Reap

Security Engineer, Detection and Security Operations

Reap  •  Singapore, SG (Onsite)  •  4 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

About Reap

Reap is a leading global payment technology provider that enables financial connectivity and access for businesses worldwide. By merging traditional finance with digital assets, bridging disparate economies, and connecting key financial players, we are transforming the financial landscape into a more interconnected and interoperable space for efficient money movement.

With stablecoin‑enabled corporate cards, payout solutions, and expense management tools, we streamline financial operations and empower businesses to scale. Our APIs enable businesses to embed finance into their own products and services, from issuing Visa cards to facilitating cross‑border payments.

Reap is supported by a strong network of investors, including Acorn Pacific Ventures, Arcadia Funds, HashKey Capital, Hustle Fund, Fresco Capital, Abacus Ventures, and Payment Asia.

Founded in 2018

Security at Reap

Reap builds financial connectivity for a multi‑rail world-traditional finance, stablecoins, and real‑time payments. Security is foundational to that mission. We're looking for a pragmatic engineer who can turn regulation into robust systems, and complex threats into clear controls. You'll partner with Engineering, Risk, and Operations to keep value moving safely, globally, and 24/7.

Your Mission

A state-sponsored threat actor (Lazarus Group, DPRK) was inside one of our colleague's endpoints for seven months before we detected it. The reason is straightforward: we had no SIEM, no centralised log aggregation, and no detection rules. You are the hire that makes sure it cannot happen again.

As our Detection Engineering and Security Operations lead, you will build our detection infrastructure from scratch: evaluate and deploy our SIEM, ingest every relevant log source, write the rules that catch the specific

TTPs we know from confirmed incidents, and own the alert pipeline that connects telemetry to a human decision.

What You Will Do

• Own the SIEM platform from evaluation through to a production detection capability: choose the platform, drive ingestion from CrowdStrike, AWS CloudTrail, Okta, M365, and our SaaS applications, and build the detection rule library.

• Write detection rules for the TTPs we know are relevant to Reap: Lazarus Group C2 beaconing, credential harvesting, lateral movement, social engineering patterns from the KAST incident, cloud misconfiguration exposure events, and AI platform data exfiltration anomalies.

• Own the alert triage and escalation process: define SLAs, reduce false positive rates, and build the handoff protocol to the Crypto/IR Security Engineer when an alert becomes a confirmed incident.

• Operationalise threat intelligence: consume feeds, extract relevant IOCs and TTPs, and translate them into detection rules on a defined cadence.

• Build the security metrics infrastructure: the dashboards and automated reports that feed the CISO board pack with mean detection time, mean response time, alert volume, and coverage gaps.

• Support CrowdStrike Falcon Complete configuration: customise detection logic for our environment and own the response workflow when Falcon generates a critical alert.

• Build AI-related detection rules: bulk Snowflake exports followed by AI platform uploads, anomalous SaaS traffic volumes, shadow AI usage.

Your Superpowers

• You have built detection rules from scratch, not just operated a pre-configured platform. SIEM

platform experience in Microsoft Sentinel, Splunk, or Elastic. KQL or SPL proficiency.

• You can translate a MITRE ATT&CK profile into a testable detection rule. We have a confirmed Lazarus Group incident and a confirmed social engineering incident. You know how to build rules that would have caught them.

• Hands-on log source integration. AWS CloudTrail, Okta system logs, CrowdStrike event stream, M365

audit logs. You have connected these to a SIEM and normalised the data yourself.

• Alert triage experience. You have investigated your own alerts. You understand the difference between a detection engineer who builds rules and one who also knows if they work.

• Python for security automation. Log parsing, alert enrichment, automated response workflows.

Nice to Have

• Microsoft Sentinel specifically, given our M365 licensing.

• CrowdStrike Falcon event stream integration and custom IOA rules.

• Knowledge of Lazarus Group TTPs from prior threat intelligence or incident response experience.

• SOAR platform experience (Sentinel Playbooks, Splunk SOAR).

• GIAC GCIA, GDAT, Microsoft SC-200, or CrowdStrike CCFA certification.

Why You Will Love It Here

• You will build Reap's detection capability from a blank page, with a confirmed threat actor profile to build

against. The scope and impact of this role are unusually clear.

• You will work directly with the CISO and alongside a team of engineers with deep specialisms in crypto

security and application security.

• We are an AI-first company and that extends to how we think about security. You will build the detection

rules that catch AI data leakage, not just traditional threats.

• APAC-friendly hours, remote-first, and a company mid-acquisition by one of the largest crypto exchanges in the world.

Benefits you'll enjoy

  • A vibrant, inclusive work culture.

  • Annual leave to relax and recharge, plus public holidays.

  • Health insurance budget.

  • Be part of a fast‑growing global team.

  • Flexible remote work options.

  • Home office equipment budget.

  • Your own Corporate Reap Card-no more out‑of‑pocket spending.

About Reap

Reap is a leading global payment technology provider that enables financial connectivity and access for businesses worldwide. By merging traditional finance with digital assets, bridging disparate economies, and connecting key financial players, we are transforming the financial landscape into a more interconnected and interoperable space for efficient money movement.

With stablecoin‑enabled corporate cards, payout solutions, and expense management tools, we streamline financial operations and empower businesses to scale. Our APIs enable businesses to embed finance into their own products and services, from issuing Visa cards to facilitating cross‑border payments.

Reap is supported by a strong network of investors, including Acorn Pacific Ventures, Arcadia Funds, HashKey Capital, Hustle Fund, Fresco Capital, Abacus Ventures, and Payment Asia.

Founded in 2018 Coworkers 300+

Reap

About Reap

Reap is a leading global payment technology provider that enables financial connectivity and access for businesses worldwide. By merging traditional finance with digital assets, bridging disparate economies, and connecting key financial players, we are transforming the financial landscape into a more interconnected and interoperable space for efficient money movement.

With stablecoin-enabled corporate cards, payout solutions, and expense management tools, we streamline financial operations and empower businesses to scale. Our APIs enable businesses to embed finance into their own products and services, from issuing Visa cards to facilitating cross-border payments.

Reap is supported by a strong network of investors, including Acorn Pacific Ventures, Arcadia Funds, HashKey Capital, Hustle Fund, Fresco Capital, Abacus Ventures, and Payment Asia. Founded in 2018 in Hong Kong, we have since expanded to a team of over 100 across the globe.

Industry
Unknown
Company Size
201-500 employees
Headquarters
Global, HK
Year Founded
2018
Social Media