Digitial Forensic Incident Responder, Threat Intelligence & Repsonse Division
Sggovterp
·Today
- Location
- IMD - Mapletree Business City, MBC BLK 10, Singapore
- Type
- Full-time
- Department
- Human Resources
- Closing date
- Today
- Source
- Workday
Description
[What the role is]
This role sits within the Connectivity, Cybersecurity & Resilience Group(C2R) Group. C2R strengthens the cybersecurity and resilience posture of
the telecommunication and media sectors in Singapore.
The Group keeps Singapore’s digital connectivity secure,
trusted, and robust against an evolving and increasingly
complex threat landscape.
[What you will be working on]
- Work with team members to ensure smooth daily operations and tasks prioritisation and collaborate with stakeholders to ensure timely response to cybersecurity incidents from containment till closure.
- Investigate cybersecurity incidents to determine root cause, involving log and digital forensic analysis or malware analysis, and assess cybersecurity threats, vulnerabilities and exploits to provide strong technical guidance to investigation and threat assessments.
- Recommend preventive actions and mitigations against techniques used in incidents, as well as threat detection rules and signatures (e.g., Snort, Yara, Sigma) against cyber incidents or campaigns.
- Prepare and review incident reports to update stakeholders, and present incident briefings including attack techniques and malware behaviours observed, risk, impact, and address enquiries from various stakeholders.
- Review and update incident response playbooks, maintain processes, and uphold situational awareness by keeping current with cybersecurity trends, threats, and attacker Tactics, Techniques and Procedures (TTPs).
[What we are looking for]
- Background in Information Security, Computer Science, Engineering or equivalent
- 5 years or more of related work experience in cybersecurity incident investigations or digital forensics.
- Relevant professional certifications including GIAC GCFA, GREM, GCFE, or GCIH are highly regarded.
- Proficiency in forensic toolkits such as Magnet AXIOM, Encase, X-Ways, FTK, or Autopsy.
- Experience working in a Security Operation Centre (SOC) is advantageous.
- Strong analytical mindset with keen attention to detail, and good communication and interpersonal skills to engage effectively with diverse stakeholders.
- A growth mindset with a willingness to learn and stay ahead of the evolving cybersecurity landscape.
Skills
CybersecuritySOC