AI Cyber Defence Specialist

Singtel Group

Singapore

On-site

SGD 120,000 - 190,000

Full time

6 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Singtel Group invites an AI Cyber Defence Specialist to lead threat management across SOC, vulnerability, threat hunting, and DFIR. The role reports to the CISO Office and emphasizes intelligence-led, AI-enabled security aligned with regulatory expectations.

You will oversee SOC operations, drive MITRE ATT&CK-aligned detections, and manage MSSP/MDR partners while coordinating with internal and external stakeholders during incidents.

Qualifications

  • Bachelor's degree in Computer Science, IT, Cybersecurity or related field.
  • Minimum 5 years in cybersecurity with hands-on SOC, IR, and DFIR experience.
  • Proven incident response leadership for major incidents (ransomware, data breaches).

Responsibilities

  • Lead 24x7 SOC operations including MSSP/MDR partners with defined SLAs.
  • Own SOC model: playbooks, escalation matrix, and process improvements with AI.
  • Drive detection engineering across SIEM/EDR/XDR; map use cases to MITRE ATT&CK.
  • Ensure log source coverage for endpoints, servers, and networks.
  • Oversee SOAR automation for enrichment, triage, and containment.
  • Define and report SOC KPIs/KRIs to CISO and management.
  • Lead response to zero-day and emerging vulnerabilities; coordinate patches.
  • Structured threat hunting using threat intel, MITRE ATT&CK, telemetry.
  • Develop hypotheses and hunts; translate findings into detections.
  • Gather intel from commercial/government/open sources; derive TTPs.
  • Operationalise threat intel; manage IOC ingestion and TIP.
  • Act as security incident responder across internal and external teams.
  • Manage MSSP/MDR vendors, IR retainers, budgets; ensure tooling efficacy.
  • Present threat landscape and trends to CISO.
  • Support audits/regulatory inspections with evidence of controls.
  • Coordinate with stakeholders during security incidents; manage partnerships.
  • Other duties as business requirements evolve.

Skills

Analytical
Problem Solving
Independent Working
On-call Readiness

Education

Bachelor's degree in Computer Science / IT / Cybersecurity

Tools

Elastic
Microsoft Sentinel
Google SecOps
QRadar
CrowdStrike
Microsoft Defender
Tenable Nessus

Job description

Select how often (in days) to receive an alert:

We are seeking an Artificial Intelligence (AI) Cyber Defence Specialist to lead the organisation’s threat management capabilities across Security Operations, Vulnerability Management, Threat Hunting and Digital Forensics & Incident Response (DFIR) by leveraging AI.

Reporting to the CISO Office, the candidate will be accountable for the responsibilities as stated below. The candidate will ensure these capabilities are intelligence-led using AI, measurable and aligned with applicable regulatory and industry expectations, including (but not limited to) the Cybersecurity Act and applicable Cybersecurity Codes of Practice (CCoP).

Roles and Responsibilities:
  • Lead and manage the 24x7 Security Operations Centre (SOC) operations, including any Managed Security Service Provider (MSSP) or MDR partner, ensuring security events are monitored, triaged, escalated and resolved within defined Service Level Agreements (SLAs).
  • Own the SOC operating model and its associated processes – tiered analyst structure, shift roster, playbooks, runbooks and escalation matrix – and drive measurable improvement in SOC maturity using AI.
  • Drive detection engineering across SIEM, EDR/XDR, identity and cloud-native security tooling; develop, tune and retire use cases mapped to MITRE ATT&CK to increase detection coverage and reduce false positives.
  • Ensure log source coverage across critical assets – endpoints, servers and networks.
  • Oversee SOAR automation to accelerate alert enrichment, triage and containment actions.
  • Define and report SOC KPIs and KRIs (e.g. MTTD, MTTR, ATT&CK coverage, alert severity, SLA adherence) to the CISO and senior management.
  • Lead the organisation’s response to critical zero-day and emerging vulnerabilities, including rapid exposure assessment, compensating controls and emergency patching coordination.
  • Establish and lead a structured, hypothesis-driven threat hunting programme based on threat intelligence, MITRE ATT&CK and anomalies observed in environment telemetry.
  • Develop hypotheses and techniques and execute hunts to identify undetected threats across the environment; convert hunt findings into new or improved detections.
  • Gather and analyse cyber threat information and intelligence from commercial feeds, government sources (e.g. CSA / Sectoral Lead) and open sources to derive insights on attack tactics, techniques and procedures (TTPs), campaigns and threat actor profiles relevant to the organisation and its sector.
  • Operationalise threat intelligence, including IOC ingestion and management of the threat intelligence platform (TIP).
  • Act as a security incident responder for cyber incidents, coordinating technical response, containment, eradication and recovery across internal teams and external partners.
  • Manage vendor relationships, contracts and performance for MSSP/MDR, IR retainer, maintenance of the cybersecurity technology stack and security tooling providers; plan and manage the cyber defence budget.
  • Present the organisation’s threat landscape, incident trends and cyber defence posture to the CISO.
  • Support internal and external audits and regulatory inspections, providing evidence of control design and operating effectiveness.
  • Proactively coordinate with technical and business stakeholders and manage internal and external partnerships during a security incident.
  • Any other assigned duties when there is a change in business requirements and scope of work.
What we’re looking for...

