Overview WELCOME TO SITA At SITA, we keep airports moving, airlines flying smoothly, and borders open. Our technology and communication innovations power the success of the global air travel industry. You'll find us in 95% of international airports, working closely with over 2,500 transportation and government clients. Each partnership brings unique challenges, and we thrive on delivering fresh solutions and cutting-edge tech to keep operations running like clockwork. We don't just move the world forward-we're proud to be recognized as a Great Place to Work ® by 79% of our employees and certified in most of our growing locations. Here, we feel empowered, supported, and inspired to grow. Are you ready to love your job? The adventure begins right here, with you, at SITA. PURPOSE Supports operationalization of security by addressing vulnerabilities responding to incidents and maintaining compliance set out by EADAS. Manages service operations ensuring coordination across functions and continuous improvement of operational processes. KEY RESPONSIBILITIES Serve as the primary escalation point for SOC Analysts during security investigations. Lead technical investigations of security alerts and incidents. Validate alert classifications, severity ratings, incident scope, and escalation decisions. Perform advanced correlation and analysis across SIEM, EDR/XDR, cloud, identity, network, and endpoint telemetry. Build investigation timelines, collect evidence, and document findings to support escalation decisions. Escalate confirmed or suspected security incidents to the SIRT team in accordance with established Incident Response procedures. Collaborate with SIRT and other technical teams by providing investigative findings, evidence, and security context. Identify false positive trends, detection gaps, and monitoring deficiencies, and recommend improvements. Develop, maintain, and optimize detection rules, correlation logic, SOC use cases, and investigation playbooks. Perform tuning activities to improve alert fidelity and reduce false positives. Mentor SOC Analysts by providing technical guidance, investigation support, and quality reviews. Review investigation records to ensure consistency, accuracy, and compliance with SOC standards. Produce technical investigation reports, security summaries, and operational metrics. Participate in tabletop exercises, cyber simulations, and post incident review activities as required. Provide timely updates and escalation briefings to the SOC Manager, SOC SME, and relevant stakeholders. Apply the MITRE ATT&CK framework to classify adversary techniques and improve detection coverage. Provide part-time support to the Vulnerability Management (VM) function, including vulnerability validation, risk prioritization, and remediation support. Support continuous improvement initiatives to enhance SOC processes, operational efficiency, and service quality. Qualifications EXPERIENCE Advanced experience investigating security events using SIEM and EDR/XDR platforms, preferably with Elastic (SIEM) and Palo Alto Cortex XDR, Microsoft Defender XDR, and CrowdStrike Falcon (EDR/XDR). Experience analyzing logs from endpoints, identity platforms, cloud services, firewalls, proxies, DNS, VPN, and applications. Experience developing and tuning detection rules, correlation logic, and SOC use cases. Experience mentoring junior analysts and performing investigation quality reviews. KNOWLEDGE & SKILLS Strong understanding of the incident investigation and escalation lifecycle. Strong analytical and troubleshooting skills, including the ability to correlate events across multiple security technologies. Proficiency with security query languages such as KQL, Lucene, EQL, and Sigma. Working knowledge of PowerShell and/or Python for investigations and automation. Solid understanding of Windows, Linux, Active Directory, Microsoft 365, Azure/AWS, networking, and common attack techniques. Strong knowledge of the MITRE ATT&CK framework and its application to security monitoring and detection engineering. Strong written and verbal communication skills. Strong attention to detail and documentation skills. Self-motivated, adaptable, proactive, and committed to continuous learning. EDUCATION & QUALIFICATIONS Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, or a related field. 3–5 years of experience as a SOC L2 Analyst or in an equivalent Security Operations role. At least one industry-recognized cybersecurity certification (e.g., SC-200, GCIH, GCIA, CySA+, ECIH). WHAT WE OFFER We're all about diversity. We operate in 200 countries and speak 60 different languages and cultures. We're really proud of our inclusive environment. Our offices are comfortable and fun places to work, and we make sure you get to work from home too. Find out what it's like to join our team and take a step closer to your best life ever. 🏡 Flex Week: Work from home up to 2 days/week (depending on your team's needs) ⏰ Flex Day: Make your workday suit your life and plans. 🌎 Flex-Location: Take up to 30 days a year to work from any location in the world. 🌿 Employee Wellbeing: We have got you covered with our Employee Assistance Program (EAP), for you and your dependents 24/7, 365 days/year. We also offer Champion Health - a personalized platform that supports a range of wellbeing needs. 🚀 Professional Development: At SITA, we believe growth fuels innovation. Our learning ecosystem offers access to world-class platforms and programs designed to help you thrive. From LinkedIn Learning, Microsoft's Enterprise Skills Initiative, and Airport Council International -available to all employees-to specialized solutions like Pluralsight for technology upskilling, Harvard Business Publishing for people leadership, Stanford for strategic development and many others, we align learning opportunities with your Development Plan and our business priorities. Your development journey is supported every step of the way. 🙌 Competitive Benefits: Competitive benefits that make sense with both your local market and employment status. SITA is an Equal Opportunity Employer. We value a diverse workforce. In support of our Employment Equity Program, we encourage women, aboriginal people, members of visible minorities, and/or persons with disabilities to apply and self-identify in the application process. Starting Compensation Starting Compensation Compensation Note Hidden (-999)
GRC / Security Compliance Analyst
Reap
Security Monitoring Analyst
Eset
Cybersecurity Analyst
Vigilbase
Software Engineer – Elite Quant Fund - Up to 250,000 SGD - Starting base + Exceptional benefits/bonus package Fund – Singapore
Hunter Bond
Quality Engineer II
Jabil
Senior Director, Solutions Architecture, APAC
Cohere