AI Cyber Defence Specialist

Singapore Telecommunications Limited

Singapore

On-site

SGD 180,000 - 240,000

Full time

6 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Singapore Telecommunications Limited seeks an AI Cyber Defence Specialist to lead threat management across SOC operations, vulnerability management, threat hunting and DFIR using AI. You will report to the CISO Office and ensure intelligence-led, regulatory-aligned capabilities with measurable outcomes.

The role requires 5+ years in cybersecurity, hands-on SOC/IR/DFIR, leadership, and strong tooling experience (SIEM/EDR/SOAR).

Qualifications

  • Degree in Computer Science, IT, Cybersecurity or related field.
  • 5+ years in cybersecurity with hands-on SOC, IR and DFIR experience.
  • Proven incident response leadership and post-incident review experience.
  • Hands-on with SIEM, EDR/XDR and SOAR tooling.
  • Familiarity with vulnerability management and risk-based prioritisation.
  • Knowledge of MITRE ATT&CK, CIS Controls, ISO27001 and PDPA.

Responsibilities

  • Lead 24x7 SOC operations, including MSSP/MDR partners, with defined SLAs.
  • Own SOC operating model, playbooks, runbooks and escalation matrix.
  • Drive detection engineering across SIEM/EDR/XDR and cloud security tooling.
  • Oversee log coverage across endpoints, servers and networks.
  • Manage SOAR automation for alert enrichment and containment.
  • Define and report SOC KPIs and KRIs to leadership.
  • Lead response to zero-days and emerging vulnerabilities.
  • Establish threat hunting programme using threat intel and MITRE ATT&CK.
  • Operationalise threat intel and manage TIP.
  • Coordinate security incident response with internal and external teams.

Skills

SOC operations
Incident response
Digital forensics
Threat hunting
AI-enabled security
MITRE ATT&CK knowledge
Leadership
SIEM/EDR/SOAR familiarity

Education

Degree in Computer Science / IT / Cybersecurity

Tools

Elastic
Microsoft Sentinel
Google SecOps
QRadar
CrowdStrike
Microsoft Defender
Trend Micro
Trellix
Tenable Nessus
SOAR platforms

Job description

We are seeking an Artificial Intelligence (AI) Cyber Defence Specialist to lead the organisation's threat management capabilities across Security Operations, Vulnerability Management, Threat Hunting and Digital Forensics & Incident Response (DFIR) by leveraging AI.

Reporting to the CISO Office, the candidate will be accountable for the responsibilities as stated below. The candidate will ensure these capabilities are intelligence-led using AI, measurable and aligned with applicable regulatory and industry expectations, including (but not limited to) the Cybersecurity Act and applicable Cybersecurity Codes of Practice (CCoP).

Roles and Responsibilities:
  • Lead and manage the 24x7 Security Operations Centre (SOC) operations, including any Managed Security Service Provider (MSSP) or MDR partner, ensuring security events are monitored, triaged, escalated and resolved within defined Service Level Agreements (SLAs).
  • Own the SOC operating model and its associated processes - tiered analyst structure, shift roster, playbooks, runbooks and escalation matrix, and drive measurable improvement in SOC maturity using AI.
  • Drive detection engineering across SIEM, EDR/XDR, identity and cloud-native security tooling; develop, tune and retire use cases mapped to MITRE ATT&CK to increase detection coverage and reduce false positives.
  • Ensure log source coverage across critical assets - endpoints, servers and networks.
  • Oversee SOAR automation to accelerate alert enrichment, triage and containment actions.
  • Define and report SOC KPIs and KRIs (e.g. MTTD, MTTR, ATT&CK coverage, alert severity, SLA adherence) to the CISO and senior management.
  • Lead the organisation's response to critical zero-day and emerging vulnerabilities, including rapid exposure assessment, compensating controls and emergency patching coordination.
  • Establish and lead a structured, hypothesis-driven threat hunting programme based on threat intelligence, MITRE ATT&CK and anomalies observed in environment telemetry.
  • Develop hypotheses and techniques and execute hunts to identify undetected threats across the environment; convert hunt findings into new or improved detections.
  • Gather and analyse cyber threat information and intelligence from commercial feeds, government sources (e.g. CSA / Sectoral Lead) and open sources to derive insights on attack tactics, techniques and procedures (TTPs), campaigns and threat actor profiles relevant to the organisation and its sector.
  • Operationalise threat intelligence, including IOC ingestion and management of the threat intelligence platform (TIP).
  • Act as a security incident responder for cyber incidents, coordinating technical response, containment, eradication and recovery across internal teams and external partners.
  • Manage vendor relationships, contracts and performance for MSSP/MDR, IR retainer, maintenance of the cybersecurity technology stack and security tooling providers; plan and manage the cyber defence budget.
  • Present the organisation's threat landscape, incident trends and cyber defence posture to the CISO.
  • Support internal and external audits and regulatory inspections, providing evidence of control design and operating effectiveness.
  • Proactively coordinate with technical and business stakeholders and manage internal and external partnerships during a security incident.
  • Any other assigned duties when there is a change in business requirements and scope of work.
What we're looking for...