You embrace continuous learning and use lessons from challenges to improve future outcomes. You can inspire and motivate others to deliver the organisation’s vision. You view obstacles as problems to be solved. You are driven by the desire to deliver positive outcomes for your internal customer – Singtel Digital InfraCo.

What you need to have:
  • A degree in Computer Science, Information Technology, Cybersecurity or a related discipline.
  • At least 5 years of cybersecurity experience, with substantial hands-on experience in SOC operations, incident response and digital forensics, including at least 3 years leading a team.
  • Proven track record of leading the response to significant incidents (e.g. ransomware, targeted intrusions, data breaches) from detection through to recovery and post-incident review.
  • Hands-on expertise with SIEM (e.g. Elastic, Microsoft Sentinel, Google SecOps, QRadar), EDR/XDR (e.g. CrowdStrike, Microsoft Defender, Trend Micro, Trellix), and SOAR platforms.
  • Experience with vulnerability management platforms (e.g. Tenable Nessus) and risk-based prioritisation approaches.
  • Highly analytical, with strong attention to detail and outstanding problem-solving skills; able to work independently and under pressure in a fast-paced environment.
  • Willingness to be on call and respond outside office hours during major incidents and/or as and when the need arises.
  • Relevant cybersecurity certifications.
  • Strong knowledge of frameworks and regulations such as MITRE ATT&CK, CIS Controls v8.1, ISO/IEC 27001:2022, Cybersecurity Act and PDPA.
  • Familiarity with AI-enabled security operations and threats targeting AI/LLM workloads.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

AI Cyber Defence Specialist
AI Cyber Defence Specialist

Singtel • Singapore

On-site
Confidential
Associate Director - Cyber Security
Associate Director - Cyber Security

Singtel Group • Singapore

On-site
SGD 220,000 - 300,000
N/A
Senior Cyber Security Consultant
Senior Cyber Security Consultant

Singtel Group • Singapore

On-site
SGD 120,000 - 180,000
Cyber Security Resident Engineer
Cyber Security Resident Engineer

Ensign InfoSecurity • Singapore

On-site
SGD 70,000 - 100,000
Associate Director - Cyber Security (Singapore, Singapore)
Associate Director - Cyber Security (Singapore, Singapore)

Singtel • Singapore

On-site
Confidential
Associate Director - Cyber Security
Associate Director - Cyber Security

Singapore Telecommunications Limited • Singapore

On-site
SGD 180,000 - 280,000
SL2471 - Information Security (Managed Detection and Response)
SL2471 - Information Security (Managed Detection and Response)

FPT Asia Pacific Pte Ltd • Singapore

On-site
SGD 180,000 - 260,000
Senior Cyber Security Consultant (Singapore, Singapore)
Senior Cyber Security Consultant (Singapore, Singapore)

Singtel • Singapore

On-site
Confidential
Senior Director Cyber Defence Operations
Senior Director Cyber Defence Operations

Jobline Resources Pte Ltd • Singapore

On-site
SGD 180,000 - 280,000
Senior Director Cyber Defence Operations (Ref 26395)
Senior Director Cyber Defence Operations (Ref 26395)

Jobline Resources Pte Ltd • Singapore

On-site
SGD 180,000 - 260,000