Senior Consultant, Incident Response and Threat Hunting
Ensign InfoSecurity · Singapore, Singapore
Apply & track with Apply EdgeRole SummaryThe Senior Consultant, Incident Response & Threat Hunting leads complex cybersecurity investigations, digital forensic engagements, threat hunting operations, compromise assessments, cloud incident response activities, and AI-related security investigations.The role combines deep technical expertise with consulting, stakeholder management, and leadership capabilities to deliver high-value client engagements across enterprise, cloud, mobile, and hybrid environments. The consultant will also mentor junior staff, develop service offerings, and contribute to cyber resilience initiatives.Key ResponsibilitiesIncident ResponseLead end-to-end incident response engagements involving: Ransomware attacksAdvanced persistent threats (APT)Business email compromise (BEC)Cloud compromisesInsider threatsData exfiltration incidentsIdentity-based attacksEstablish investigative strategies and response priorities.Direct forensic acquisition, evidence preservation, root cause analysis, and attack reconstruction.Develop containment, eradication, recovery, and remediation recommendations.Lead executive briefings and incident response war rooms.Threat HuntingLead proactive threat hunting engagements across enterprise and cloud environments.Develop intelligence-driven and hypothesis-based hunting methodologies.Conduct advanced threat hunts against sophisticated adversaries and emerging attack techniques.Correlate endpoint, network, cloud, identity, mobile, and application telemetry.Identify detection gaps and improve monitoring capabilities.Develop threat hunting playbooks, detection use cases, and adversary emulation scenarios.Mentor consultants on advanced hunting methodologies and threat intelligence utilisation.Digital ForensicsConduct forensic investigations across: WindowsLinuxUnixmacOSVirtualized environmentsPerform attack reconstruction and evidentiary analysis.Lead malware triage and forensic examinations.Produce defensible investigative findings and reports.Network & Security Appliance InvestigationsLead investigations involving: FirewallsVPN solutionsNetScalerF5 Load BalancersWAF platformsIDS/IPS solutionsEmail gatewaysProxy solutionsNDR platformsEndpoint security solutionsAnalyse network traffic, authentication patterns, lateral movement, and data exfiltration activities.Review security architecture and identify attack paths.Cloud & Identity ResponseLead compromise assessments and incident response engagements involving: Microsoft AzureAWSGCPMicrosoft 365SaaS platformsInvestigate identity-based attacks involving Active Directory and Microsoft Entra ID.Analyse cloud-native logs, security telemetry, and access activities.Mobile Security InvestigationsLead investigations involving Android and iOS devices.Conduct mobile compromise assessments and forensic analysis.Review mobile application threats, MDM events, and enterprise mobility incidents.AI Security InvestigationsLead investigations involving: AI platformsLLM deploymentsGenerative AI applicationsAI agentsAI-enabled business systemsAssess: Prompt injection attacksAI misuseUnauthorized model accessModel poisoningData leakageAI supply chain risksAdvise clients on AI security controls, governance, and incident response preparedness.Incident Replay & Cyber Range CapabilityDesign, build, and manage virtualized forensic laboratories and cyber range environments.Reconstruct incidents through attack replay and adversary emulation.Develop isolated environments for malware detonation and investigation.Simulate enterprise infrastructures to validate attack paths and investigative findings.Develop repeatable environments for incident readiness testing and tabletop exercises.Automate investigation workflows and analysis processes where appropriate.Client Advisory & ConsultingLead client workshops, tabletop exercises, breach simulations, and cyber readiness assessments.Present findings to executives, legal counsel, regulators, and technical stakeholders.Develop incident response playbooks, forensic methodologies, and response procedures.Mentor junior consultants and contribute to team capability development.Business Development & Thought LeadershipSupport proposal development and pre-sales activities.Contribute to research, publications, threat intelligence initiatives, and service innovation.Develop new service offerings related to DFIR, threat hunting, cloud security, and AI security.RequirementsBachelor's Degree in Cybersecurity, Information Security, Computer Science, Information Technology, or related field.Equivalent practical experience may be considered.5-10+ years of experience in Incident Response, Digital Forensics, Threat Hunting, Cyber Security Consulting, Security OperationsTechnical ExpertiseSystems & Endpoint SecurityWindows, Linux, Unix, macOS.Endpoint forensic investigations.Malware analysis and attack reconstruction.Active Directory and Entra ID investigations.Network & Security InfrastructureTCP/IP and enterprise networking.Network forensics and packet analysis.Firewall technologies.VPN platforms.IDS/IPS.Proxy solutions.NDR platforms.Security appliance investigations.Cloud & IdentityAzureAWSGCPMicrosoft 365SaaS securityCloud-native logging and investigationsThreat Hunting & Detection EngineeringMITRE ATT&CKThreat intelligenceDetection engineeringSIEM, EDR, NDR, and SOAR platformsAdversary emulation and attack simulationMobile SecurityAndroid and iOS investigationsMobile device forensicsMobile threat analysisMDM solutionsAI SecurityAI/LLM security architectureAI threat modelsAI incident response methodologiesAI governance and riskVirtualization & Incident ReplayVMware ESXiHyper-VProxmoxKVMCloud-based lab environmentsCyber range design and administrationSandbox technologiesAttack replay and adversary emulationScripting & AutomationPowerShellPythonBashAutomation and orchestration toolsPreferred CertificationsGCFA; GCIH; GNFA; GCFE; GCIA; CISSP; CCSP; SC-200; SC-100; AZ-500; AWS Security Specialty; CCD; Mobile forensic certifications; AI security or governance certificationsCore CompetenciesIncident ResponseThreat HuntingDigital ForensicsNetwork SecurityCloud SecurityMobile SecurityAI SecuritySecurity Appliance InvestigationAttack ReconstructionIncident Replay & Cyber Range OperationsTechnical Reporting