inhousefyi
← Back to listings

Lead Cybersecurity Incident Response Specialist

GovTechSingapore, Singapore · Posted 2 months ago
Full-time
Apply now

Description

The Government Technology Agency (GovTech) is the lead agency driving Singapore’s Smart Nation initiatives and public sector digital transformation. As the Centre of Excellence for Infocomm Technology and Smart Systems (ICT & SS), GovTech develops the Singapore Government’s capabilities in Data Science & Artificial Intelligence, Application Development, Smart City Technology, Digital Infrastructure, and Cybersecurity.    

At GovTech, we offer you a purposeful career to make lives better. We empower our people to master their craft through continuous and robust learning and development opportunities all year round. Our GovTechies embody our Agile, Bold and Collaborative values to deliver impactful solutions.   GovTech aims to transform the delivery of Government digital services by taking an "outside-in" view, putting citizens and businesses at the heart of everything we do.   Play a part in Singapore’s vision to build a Smart Nation and embark on your meaningful journey to build tech for public good. Join us to advance our mission and shape your future with us today!    

Learn more about GovTech at tech.gov.sg.

Job Description

Join us and you will play a key role in the Cyber Defense Ops & Intelligence (CDOI) of Cyber Security Group (CSG) as Cybersecurity Operations Specialist (Incident Response) to manage and investigate cybersecurity incidents.

The successful candidate will ensure the delivery of cybersecurity operations services across all stages of the incident response lifecycle. This encompasses triaging potential security events, conducting in-depth investigations and advising on containment, eradication and recovery strategies. Candidate must possess strong log analysis and digital forensics skills to drive effective responses to cybersecurity incidents that ensure secure delivery of applications and infrastructure services. Critical thinking and great communication skills are required to articulate technical concepts and guide decision makers towards optimal courses of action. This is a key position in the Cyber Incident Response Team (CIRT).

What you will be working on:

  • Lead incident response activities through all phases of an incident:
  • Conduct triage and investigation of potential cybersecurity incidents to determine incident scope and severity
  • Develop and execute containment strategies
  • Perform investigations and root cause analysis to identify attack vectors, tactics, and impact
  • Conduct comprehensive security event log analysis to validate security detections, investigate alerts, and identify attacks across multiple data sources including:
  • Endpoint system logs or Endpoint detection and response (EDR) telemetry
  • Network traffic logs
  • Application logs
  • Cloud service logs and audit trails
  • Conduct digital forensic acquisition and analysis of artifacts from various sources including:
  • Endpoint systems and servers
  • Network devices and logs
  • Cloud environments
  • Mobile devices and storage media
  • Maintain clear stakeholder communication throughout incident lifecycle and prepare comprehensive post-incident reports with preventive recommendations
  • Provide expert input for automating Security Operations (E.g Implement SOAR playbooks)
  • Develop and test incident response playbooks and processes
  • Maintain situational awareness of cyber security landscape and emerging threat actor TTPs

What we are looking for:

  • Bachelor’s Degree in Computer Science/Information Security or equivalent
  • Professional certifications, including GCFA, GREM, GNFA, GCTI, CISSP or other relevant certifications will be preferred
  • Preferably 5 years or more of experience as a full-time incident responder/digital forensic/malware analysis or related discipline
  • Understanding of operating systems and platform (e.g. Windows, Linux) and knowledge of computer networking, LAN, and server
  • Strong ability with log analysis techniques, familiarity with platforms (e.g., Splunk, ELK Stack, Google SecOps) and analytical skills to correlate events across multiple log sources to identify attack patterns
  • Proficient in Forensic Tools such as AXIOM, FTK or Autopsy
  • Ability to perform basic static and dynamic malware analysis and to analyse network and application logs
  • Good working knowledge of Cloud and Container technologies are a plus
  • Familiarity with good security practices

Similar jobs

NebiusIsrael

About Nebius: Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from data and model training through to…

Full-time
TruvetaHyderabad, India

Truveta provides unprecedented real-world data and real-time intelligence, powered by a dataset built with and owned by US health systems united in a mission of Saving Lives with Data. Together, we power breakthrough med…

Full-time
TruvetaHyderabad, India

Truveta provides unprecedented real-world data and real-time intelligence, powered by a dataset built with and owned by US health systems united in a mission of Saving Lives with Data. Together, we power breakthrough med…

Full-time
GovTechSingapore, Singapore

GovTech supports various Government Agencies in carrying out ICT delivery services and appoints Agency Chief Information Security Officers (ACISO) to oversee information security management within these agencies. The ACI…

Full-time
GovTechSingapore, Singapore

[What the role is] GovTech is the lead agency driving Singapore’s Smart Nation initiatives and public

Full-time
TruvetaHyderabad, India

Truveta provides unprecedented real-world data and real-time intelligence, powered by a dataset built with and owned by US health systems united in a mission of Saving Lives with Data. Together, we power breakthrough med…

Full-time
CisionRemote

Est. 80,000 EUR

At Cision, we believe in empowering every individual to make an impact. Here, your voice is heard, your ideas are valued, and your unique perspective fuels our collective success. As part of our global team, you'll thriv…

Full-timeRemote
GovTechSingapore, Singapore

GovTech is the lead agency driving Singapore’s Smart Nation initiatives and public sector digital transformation. As the Centre of Excellence for Infocomm Technology and Smart Systems (ICT & SS), GovTech develops the…

