About this role
Honeywell helps organizations solve the world's most complex challenges in automation, the future of aviation and energy transition. As a trusted partner, we provide actionable solutions and innovation through our Aerospace Technologies, Building Automation, Energy and Sustainability Solutions, and Industrial Automation business segments – powered by our Honeywell Forge software – that help make the world smarter, safer and more sustainable. THE FUTURE IS WHAT WE MAKE IT Senior Advance Cyber Security Architect/ Engineer Singapore, Singapore This position will be a part of the Industrial Cyber-Security team and will participate in delivering and developing cyber security services for a wide range of industrial global customers. The position will have a direct reporting relationship to the Global Security Operation Center Manager and work as part of a global managed services team. The position requires strong cyber security knowledge, excellent analytical & people management skills and proficient handling of specific tools such as SIEMs and Orchestration and Automation platforms. A successful candidate would be able to coordinate team members into evaluating security incidents or high-risk situations within an environment to provide clear, concise recommendations for customers before escalation to Global Security Operation Center Manager as needed. KEY RESPONSIBILITIES
• Create, implement and monitor utilization of standard processes for monitoring and incident response; • Creates manuals, guides and knowledge base entries; • Create reports and presentations for management and customers; • Monitor KPIs for deliverables; • Develop workflows and playbooks for different types of cyber threats analysis; • Assist forensic investigation by providing reports and other information; • Performs advanced investigations and data loss analysis; • Monitors SIEM, trouble tickets / email notifications and in-person escalations, logs from infrastructure components, applications or network devices such as firewalls, IDS/IPS; • Reviews and suggests improvements to control deployment process and installation procedures • Develops and documents remediation recommendations for business owners to improve the control environment in which a security incident occurs. Recommendations must be easily understood by non-technical staff; • Provide recommendations and direction on the tuning of signatures, rules, alerts, parsers, and custom scripts within the monitoring solutions; • Understand defense in depth strategies and apply those to Client’s environment; • Creates and disseminates security related notifications for internal staff (for example: trends, developments, changes in capabilities); • Hires, trains and mentors Level 1, 2 and 3 SOC Analysts, Experts and Consultants; • Acts as L4 Escalation layer in the SOC. • Oversees daily operational monitoring activities for team members; • Ensures team members are trained and follow established customer specific procedures as well as HPS ICS SOC internals policies; • Keep abreast of latest security and privacy legislation, emerging threats, regulations, advisories, alerts, and vulnerabilities pertaining to HPS ICS SOC and its customers; • Remains knowledgeable of our current solution portfolio and the technical specificities of our offerings. YOU MUST HAVE
• Bachelor’s degree in a computer related field such as Computer Science, Computer information systems or electronics; • Minimum of 5 years’ experience in cyber security SOC industry; • Minimum of 8 years’ experience in Information Technology; • Strong diagnostic and analytical skills including problem solving, trouble shooting, management of priorities and self-direction to resolve complex issues; • Effective written and verbal skill to enable strong communication capabilities; • Information Technology certifications: ITIL Foundations; • Security Certifications: CISSP, CCNA, Comptia Security+, GCIH, GCFA or CEH or other similar certifications; WE VALUE
• Ability to write documentation and summaries; • Mentoring, lead-by-example, conflict resolution; • Experience working in a client facing Cyber SOC environment; • Experience securing industrial or corporate networks and assets against cyber threats;