Reap

Security Engineer, Detection and Security Operations

Reap Hong Kong, Hong Kong Island, Hong Kong S.A.R.

Information Technology & Services · 201-500 employees

5 h ago
security Senior (5-10 yrs) Full-time Singapore
Log in to apply, save this posting, or score it against your profile with AI.

About the role

You will build the company's detection infrastructure from scratch, including SIEM deployment, log ingestion, and rule development. You will also own the alert triage process and operationalize threat intelligence to protect against complex security threats.

What they look for

SIEM Detection engineering AWS CloudTrail CrowdStrike Okta Python KQL SPL Threat intelligence Incident response MITRE ATT&CK Log aggregation Security operations Cloud security Data exfiltration detection

Requirements

The role requires hands-on experience in building detection rules, managing SIEM platforms like Sentinel or Splunk, and proficiency in Python for security automation. Candidates must have a strong background in log source integration and translating threat intelligence into actionable security controls.

Benefits

Annual leave Health insurance budget Flexible remote work options Home office equipment budget Corporate Reap Card

Full description

About Reap

Reap is a leading global payment technology provider that enables financial connectivity and access for businesses worldwide. By merging traditional finance with digital assets, bridging disparate economies, and connecting key financial players, we are transforming the financial landscape into a more interconnected and interoperable space for efficient money movement.

With stablecoin‑enabled corporate cards, payout solutions, and expense management tools, we streamline financial operations and empower businesses to scale. Our APIs enable businesses to embed finance into their own products and services, from issuing Visa cards to facilitating cross‑border payments.

Reap is supported by a strong network of investors, including Acorn Pacific Ventures, Arcadia Funds, HashKey Capital, Hustle Fund, Fresco Capital, Abacus Ventures, and Payment Asia.

Founded in 2018

Security at Reap

Reap builds financial connectivity for a multi‑rail world-traditional finance, stablecoins, and real‑time payments. Security is foundational to that mission. We're looking for a pragmatic engineer who can turn regulation into robust systems, and complex threats into clear controls. You'll partner with Engineering, Risk, and Operations to keep value moving safely, globally, and 24/7.

Your Mission

A state-sponsored threat actor (Lazarus Group, DPRK) was inside one of our colleague's endpoints for seven months before we detected it. The reason is straightforward: we had no SIEM, no centralised log aggregation, and no detection rules. You are the hire that makes sure it cannot happen again.

As our Detection Engineering and Security Operations lead, you will build our detection infrastructure from scratch: evaluate and deploy our SIEM, ingest every relevant log source, write the rules that catch the specific

TTPs we know from confirmed incidents, and own the alert pipeline that connects telemetry to a human decision.

What You Will Do

  • Own the SIEM platform from evaluation through to a production detection capability: choose the platform, drive ingestion from CrowdStrike, AWS CloudTrail, Okta, M365, and our SaaS applications, and build the detection rule library.
  • Write detection rules for the TTPs we know are relevant to Reap: Lazarus Group C2 beaconing, credential harvesting, lateral movement, social engineering patterns from the KAST incident, cloud misconfiguration exposure events, and AI platform data exfiltration anomalies.
  • Own the alert triage and escalation process: define SLAs, reduce false positive rates, and build the handoff protocol to the Crypto/IR Security Engineer when an alert becomes a confirmed incident.
  • Operationalise threat intelligence: consume feeds, extract relevant IOCs and TTPs, and translate them into detection rules on a defined cadence.
  • Build the security metrics infrastructure: the dashboards and automated reports that feed the CISO board pack with mean detection time, mean response time, alert volume, and coverage gaps.
  • Support CrowdStrike Falcon Complete configuration: customise detection logic for our environment and own the response workflow when Falcon generates a critical alert.
  • Build AI-related detection rules: bulk Snowflake exports followed by AI platform uploads, anomalous SaaS traffic volumes, shadow AI usage.

Your Superpowers

  • You have built detection rules from scratch, not just operated a pre-configured platform. SIEM

platform experience in Microsoft Sentinel, Splunk, or Elastic. KQL or SPL proficiency.

  • You can translate a MITRE ATT&CK profile into a testable detection rule. We have a confirmed Lazarus Group incident and a confirmed social engineering incident. You know how to build rules that would have caught them.
  • Hands-on log source integration. AWS CloudTrail, Okta system logs, CrowdStrike event stream, M365

audit logs. You have connected these to a SIEM and normalised the data yourself.

  • Alert triage experience. You have investigated your own alerts. You understand the difference between a detection engineer who builds rules and one who also knows if they work.
  • Python for security automation. Log parsing, alert enrichment, automated response workflows.

Nice to Have

  • Microsoft Sentinel specifically, given our M365 licensing.
  • CrowdStrike Falcon event stream integration and custom IOA rules.
  • Knowledge of Lazarus Group TTPs from prior threat intelligence or incident response experience.
  • SOAR platform experience (Sentinel Playbooks, Splunk SOAR).
  • GIAC GCIA, GDAT, Microsoft SC-200, or CrowdStrike CCFA certification.

Why You Will Love It Here

  • You will build Reap's detection capability from a blank page, with a confirmed threat actor profile to build

against. The scope and impact of this role are unusually clear.

  • You will work directly with the CISO and alongside a team of engineers with deep specialisms in crypto

security and application security.

  • We are an AI-first company and that extends to how we think about security. You will build the detection

rules that catch AI data leakage, not just traditional threats.

  • APAC-friendly hours, remote-first, and a company mid-acquisition by one of the largest crypto exchanges in the world.

Benefits you'll enjoy

  • A vibrant, inclusive work culture.
  • Annual leave to relax and recharge, plus public holidays.
  • Health insurance budget.
  • Be part of a fast‑growing global team.
  • Flexible remote work options.
  • Home office equipment budget.
  • Your own Corporate Reap Card-no more out‑of‑pocket spending.

About Reap

Reap is a leading global payment technology provider that enables financial connectivity and access for businesses worldwide. By merging traditional finance with digital assets, bridging disparate economies, and connecting key financial players, we are transforming the financial landscape into a more interconnected and interoperable space for efficient money movement.

With stablecoin‑enabled corporate cards, payout solutions, and expense management tools, we streamline financial operations and empower businesses to scale. Our APIs enable businesses to embed finance into their own products and services, from issuing Visa cards to facilitating cross‑border payments.

Reap is supported by a strong network of investors, including Acorn Pacific Ventures, Arcadia Funds, HashKey Capital, Hustle Fund, Fresco Capital, Abacus Ventures, and Payment Asia.

Founded in 2018 Coworkers 300+

Similar roles