development, accelerate alert triage, draft incident reports, and enrich threat intelligence for faster response cycles.
Work Arrangement
Remote (Worldwide) — Singapore, India, Japan, Europe, US
Work Arrangement
Remote (Worldwide) — Singapore, India, Japan, Europe, US