Job Responsibilities:
- Lead Security Operations and Incident Management, ensuring effective monitoring, investigation, escalation and response to cybersecurity events and incidents.
- Act as the senior escalation point for major and complex cyber incidents, coordinating technical teams and relevant stakeholders through containment, remediation and recovery.
- Lead root-cause analysis and post-incident reviews, identifying control, technology and process gaps and ensuring corrective actions are implemented.
- Drive continuous improvement of Incident Response frameworks, SOPs, playbooks and escalation processes.
- Oversee and strengthen SOC/Security Operations capabilities across monitoring, detection, investigation and response.
- Partner with Threat Intelligence, Threat Hunting, Infrastructure, Cloud, Application and Cybersecurity teams to improve detection and response capabilities.
- Support digital forensic investigations where required; deep forensic specialisation is advantageous but not mandatory.
- Identify opportunities to improve security operations through automation, SIEM, EDR/XDR, security analytics and emerging technologies.
- Lead cyber incident exercises and simulations to strengthen organisational readiness and resilience.
- Establish operational metrics and reporting covering incident trends, response effectiveness, root causes and areas of improvement.
- Lead, mentor and develop Cybersecurity Operations and Incident Response professionals.
- Engage senior management and business stakeholders during significant cybersecurity incidents and clearly communicate technical risks and business impact.
Requirements:
- Candidates should have experience managing significant cybersecurity incidents and a strong understanding of the end-to-end incident lifecycle, including investigation, containment, remediation, recovery and root-cause analysis.
- Experience leading a SOC, Security Operations, Cyber Defence or Incident Response team would be highly regarded.
- Good understanding of SIEM, EDR/XDR, security monitoring, threat detection and incident-response technologies, together with frameworks such as MITRE ATT&CK, Cyber Kill Chain and NIST CSF.
- Strong stakeholder management and communication skills, including the ability to coordinate multiple technical teams and communicate effectively with senior management during major incidents.
- Relevant certifications such as CISSP, GCIH, GCIA, GCFE, GREM or equivalent are advantageous.
Interested candidates who would like to explore this opportunity may apply by sending their your CV
Pam Lim
Morgan Mckinley Pte Ltd
EA Licence No: 11C5502 | EAP Registration No: R1106192
