Free with a WorkJio account: we compare your profile with this job and show what you already meet.
Share with a friend
Start
Not stated
Work mode
On-site
Experience
Experienced
About the role
This role leads the organisation's cyber defence capabilities across security operations, vulnerability management, threat hunting and digital forensics and incident response, using AI to make them intelligence-led and measurable. You will report to the CISO Office and work with internal teams and external partners to protect Singtel Digital InfraCo. It suits an experienced cybersecurity leader who can inspire others, solve problems and keep learning.
What you'll do
Lead 24x7 Security Operations Centre operations, including any managed security service provider or MDR partner, so events are monitored, triaged, escalated and resolved within agreed service levels.
Own the SOC operating model and its processes, such as tiered analyst structure, shift roster, playbooks, runbooks and escalation matrix, and drive measurable maturity improvement using AI.
Drive detection engineering across SIEM, EDR/XDR, identity and cloud-native security tooling, developing, tuning and retiring use cases mapped to MITRE ATT&CK to raise coverage and cut false positives.
Ensure log source coverage across critical assets including endpoints, servers and networks.
Oversee SOAR automation to speed up alert enrichment, triage and containment.
Define and report SOC KPIs and KRIs, such as MTTD, MTTR, ATT&CK coverage, alert severity and SLA adherence, to the CISO and senior management.
Lead the response to critical zero-day and emerging vulnerabilities, including rapid exposure assessment, compensating controls and emergency patching coordination.
Establish and lead a structured, hypothesis-driven threat hunting programme based on threat intelligence, MITRE ATT&CK and anomalies in environment telemetry.
Develop hypotheses and techniques and run hunts to find undetected threats, turning findings into new or improved detections.
Gather and analyse cyber threat information from commercial feeds, government sources such as CSA or Sectoral Lead, and open sources to derive insights on attack tactics, techniques and procedures, campaigns and threat actor profiles relevant to the organisation and its sector.
Operationalise threat intelligence, including IOC ingestion and management of the threat intelligence platform.
Act as a security incident responder for cyber incidents, coordinating technical response, containment, eradication and recovery across internal teams and external partners.
Manage vendor relationships, contracts and performance for MSSP/MDR, IR retainer, maintenance of the cybersecurity technology stack and security tooling providers, and plan and manage the cyber defence budget.
Present the organisation's threat landscape, incident trends and cyber defence posture to the CISO.
Support internal and external audits and regulatory inspections by providing evidence of control design and operating effectiveness.
Coordinate proactively with technical and business stakeholders and manage internal and external partnerships during a security inc
Requirements
Degree in Computer Science, Information Technology, Cybersecurity or a related discipline
At least 5 years of cybersecurity experience, with substantial hands-on SOC operations, incident response and digital forensics work
At least 3 years leading a team
Proven track record leading response to significant incidents such as ransomware, targeted intrusions or data breaches, from detection through recovery and post-incident review
Hands-on expertise with SIEM platforms such as Elastic, Microsoft Sentinel, Google SecOps or QRadar
Hands-on expertise with EDR/XDR platforms such as CrowdStrike, Microsoft Defender, Trend Micro or Trellix
Jio can write this application for you
Jio reads this job and your profile, then writes a short letter in your words. You read it, change anything, and send it yourself. Nothing is sent until you say so.