Take command of major cyber incidents and own the end-to-end DFIR lifecycle - from detection and containment through eradication, recovery and post-incident review.
Set and drive the Group's cyber defence and detection-and-response strategy, aligned to MAS TRM, NIST CSF v2.0 and ISO/IEC 27001:2022.
Govern and optimise our SIEM, SOAR, EDR and DLP platforms to maximise detection coverage, efficacy and value.
Lead detection engineering and proactive, intelligence-led threat hunting mapped to the MITRE ATT&CK framework.
Shape our security telemetry and logging strategy, prioritising log source onboarding for comprehensive coverage.
Build security automation and orchestration that make detection and response faster, more consistent and higher quality.
Adopt and govern AI-enabled capabilities to strengthen security operations while keeping the right guardrails in place.
Develop, maintain and regularly test incident response playbooks, runbooks and cyber crisis and tabletop exercises.
Manage external forensic, MDR and threat-intelligence partners, including onboarding, performance and SLA oversight.
Define, track and report detection-and-response metrics (such as MTTD and MTTR) to drive continuous improvement.
Mentor analysts and engineers, sharing your expertise to build a high-performing, resilient and collaborative team.
Support audits, regulatory engagements and executive/Board reporting, and represent Singlife in industry threat-sharing communities.
Requirements
5+ years in cyber security, with deep, hands-on expertise in DFIR, Detection Engineering, Threat Hunting, SIEM, SOAR, EDR, DLP, security automation and AI-enabled Security Operations.
A proven track record leading major cyber incidents and complex forensic investigations from start to finish.
Strong working knowledge of MAS TRM, NIST CSF v2.0, ISO/IEC 27001:2022 and the MITRE ATT&CK framework.
Hands-on experience across cloud (AWS/Azure), endpoint, network and identity telemetry, detection-as-code and automation.
Experience in a regulated financial services or insurance environment (strongly preferred).
A Bachelor's degree in Computer Science, Information Security or a related field, or equivalent professional experience.
One or more relevant certifications - CISSP, GCFA, GCIH, GNFA, GREM, GCTI or equivalent.
Calm, decisive leadership under pressure, sharp analytical thinking, and the ability to translate technical risk clearly for management and stakeholders.