Threat Detection Analyst
Job description
About the role
Fastly is seeking a dedicated professional to join our security team in Singapore. You will focus on identifying and mitigating emerging threats to ensure the safety and integrity of our global edge cloud platform. In this capacity, you will own the design and implementation of detection strategies that directly protect our critical infrastructure. The role requires a high level of ownership over security workflows and the proactive identification of risks before they escalate. You will serve as a key defender of our systems, using advanced analytical techniques to safeguard our customers' digital presence. Success in this position will be measured by the reduction in incident impact and the improvement of our overall security posture. You will be expected to contribute to a culture of security excellence and continuous improvement within the organization.
Key facts
What you'll do
- Conduct continuous surveillance of network traffic and system logs to uncover indicators of compromise and potential security breaches.
- Perform detailed forensic analysis on security events to determine root causes and develop effective remediation strategies.
- Design and iteratively refine detection rules and logic to keep pace with evolving threat landscapes and attack methodologies.
- Execute complex investigations into suspicious activities, correlating data from multiple sources to build a comprehensive threat picture.
- Work closely with engineering and operations teams to translate security insights into actionable defensive measures and architectural improvements.
- Develop and maintain comprehensive documentation for threat detection procedures, playbooks, and incident response protocols.
- Collaborate with intelligence feeds and industry resources to stay informed about emerging vulnerabilities and targeted campaigns.
- Utilize advanced analytical methodologies to identify subtle anomalies that may indicate sophisticated, low-and-slow attack patterns.
- Participate actively in incident response lifecycle management, from initial detection through containment, eradication, and recovery.
- Contribute to the enhancement of security tooling and processes to improve efficiency and effectiveness of monitoring operations.
- Provide clear technical communication of threat findings and recommended actions to both technical and executive stakeholders.
- Support the development and validation of new security use cases to proactively identify risks within the edge cloud environment.
Requirements
- Demonstrate proven experience in a security operations or threat analysis role within a technology or internet-focused environment.
- Show proficiency in analyzing large datasets and log sources to identify security anomalies, patterns, and outliers.
- Exhibit a deep understanding of web application security principles, common attack vectors, and the tactics used by threat actors.
- Prove the ability to work effectively within a distributed, global team environment, collaborating across time zones and cultural boundaries.
- Maintain strong written and verbal communication skills for reporting findings, documenting procedures, and coordinating incident responses.
- Hold the legal right to work in Singapore and possess any required local certifications or qualifications for security roles.
- Apply a methodical and detail-oriented approach to investigations, ensuring thoroughness and accuracy in all security-related tasks.
- Comply with all organizational security policies, procedures, and data governance requirements in the execution of daily duties.
Skills & tools
- Apply expertise in Web Application Firewall (WAF) technologies to monitor, analyze, and tune security policies.
- Utilize log analysis and observability tools to aggregate, correlate, and visualize security data from distributed systems.
- Leverage knowledge of network security protocols and traffic analysis techniques to inspect and interpret complex data flows.
- Draw upon a solid understanding of modern web architecture, including edge computing concepts, to assess security implications effectively.
- Familiarize with scripting and automation principles to enhance the efficiency of repetitive security analysis tasks.
- Engage with threat intelligence platforms and security information and event management (SIEM) systems as core components of the toolkit.
- Contribute to the evaluation and implementation of security best practices aligned with industry standards and frameworks.
- Collaborate with product and engineering teams to ensure security considerations are integrated into the development lifecycle.
Practical notes
Applicants must have the legal right to work in Singapore. Please submit your application through the Fastly careers portal. The role is based in Singapore and requires full-time onsite engagement. There are no specific travel requirements or visa sponsorship details provided for this position at this time. The recruitment process is active, and applications should be submitted promptly through the designated channel to be considered.