What you will be working on
You will be part of the Board’s network security team responsible for protecting systems, networks, and endpoints from cybersecurity threats. As an NDR & EDR Engineer, you will manage and operationalise Network Detection and Response (NDR) and Endpoint Detection and Response (EDR) platforms, working closely with internal teams to ensure robust threat detection and response capabilities.
In this role, you will:
- Deploy, configure, and maintain NDR and EDR solutions across on-premises and cloud environments, in accordance with applicable ICT security policies and standards.
- Develop, tune, and maintain detection rules and alert policies to improve detection accuracy and minimise false positives across networks and endpoints.
- Monitor, triage security alerts and escalate incidents to the SOC or Incident Response team in accordance with established procedures.
- Support incident response and forensic investigations, including analysis of endpoint and network telemetry, evidence handling and reporting.
- Conduct proactive threat hunting using NDR and EDR telemetry to identify indicators of compromise, suspicious and advanced persistent threats (APTs) targeting government infrastructure.
- Integrate NDR and EDR platforms with SIEM and security orchestration tools to support effective detection, investigation and response workflows.
- Ensure platform configurations and detection logic comply with applicable security frameworks, including the Government Instruction Manual on IT Management (IM8) and relevant cybersecurity guidelines.
- Maintain accurate and up-to-date documentation including platform configurations, standard operating procedures, and incident runbooks.
- Liaise with vendors, GovTech and internal stakeholders on platform updates, threat intelligence sharing, security advisories and related operational matters.
What we are looking for
We value the diverse talents and experiences that each individual brings to the table. While mastery of every requirement may not be necessary, familiarity and expertise in some of the following areas will position you for success within this team.
- Experience in cybersecurity engineering or security operations, including hands-on experience with EDR and/or NDR platforms such as CrowdStrike Falcon, Microsoft Defender for Endpoint, Trend Vision One, Darktrace, ExtraHop, Vectra AI or Corelight.
- Knowledge of network protocols, traffic analysis, and endpoint telemetry and forensic investigation techniques
- Good understanding of Windows and Linux internals, including processes, memory, registry and security models, with experience analysing event logs for threat detection.
- Familiarity with attack and persistence techniques (e.g. Pass-the-Hash, Kerberoasting, LOLBins, privilege escalation, SSH persistent) and their mapping to the MITRE ATT&CK framework, as well as experience deploying EDR agents and telemetry tools like Sysmon, auditd, and osquery.
- Proficiency in using SIEM platforms (e.g. Splunk, Microsoft Sentinel, QRadar) for security log analysis and investigation.
- Ability to develop and tune detection rules and queries using languages and formats such as KQL, SPL, Sigma rules.
- Experience supporting incident response investigations, including evidence handling, analysis and reporting.
- Ability to use scripting languages such as Python, PowerShell or Bash for automation and detection engineering.
- Familiarity with Singapore Government security frameworks including IM8, the Cybersecurity Act, and CSA's Cybersecurity Code of Practice would be advantageous.
- Exposure to cloud environments (e.g. Azure, AWS or Government Commercial Cloud) and associated security tools would be advantageous.
- Relevant certifications such as GCFA, GCFE, GCIA, GCED, CEH, or EDR/NDR certifications would be advantageous.
The seniority of appointment and actual corporate job title will commensurate with individual work experiences.
Position is on a 2-year full-time contract directly under the payroll of CPF Board with potential for emplacement into a permanent position.