- Location
- Singapore
- Type
- Full-time
- Department
- Security
- Education
- Bachelor
- Closing date
- Today
- Source
- CareersPage
Description
Responsibilities
- Take command of major cyber incidents and own the end-to-end DFIR lifecycle — from detection and containment through eradication, recovery and post-incident review.
- Set and drive the Group's cyber defence and detection-and-response strategy, aligned to MAS TRM, NIST CSF v2.0 and ISO/IEC 27001:2022.
- Govern and optimise our SIEM, SOAR, EDR and DLP platforms to maximise detection coverage, efficacy and value.
- Lead detection engineering and proactive, intelligence-led threat hunting mapped to the MITRE ATT&CK framework.
- Shape our security telemetry and logging strategy, prioritising log source onboarding for comprehensive coverage.
- Build security automation and orchestration that make detection and response faster, more consistent and higher quality.
- Adopt and govern AI-enabled capabilities to strengthen security operations while keeping the right guardrails in place.
- Develop, maintain and regularly test incident response playbooks, runbooks and cyber crisis and tabletop exercises.
- Manage external forensic, MDR and threat-intelligence partners, including onboarding, performance and SLA oversight.
- Define, track and report detection-and-response metrics (such as MTTD and MTTR) to drive continuous improvement.
- Mentor analysts and engineers, sharing your expertise to build a high-performing, resilient and collaborative team.
- Support audits, regulatory engagements and executive/Board reporting, and represent Singlife in industry threat-sharing communities.
Requirements
- 8+ years in cyber security, with deep, hands-on expertise in DFIR, Detection Engineering, Threat Hunting, SIEM, SOAR, EDR, DLP, security automation and AI-enabled Security Operations.
- A proven track record leading major cyber incidents and complex forensic investigations from start to finish.
- Strong working knowledge of MAS TRM, NIST CSF v2.0, ISO/IEC 27001:2022 and the MITRE ATT&CK framework.
- Hands-on experience across cloud (AWS/Azure), endpoint, network and identity telemetry, detection-as-code and automation.
- Experience in a regulated financial services or insurance environment (strongly preferred).
- A Bachelor's degree in Computer Science, Information Security or a related field, or equivalent professional experience.
- One or more relevant certifications — CISSP, GCFA, GCIH, GNFA, GREM, GCTI or equivalent.
- Calm, decisive leadership under pressure, sharp analytical thinking, and the ability to translate technical risk clearly for management and stakeholders.
Skills
AWSAzureSIEMCISSP