← WorkMundi · 1M+ jobs from around the world, liveSign inCreate free account

Security Engineer, Detection and Security Operations

REAP Limited · Hong Kong SAR

🌐 Remote📅 12/08/2026
🔔 Alert me about jobs like this
No password, no sign-up. Just the email — and you can leave the list anytime.
🔓 Apply — free →
Opens this job on WorkMundi. The account is free and takes under a minute.

See the other 7,066 jobs in Hong Kong →

🎁 Before you apply, rehearse this interview. Create your free WorkMundi account and get an Interview Training on HelpsYouSpeak — no cost, no card. I want my training →
Founded in 2018 Security at Reap Reap builds financial connectivity for a multi‑rail world-traditional finance, stablecoins, and real‑time payments. Security is foundational to that mission. We're looking for a pragmatic engineer who can turn regulation into robust systems, and complex threats into clear controls. You'll partner with Engineering, Risk, and Operations to keep value moving safely, globally, and 24/7. Your Mission A state-sponsored threat actor (Lazarus Group, DPRK) was inside one of our colleague's endpoints for seven months before we detected it. The reason is straightforward: we had no SIEM, no centralised log aggregation, and no detection rules. You are the hire that makes sure it cannot happen again. As our Detection Engineering and Security Operations lead, you will build our detection infrastructure from scratch: evaluate and deploy our SIEM, ingest every relevant log source, write the rules that catch the specific TTPs we know from confirmed incidents, and own the alert pipeline that connects telemetry to a human decision. What You Will Do • Own the SIEM platform from evaluation through to a production detection capability: choose the platform, drive ingestion from CrowdStrike, AWS CloudTrail, Okta, M365, and our SaaS applications, and build the detection rule library. • Write detection rules for the TTPs we know are relevant to Reap: Lazarus Group C2 beaconing, credential harvesting, lateral movement, social engineering patterns from the KAST incident, cloud misconfiguration exposure events, and AI platform data exfiltration anomalies. • Own the alert triage and escalation process: define SLAs, reduce false positive rates, and build the handoff protocol to the Crypto/IR Security Engineer when an alert becomes a confirmed incident. • Operationalise threat intelligence: consume feeds, extract relevant IOCs and TTPs, and translate them into detection rules on a defined cadence. • Build the security metrics infrastructure: the dashboards and automated reports that feed the CISO board pack with mean detection time, mean response time, alert volume, and coverage gaps. • Support CrowdStrike Falcon Complete configuration: customise detection logic for our environment and own the response workflow when Falcon generates a critical alert. • Build AI-related detection rules: bulk Snowflake exports followed by AI platform uploads, anomalous SaaS traffic volumes, shadow AI usage. Your Superpowers • You have built detection rules from scratch, not just operated a pre-configured platform. SIEM platform experience in Microsoft Sentinel, Splunk, or Elastic. KQL or SPL proficiency. • You can translate a MITRE ATT&CK profile into a testable detection rule. We have a confirmed Lazarus Group incident and a confirmed social engineering incident. You know how to build rules that would have caught them. • Hands-on log source integration. AWS CloudTrail, Okta system logs, CrowdStrike event stream, M365 audit logs. You have connected these to a SIEM and normalised the data yourself. • Alert triage experience. You have investigated your own alerts. You understand the difference between a detection engineer who builds rules and one who also knows if they work. • Python for security automation. Log parsing, alert enrichment, automated response workflows. Nice to Have • Microsoft Sentinel specifically, given our M365 licensing. • CrowdStrike Falcon event stream integration and custom IOA rules. • Knowledge of Lazarus Group TTPs from prior threat intelligence or incident response experience. • SOAR platform experience (Sentinel Playbooks, Splunk SOAR). • GIAC GCIA, GDAT, Microsoft SC-200, or CrowdStrike CCFA certification. Why You Will Love It Here • You will build Reap's detection capability from a blank page, with a confirmed threat actor profile to build against. The scope and impact of this role are unusually clear. • You will work directly with the CISO and alongside a team of engineers with deep specialisms in crypto security and application security. • We are an AI-first company and that extends to how we think about security. You will build the detection rules that catch AI data leakage, not just traditional threats. • APAC-friendly hours, remote-first, and a company mid-acquisition by one of the largest crypto exchanges in the world. Benefits you'll enjoy A vibrant, inclusive work culture. Annual leave to relax and recharge, plus public holidays. Health insurance budget. Be part of a fast‑growing global team. Flexible remote work options. Home office equipment budget. Your own Corporate Reap Card-no more out‑of‑pocket spending.
Read the rest of the job →
For people searching Engineer

144,883 engineer jobs are open right now

Here's how to pick the right one and stand out in your application.

144.883Jobs
31.687IN
81%EN

That number is real. WorkMundi's database shows 144,883 open engineer roles across the world. India has the most with 31,687 jobs, followed by the United States with 30,084. If you just finished reading one job ad and felt paralyzed by choice, you're not alone—but this scale is actually an advantage. It means you can afford to be selective.

Start by geography and language. The majority of engineer ads—117,837 of them—have the job posting text written in English. Use that as one filter, but remember: the ad text language tells you nothing about whether the role actually requires you to speak English day-to-day. Read the job description carefully. Then check which countries have the volume you're targeting. Singapore, Poland, and Australia round out the top five after India and the US.

Next, learn who's hiring. Accenture has posted 2,801 engineer roles. andurilindustries, speechify, and jobgether are also actively recruiting. If you're applying to one of these names, research their hiring patterns and interview style before you apply. That homework pays off.

When you interview, expect the question every engineer hears: 'Tell me about a time you had to debug a problem that wasn't in your job description.' Have a specific story ready—not a general one. Name the tools, the deadline pressure, and what you learned. Hiring managers listen for whether you see problem-solving as part of the role itself, not a favour.

👁 21 have read this
0 comments
Want to comment?

Leave your e-mail to comment, react and follow the posts for your role. It is free.

Similar jobs

Job on WorkMundi — the world's largest job board. See more jobs from every continent, updated live.

📢
🎁

Before you apply, rehearse this interview.

Create your free WorkMundi account and get an Interview Training on HelpsYouSpeak — no cost, no card.

I want my training →