Cyber Threat (CSOC) Engineer

NETS

Singapore

On-site

SGD 90,000 - 130,000

Full time

10 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

NETS, through its subsidiary BCS, is seeking a CSOC Engineer to join the IT Security Team in Singapore. You will monitor, detect, investigate and respond to cybersecurity threats across the organization, operating 24/7 security controls and incident workflows.

You will optimize detection capabilities, automate security operations with SIEM/SOAR, support forensic investigations, and provide Tier 2/3 incident support in a fast-paced environment.

Qualifications

  • Degree or Diploma in Computer Science, Computer Engineering, or Information Security.
  • At least 6 years of experience in a SOC, CERT/CIRT, or similar incident response environment.
  • Strong hands-on experience with SIEM/SOAR platforms and security controls.
  • Knowledge of MAS TRMG, Cyber Hygiene Notice, and Cybersecurity Code of Practice (CCoP).
  • Proficiency in Windows, UNIX, Linux, and understanding of network architectures.
  • Experience in scripting (Python, Bash, PowerShell) and cloud environments is an advantage.
  • Good communication and reporting skills.

Responsibilities

  • Operate and manage cyber defence tools to monitor system activities, identify threats and vulnerabilities.
  • Review and enhance monitoring use cases for effectiveness and coverage.
  • Develop and implement improvements, including SIEM/SOAR tuning and automation.
  • Identify security weaknesses and coordinate remediation with IT teams.
  • Perform proactive threat hunting for IOCs and TTPs.
  • Support 24x7 security operations with Tier 2/3 incident escalations, investigation and reporting.
  • Assist in digital forensic investigations and evidence analysis.

Job description

BCS is NETS’ wholly owned subsidiary and is an entity within the NETS Group. It manages and operates clearing and payment infrastructure for the Singapore Automated Clearing House, including Fast And Secure Transfers (FAST), Inter-bank GIRO (IBG), Cheque Truncation System (CTS), and provides services for PayNow and SGQR Central Repository.

Team and Position Summary:

The IT Security Team at BCS ensures the security, availability and resilience of BCS systems, protecting data and mitigating emerging cyber threats in alignment with regulatory requirements.

The Cyber Security Operations Centre (CSOC) unit is a key function within IT Security, providing 24/7 monitoring, threat detection, and incident response to safeguard BCS’ critical assets.

The CSOC Engineer is responsible for monitoring, detecting, investigating, and responding to cybersecurity threats across the organization. This role focuses on operating and optimizing security monitoring technologies, conducting threat hunting activities, managing security incidents, and identifying vulnerabilities to strengthen the organization's security posture.

The engineer will work closely with IT and security teams to enhance detection capabilities, automate security operations through SIEM/SOAR platforms, support incident response and forensic investigations, and provide Tier 2/3 support for complex cybersecurity events within a 24/7 security operations environment

Responsibilities:

  • Operate and manage cyber defence tools to continuously monitor and analyse system activities, identifying potential threats, vulnerabilities, and malicious behaviour.
  • Review and enhance routine monitoring use cases to ensure effectiveness, relevance, and adequate coverage.
  • Develop and implement improvements, including scripting and SIEM/SOAR tuning, to strengthen and automate monitoring, triaging, and analysis processes.
  • Identify security weaknesses across systems and applications, and collaborate with IT teams to prioritise remediation, track progress, and ensure timely patching and risk mitigation.
  • Perform proactive threat hunting to detect indicators of compromise (IOCs), and identify threat actor tactics, techniques, and procedures (TTPs) within the environment.
  • Support 24x7 security operations by handling Tier 2/3 incident escalations, including investigation, response, and reporting of security events.
  • Assist in digital forensic investigations, including collection, preservation, and analysis of evidence.

Requirements:

Education and Experience

  • Degree or Diploma in Computer Science, Computer Engineering, or Information Security related fields.
  • At least 6 years of experience in a Security Operations Centre (SOC), CERT/CIRT, or a similar incident response environment.

Skills and Knowledge

  • Strong hands-on experience with SIEM/SOAR platforms and security controls across host and network layers.
  • Familiarity with MAS Technology Risk Management Guidelines (TRMG), Cyber Hygiene Notice, and Cybersecurity Code of Practice (CCoP).
  • Strong ability to analyse and interpret network diagnostic outputs (e.g. ping, traceroute, nslookup).
  • Good understanding of frameworks and standards such as OWASP Top 10, CVSS, MITRE ATT&CK, and Cyber Kill Chain.
  • Solid working knowledge of operating systems (Microsoft Windows, UNIX, Linux).
  • Understanding of network architectures and communication protocols (LAN, WAN, WLAN, WWAN).
  • Proficient in incident response methodologies and best practices.
  • Experience in scripting (e.g. Python, Bash, PowerShell) and cloud environments is an advantage.
  • Strong analytical and problem-solving skills, with the ability to handle complex security investigations.
  • Resilient and able to perform effectively in a fast-paced, high-pressure environment.
  • Good communication and presentation skills, including the ability to present findings clearly to stakeholders and management.

Professional Certifications

  • Relevant industry certifications (e.g. GSEC, GCIH, GCIA, GCTI, GCFA, GCFE, GNFA) are advantageous.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Engineer
Cyber Security Engineer

NETS • Singapore

On-site
SGD 110,000 - 150,000
IT Security Governance and Assurance Lead
IT Security Governance and Assurance Lead

NETS • Singapore

On-site
SGD 180,000 - 300,000
Performance bonus
IT Security Governance & Assurance Analyst
IT Security Governance & Assurance Analyst

NETS • Singapore

On-site
SGD 60,000 - 100,000
Cyber Security Resident Engineer
Cyber Security Resident Engineer

Ensign InfoSecurity • Singapore

On-site
SGD 70,000 - 100,000
Cyber Security Resident Engineer - Incident Response & SIEM
Cyber Security Resident Engineer - Incident Response & SIEM

Ensign InfoSecurity • Singapore

On-site
SGD 70,000 - 100,000
IT Security Specialist
IT Security Specialist

sggovterp • Singapore

On-site
SGD 60,000 - 90,000
Security Operations Engineer
Security Operations Engineer

DADACONSULTANTS PTE. LTD. • Singapore

On-site
SGD 90,000 - 150,000
Cybersecurity Specialist (Audit Readiness)
Cybersecurity Specialist (Audit Readiness)

NETS • Singapore

On-site
SGD 70,000 - 110,000
Cloud Operations Engineer
Cloud Operations Engineer

NETS • Singapore

On-site
SGD 120,000 - 180,000
Senior Lead SOC Incident Responder & Security Incident Manager
Senior Lead SOC Incident Responder & Security Incident Manager

NETS • Singapore

On-site
SGD 180,000 - 260,000