- Location
- HDB HUB, Singapore
- Type
- Full-time
- Department
- Security
- Experience
- 2+ years
- Closing date
- Today
- Source
- Workday
Description
[What the role is]
As members of our Security Operations Centre (SOC) Team, you will be at the forefront of cybersecurity defence, playing a critical role in safeguarding HDB's ICT infrastructure. Whether delivering timely and actionable threat intelligence to help the organisation anticipate, detect and respond effectively to evolving cyber threats, or engineering and maintaining a robust security operations capability by equipping the SOC with the right tools, platforms and technologies, you will be an integral part of a team dedicated to keeping HDB's digital environment secure.[What you will be working on]
Cyber Threat Intelligence Analysis
Continuously review and enhance the cyber intelligence framework to provide a systematic and organized framework for collecting, processing, and leveraging intelligence to enhance HDB's cybersecurity posture and decision-making capabilities.
Integrate the cyber intelligence framework with the HDB's Security Operations Centre (SOC) and incident response team and ensure that the intelligence gathered is effectively used to detect, prevent, and respond to cyber threats.
Continuously monitor and collect information from multiple sources, including threat intelligence feeds, security vendors, dark web forums, social media, and other online platforms, to identify emerging cyber threats and attack trends.
Analyse the collected threat intelligence data to identify patterns, trends, and potential cybersecurity risks.
Prioritize and triage threats based on their relevance and potential impact to HDB.
Conduct in-depth analysis of threat actors, their motivations, capabilities, and tactics, and provide insights on potential risks and impacts to the organization's systems, networks, and data.
Produce regular and ad-hoc reports, briefings, and alerts on emerging threats, trends, and risk assessments to relevant stakeholders, including senior management, incident response teams, and other cybersecurity teams. The report shall also provide technical information in a clear and actionable format for various stakeholders.
Provide timely and accurate intelligence support on a rostered 24/7 standby duty, and when activated during security incidents, assist incident response teams in understanding the nature and scope of the threat, and provide guidance on containment, remediation and recovery strategies.
Support vulnerability management efforts by analysing threat intelligence data to identify vulnerabilities, exploit trends, and potential targets, and prioritize patching and mitigation activities.
SOC Engineering
Research and evaluate new and emerging security tools, platforms and technologies, and assess their technical feasibility and suitability for integration into the organisation's existing security infrastructure and workflows.
Liaise with product vendors to conduct Proof-of-Concept (POC) and technical evaluation of security tools, platforms and technologies.
Responsible for the procurement and implementation of security tools, platforms and technologies.
Perform knowledge transfer, prepare documentation, and hand over the operations of newly implemented security tools, platforms and technologies to the Security Operations team.
Process Innovation and Automation
Design and refine SOC processes and procedures to enhance operational efficiency and reduce response times.
Implement automation and artificial intelligence solutions to optimise SOC operations, improve threat detection and response capabilities.
Professional Development and Cross-Functional Collaboration
Participate in diverse SOC activities including security monitoring, threat hunting and incident response to broaden your expertise and accelerate career development within HDB's growing cybersecurity function.
[What we are looking for]
Have demonstrable experience and in-depth knowledge in cyber threat intelligence analysis and SOC engineering.
Possess strong experience with various cybersecurity technologies including IDS/IPS, firewalls, SIEM platforms, email security, web security, cloud security, and endpoint security solutions.
Have at least 2 years of experience as an engineer and/or cyber intelligence analyst in a SOC environment or equivalent cybersecurity engineering/operations role.
Demonstrate strong analytical and problem-solving skills with meticulous attention to detail.
Can work effectively under pressure, meet critical deadlines, and make sound decisions during security incidents.
Strong written and verbal communication skills, with ability to explain technical concepts to diverse stakeholders across the organisation.
Have experience in cyber intelligence analysis, implementation of security monitoring and detection solutions, and project management.
Hold professional certifications such as EC-Council Certified Threat Intelligence Analyst (CTIA), SIEM, SOAR and XDR/EDR product certifications, or other relevant cybersecurity qualifications.
Good to Have:
Exceptional attention to detail and commitment to quality in all security operations.
Proven ability to work autonomously while maintaining high standards of reliability, trustworthiness, and integrity.
Natural sense of ownership and accountability, taking initiative to drive continuous improvement in security processes.
Collaborative mindset with ability to work effectively across cross-functional teams.
Knowledge of cloud security frameworks and experience with modern security orchestration tools.
Successful candidates will be offered a 1+1 year contract in the first instance.