You embrace continuous learning and use lessons from challenges to improve future outcomes. You can inspire and motivate others to deliver the organisation's vision. You view obstacles as problems to be solved. You are driven by the desire to deliver positive outcomes for your internal customer - Singtel Digital InfraCo.

What you need to have:
  • A degree in Computer Science, Information Technology, Cybersecurity or a related discipline.
  • At least 5 years of cybersecurity experience, with substantial hands-on experience in SOC operations, incident response and digital forensics, including at least 5 years leading a team.
  • Proven track record of leading the response to significant incidents (e.g. ransomware, targeted intrusions, data breaches) from detection through to recovery and post-incident review.
  • Hands-on expertise with SIEM (e.g. Elastic, Microsoft Sentinel, Google SecOps, QRadar), EDR/XDR (e.g. CrowdStrike, Microsoft Defender, Trend Micro, Trellix), and SOAR platforms.
  • Experience with vulnerability management platforms (e.g. Tenable Nessus) and risk-based prioritisation approaches.
  • Highly analytical, with strong attention to detail and outstanding problem-solving skills; able to work independently and under pressure in a fast-paced environment.
  • Willingness to be on call and respond outside office hours during major incidents and/or as and when the need arises.
  • Relevant cybersecurity certifications.
  • Strong knowledge of frameworks and regulations such as MITRE ATT&CK, CIS Controls v8.1, ISO/IEC 27001:2022, Cybersecurity Act and PDPA.
  • Familiarity with AI-enabled security operations and threats targeting AI/LLM workloads.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

AI Cyber Defence Specialist
AI Cyber Defence Specialist

Singtel Group • Singapore

On-site
SGD 120,000 - 190,000
AI Cyber Defence Specialist
AI Cyber Defence Specialist

Singtel • Singapore

On-site
Confidential
Senior Cyber Security Consultant
Senior Cyber Security Consultant

Singtel Group • Singapore

On-site
SGD 120,000 - 180,000
Associate Director - Cyber Security
Associate Director - Cyber Security

Singtel Group • Singapore

On-site
SGD 220,000 - 300,000
N/A
Associate Director - Cyber Security
Associate Director - Cyber Security

Singapore Telecommunications Limited • Singapore

On-site
SGD 180,000 - 280,000
Associate Director - Cyber Security (Singapore, Singapore)
Associate Director - Cyber Security (Singapore, Singapore)

Singtel • Singapore

On-site
Confidential
AI Cyber Defence Lead & SOC Architect
AI Cyber Defence Lead & SOC Architect

Singtel Group • Singapore

On-site
SGD 120,000 - 190,000
SL2471 - Information Security (Managed Detection and Response)
SL2471 - Information Security (Managed Detection and Response)

FPT Asia Pacific Pte Ltd • Singapore

On-site
SGD 180,000 - 260,000
Senior Cyber Security Consultant (Singapore, Singapore)
Senior Cyber Security Consultant (Singapore, Singapore)

Singtel • Singapore

On-site
Confidential
Cyber Security Resident Engineer
Cyber Security Resident Engineer

Ensign InfoSecurity • Singapore

On-site
SGD 70,000 - 100,000