Full-time
TruvetaHyderabad, India

Truveta provides unprecedented real-world data and real-time intelligence, powered by a dataset built with and owned by US health systems united in a mission of Saving Lives with Data. Together, we power breakthrough med…

Full-time
NebiusNew York, New York, United States

Est. 85,000 USD

About Nebius: Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from data and model training through to…

Full-time
GovTechSingapore, Singapore

Role Purpose The Deputy Director (DD), Government Incident Reporting Ops, leads a high-performing operational team responsible for centralizing, assessing, and managing the full spectrum of Whole-of-Government (WOG) inci…

Full-time
AgodaCairo, Egypt

About Agoda At Agoda, we bridge the world through travel. Our story began in 2005, when two lifelong friends and entrepreneurs, driven by their passion for travel, launched Agoda to make it easier for everyone to explore…

Full-time
Keyfactor, Inc.Stockholm, Sweden

Est. 840,000 SEK

About Keyfactor Our mission is to securely connect the world: humans, machines, and AI. Keyfactor is the leader in trust infrastructure for AI and machines, helping the world's largest enterprises and government agencies…

Full-time
AgodaBangkok, Thailand

About Agoda At Agoda, we bridge the world through travel. Our story began in 2005, when two lifelong friends and entrepreneurs, driven by their passion for travel, launched Agoda to make it easier for everyone to explore…

Full-time
GovTechSingapore, Singapore

To enhance infocomm security capabilities in GovTech and the whole-of-government, GovTech will be appointing Chief Security Information Officers (CISO) at the various ministries to oversee infocomm security management. T…

Full-time
NebiusFinland

Est. 55,000 EUR

About Nebius: Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from data and model training through to…

Full-time
Anduril IndustriesWaltham, Massachusetts, United States

Est. 124,000 USD

Anduril Industries is a defense technology company with a mission to transform U.S. and allied military capabilities with advanced technology. By bringing the expertise, technology, and business model of the 21st century…

Full-time
SpaceXHawthorne, California, United States

Est. 120,000 USD

SpaceX was founded under the belief that a future where humanity is out exploring the stars is fundamentally more exciting than one where we are not. Today SpaceX is actively developing the technologies to make this poss…

Full-time
Anduril IndustriesBroomfield, Colorado, United States

Est. 124,000 USD

Anduril Industries is a defense technology company with a mission to transform U.S. and allied military capabilities with advanced technology. By bringing the expertise, technology, and business model of the 21st century…

Full-time
Cato NetworksWarsaw, Masovian Voivodeship, Poland

Est. 120,000 PLN

Welcome to the future of cloud networking and security! Cato Networks is the first company to converge enterprise networking and security into one centralized and global service that is delivered by cloud. It is led by n…

Full-time
Cato NetworksAmsterdam, North Holland, Netherlands

Est. 90,000 EUR

Welcome to the future of cloud networking and security! Cato Networks is the first company to converge enterprise networking and security into one centralized and global service that is delivered by cloud. It is led by n…

Full-time
Data Scientist4 months ago
Cato NetworksTel Aviv, Tel Aviv District, Israel

Welcome to the future of cloud networking and security! Cato Networks is the first company to converge enterprise networking and security into one centralized and global service that is delivered by cloud. It is led by n…

Full-time

Est. 140,000 USD

Black Duck Software, Inc. helps organizations build secure, high-quality software, minimizing risks while maximizing speed and productivity. Black Duck, a recognized pioneer in application security, provides SAST, SCA, a…

Full-timeRemote
GSOC Operator1 month ago
AxonScottsdale, Arizona, United States

Est. 55,000 USD

Join Axon and be a Force for Good. At Axon, we’re on a mission to Protect Life. We’re explorers, pursuing society’s most critical safety and justice issues with our ecosystem of devices and cloud software. Like our produ…

Full-time
TruvetaHyderabad, India

Senior IT Engineer – Network & Endpoint Infrastructure Truveta provides unprecedented real-world data and real-time intelligence, powered by a dataset built with and owned by US health systems united in a mission of…

Full-time
Cato NetworksTel Aviv, Tel Aviv District, Israel

Welcome to the future of cloud networking and security! Cato Networks is the first company to converge enterprise networking and security into one centralized and global service that is delivered by cloud. It is led by n…

Full-time
PubMaticRedwood City, California, United States

Est. 250,000 USD

About the Role: PubMatic is seeking a Director of Information Security to lead and evolve our global security program across enterprise infrastructure, cloud platforms, products, corporate systems, and emerging AI techno…

Full-time
TruvetaHyderabad, India

Truveta provides unprecedented real-world data and real-time intelligence, powered by a dataset built with and owned by US health systems united in a mission of Saving Lives with Data. Together, we power breakthrough med…

Full-time
AnaplanGurugram, India

At Anaplan, we are a team of innovators focused on optimizing business decision-making through our leading AI-infused scenario planning and analysis platform so our customers can outpace their competition and the market.…

Full-time
IT Site Engineer13 days ago
SharkNinjaNeedham, Massachusetts, United States

Est. 95,000 USD

About Us SharkNinja is a global product design and technology company, with a diversified portfolio of 5-star rated lifestyle solutions that positively impact people’s lives in homes around the world. Powered by two trus…

Full-time