Cybersecurity SOC Manager

NETS

Singapore

On-site

SGD 120,000 - 190,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

NETS is seeking a senior cybersecurity leader to drive incident response across detection, containment, eradication, and recovery. You will oversee deep technical investigations across endpoints, networks, cloud, and identity, and coordinate with cross-functional teams during major security incidents to ensure swift containment and effective remediation.

The role requires extensive experience in incident response, digital forensics, and SOC operations, with a track record of leading crisis

Qualifications

  • 10–15+ years of cybersecurity experience, with 5+ years in incident response / digital forensics / SOC operations.
  • 3+ years in a lead or incident management capacity.
  • Strong hands-on experience in incident response methodologies and frameworks.

Responsibilities

  • Lead end-to-end incident response across detection, triage, containment, eradication and recovery.
  • Analyze malware and attack patterns to determine root cause and scope.
  • Act as Incident Commander during major security incidents and coordinate cross-functional teams.
  • Develop and improve incident response playbooks and runbooks.
  • Liaise with Fraud, Risk, Compliance, and IT for regulatory reporting requirements.
  • Drive SOAR automation to accelerate response actions.

Skills

Incident response
Digital forensics
SOC operations
Threat intel
Crisis management
Leadership

Tools

EDR/XDR
SIEM

Job description

Key Responsibilities

Incident Response & Investigation

Lead and conduct end-to-end incident response across detection, triage, containment, eradication, and recovery.

Able to perform deep technical investigations across endpoints, network, identity, cloud, and application layers.

Analyze malware, attacker behaviors, and intrusion patterns to determine root cause and attack scope.

Handle high-severity and sophisticated cyber incidents, including APT, ransomware, and fraud-related attacks.

Maintain detailed documentation of incidents, actions taken, and lessons learned.

Security Incident Management

Act as Incident Commander during major security incidents, coordinating cross-functional teams (SOC, IR, IT, Legal, Risk, Communications).

Drive structured incident management processes, ensuring adherence to SLAs and playbooks.

Provide timely and clear communications to senior management and stakeholders.

Lead post-incident reviews (PIRs) and ensure remediation actions are tracked to closure.

SOC Operations & Escalation

Serve as the highest technical escalation point within SOC for complex investigations.

Support SOC analysts in triage and response for high-priority alerts.

Improve escalation processes and decision-making frameworks during incidents.

Playbooks, Processes & Readiness

Develop, maintain, and continuously improve incident response playbooks and runbooks.

Ensure readiness for various threat scenarios including ransomware, data exfiltration, and insider threats.

Conduct and support tabletop exercises and incident simulations.

Align incident response processes with industry frameworks (e.g., MAS TRMG, CCoP, NIST, ISO 27035).

Threat Intelligence & Detection Feedback Loop

Leverage threat intelligence to enhance incident response effectiveness.

Provide feedback to detection engineering and threat hunting teams to improve use cases and monitoring coverage.

Identify detection gaps exposed during incidents and drive remediation.

Digital Forensics & Evidence Handling

Perform or oversee forensic data acquisition and analysis (disk, memory, logs).

Ensure proper chain of custody and evidence handling for legal and regulatory needs.

Support investigations that may require regulatory reporting or legal actions.

Automation & Tooling

Drive the use of automation and SOAR playbooks to accelerate response actions.

Recommend and implement tools to improve investigation speed and accuracy.

Stakeholder & Regulatory Engagement

Liaise with internal stakeholders including Fraud, Risk, Compliance, and IT.

Support regulatory incident reporting requirements relevant to financial/payment systems.

Act as a trusted advisor during cyber crisis situations.

Required Qualifications & Experience

10–15+ years of cybersecurity experience, with:

5+ years in incident response / digital forensics / SOC operations

3+ years in a lead or incident management capacity

Strong hands-on experience in:

Incident response methodologies and frameworks

EDR/XDR platforms

SIEM platforms

Network and endpoint investigation techniques

Deep understanding of:

Threat actor tactics, techniques, and procedures (TTPs)

MITRE ATT&CK framework

Malware behavior and attack lifecycle

Experience in:

Crisis management and incident command

Cross-functional coordination during high-pressure scenarios

Strong technical skills in:

OS internals (Windows/Linux)

Networking (TCP/IP, DNS, HTTP/S, etc.)

Log analysis and correlation

Preferred Qualifications

Experience in financial services, payments, or critical infrastructure environments

Hands-on malware analysis and reverse engineering (basic to advanced)

Familiarity with:

Cloud security incident response (AWS, Azure, GCP)

Identity-based attacks and investigations

Exposure to fraud-related cybersecurity incidents

Preferred Certifications

GIAC certifications (GCFA, GCIH, GNFA, GREM)

CISSP, CISM

Certified Incident Handler / Forensics certifications

Vendor certifications (Microsoft, CrowdStrike, Google Mandiant, Elastic, etc.)

Key Competencies

Strong technical depth and investigative skills

Ability to lead during high-pressure incidents

Excellent communication and stakeholder management

Structured and analytical thinking

Decisiveness and accountability

Mentorship and team leadership

What Success Looks Like

Rapid and effective containment of high-impact security incidents

Reduced MTTR (Mean Time to Respond) and improved response quality

Well-executed and coordinated incident management processes

Continuous improvement of IR playbooks and readiness

Strong trust and confidence from executive leadership and stakeholders

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cybersecurity SOC Manager
Cybersecurity SOC Manager

NETWORK FOR ELECTRONIC TRANSFERS (SINGAPORE) PTE LTD • Singapore

On-site
SGD 120,000 - 180,000
Senior Analyst, Threat Detection and Response
Senior Analyst, Threat Detection and Response

WhiteCrow Research • Singapore

On-site
SGD 120,000 - 180,000
Senior Cyber Security Consultant
Senior Cyber Security Consultant

Singtel • Singapore

On-site
Confidential
Risk Services, Technology Risk Services - Incident Response & SOC Compliance, Senior Associate / Assistant Manager
Risk Services, Technology Risk Services - Incident Response & SOC Compliance, Senior Associate / Assistant Manager

PRICEWATERHOUSECOOPERS RISK SERVICES PTE. LTD. • Singapore

On-site
SGD 70,000 - 120,000
Security Delivery Consultant
Security Delivery Consultant

ABPGROUP PTE. LTD. • Singapore

On-site
SGD 70,000 - 120,000
Security Operations (SOC)
Security Operations (SOC)

RED ALPHA CYBERSECURITY PTE. LTD. • Singapore

On-site
SGD 60,000 - 80,000
Senior SOC Engineer, Digital Infrastructure
Senior SOC Engineer, Digital Infrastructure

Kerry Consulting • Singapore

On-site
SGD 110,000 - 180,000
Security Operations, Consultant
Security Operations, Consultant

aia • Singapore

On-site
SGD 120,000 - 180,000
Risk Services, Technology Risk Services - Incident Response & SOC Compliance, Senior Associate [...]
Risk Services, Technology Risk Services - Incident Response & SOC Compliance, Senior Associate [...]

PwC Singapore • Singapore

On-site
SGD 60,000 - 80,000
Work visa sponsorship
Training programs
Dynamic team environment
Senior Analyst, Threat Detection and Response
Senior Analyst, Threat Detection and Response

SATS Ltd. • Singapore

On-site
SGD 90,000 - 150,000