Head of Cyber Defence (SecOps)

SPH Media

Singapore

On-site

SGD 180,000 - 280,000

Full time

9 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

SPH Media seeks a hands-on Head of Security Operations to lead enterprise cyber defence across on‑premise and cloud environments. You will manage a team of security analysts, MSSPs, and SOC providers, owning threat detection, incident response, and threat intelligence integration.

The role requires strong leadership, cloud security expertise, and a proactive security posture. You will develop playbooks, drive improvements in SOC tooling, and collaborate with Cloud, DevOps, and IT teams to embed

Qualifications

  • 7+ years of cybersecurity experience with 3+ years in SecOps leadership.
  • Proven ability to lead security incidents at scale with SIRM focus.
  • Hands-on in SIEM/SOC operations, threat hunting, and threat intel.
  • Strong cloud security knowledge (AWS, GCP, Azure) and hybrid environments.

Responsibilities

  • Lead a team of 4–5 security analysts and external MSSPs/SOC providers.
  • Own threat detection, investigation, and incident response processes.
  • Oversee real-time monitoring, threat hunting, and incident triage.
  • Integrate proactive threat intelligence into SecOps workflows.
  • Escalate security incidents and drive post-incident analysis.
  • Improve detection rules and SIEM/EDR coverage across platforms.
  • Collaborate with Cloud, DevOps, and IT for secure workflows.
  • Define KPIs and report security metrics to leadership.
  • Maintain incident response playbooks and crisis management plans.
  • Engage with external threat intel sharing communities and vendors.

Skills

Threat hunting
Threat intelligence
Incident response
Security monitoring
SIRM
Cloud security
Leadership
Communication
SOC management
Python/PowerShell

Education

CISSP
CISM
GCIH
ECIH
CCSP

Tools

Splunk
Azure Sentinel
EDR tools
SOAR platforms
Threat intelligence feeds

Job description

SPH Media’s mission is to be the trusted source of news and lifestyle content in Singapore and Asia.

One of our core purposes is to produce credible, balanced, and objective news and analysis, always with a view to uphold the public good and fostering an informed, engaged citizenry.

We welcome talented individuals to join us and grow a career in a vibrant and collaborative environment built around a culture of respect and inclusivity.

As an employer, we are committed to rewarding our people fairly and developing them in their careers.

About the Role

We are seeking a highly skilled and strategic Head of Security Operations (SecOps) to lead our enterprise cyber defence capabilities in a dynamic and fast‑paced media environment. This role is pivotal in ensuring the security and resilience of our infrastructure, content, and digital assets across on‑premise and cloud environments.

The ideal candidate is a hands‑on security leader with deep expertise in security incident response and management (SIRM), including leading the investigation, containment, remediation, and recovery of complex security incidents. The candidate should also possess strong experience in threat hunting, threat intelligence, security monitoring, and managing both internal security analysts and third‑party Security Operations Centre (SOC) providers. Familiarity with security operations and incident response across cloud and on‑premises environments is essential. The successful candidate will strengthen and modernise our cyber defence capabilities and ensure the timely and effective management of security incidents across the enterprise.

Key Responsibilities

The scope of responsibilities includes the following:

  • Lead and manage a team of 4–5 security analysts, as well as external MSSPs and SOC providers.
  • Own and continuously enhance threat detection, investigation, and response processes using modern tooling and automation.
  • Oversee real‑time threat monitoring, threat hunting, and incident triage to identify and mitigate risks promptly.
  • Develop and integrate proactive threat intelligence into SecOps processes and security technologies.
  • Serve as a key escalation point (role of SIRM) for security incidents and lead incident response, root cause analysis, and post‑incident reporting.
  • Lead the continuous improvement of detection rules, correlation logic, and threat‑hunting techniques across SIEM and EDR platforms.
  • Collaborate with Cloud, DevOps, and IT teams to ensure security is embedded in enterprise systems and media production workflows.
  • Stay ahead of emerging threats, TTPs, and relevant threat actor campaigns, especially those targeting the media industry.
  • Define, track, and report operational metrics and KPIs to senior leadership.
  • Ensure compliance with relevant frameworks, standards, and regulations (e.g., NIST, ISO/IEC 27001, GDPR, SOC 2).
  • Work with Infrastructure teams on the design, implementation, and maintenance of security solutions, including firewalls, intrusion detection systems, encryption technologies, and identity management systems.
  • Establish and regularly test incident response playbooks, escalation procedures, crisis management processes, and recovery plans.
  • Cyber Threat Intelligence: Lead efforts to continuously monitor the threat landscape and provide timely insights on emerging threats and vulnerabilities. Build relationships with external stakeholders, including threat intelligence sharing communities, government agencies, and security vendors, to strengthen organisational defences.
  • Own and manage relevant security contracts, procurement activities, and projects, including collaborating with other teams to implement and roll out new tools under the Cyber Defence Team.
  • Perform other duties as assigned by the CISO.
Required Qualifications
  • 7+ years of experience in cybersecurity with at least 3 years in a leadership or managerial role within a SecOps function.
  • Proven experience in threat hunting, threat intelligence integration, and managing security incidents at scale.
  • Hands‑on expertise in modern SIEM platforms (e.g., Splunk, Sentinel), SOAR platforms, EDR tools, and threat intelligence feeds.
  • Experience managing hybrid or outsourced SOC environments, including managing service providers against agreed performance standards and SLAs.
  • Solid understanding of cloud-native security (AWS, GCP, or Azure), preferably within media streaming or content distribution environments.
  • Strong grasp of MITRE ATT&CK framework and experience building detection coverage around it.
  • Strong communication and leadership skills, with the ability to brief senior stakeholders and collaborate cross‑functionally.
  • Familiarity with scripting (e.g., Python, PowerShell) and modern search and query languages (e.g., KQL, SPL).
  • Proven experience leading teams in security incident response and management, threat management, and cyber crisis management.
  • Preferably holds a relevant professional certification, such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), GIAC Certified Incident Handler (GCIH), EC-Council Certified Incident Handler (ECIH), or Certified Cloud Security Professional (CCSP).
  • Additional cloud or platform‑specific security certifications, such as AWS Certified Security – Specialty or Microsoft Certified: Azure Security Engineer Associate, would be advantageous.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

AI Cyber Defence Specialist
AI Cyber Defence Specialist

Singtel • Singapore

On-site
Confidential
Head of Security Operations & Incident Response
Head of Security Operations & Incident Response

Morgan McKinley • Singapore

On-site
SGD 120,000 - 190,000
Chief Cyber Defence & SecOps Leader
Chief Cyber Defence & SecOps Leader

SPH Media • Singapore

On-site
SGD 180,000 - 280,000
Cyber Security Resident Engineer - Incident Response & SIEM
Cyber Security Resident Engineer - Incident Response & SIEM

Ensign InfoSecurity • Singapore

On-site
SGD 70,000 - 100,000
Senior Manager, Cybersecurity Operations
Senior Manager, Cybersecurity Operations

GOLDTECH RESOURCES PTE LTD • Singapore

On-site
SGD 80,000 - 130,000
Cyber Security Resident Engineer
Cyber Security Resident Engineer

Ensign InfoSecurity • Singapore

On-site
SGD 70,000 - 100,000
Assistant Director (Security Operations)
Assistant Director (Security Operations)

Ministry of Defence of Singapore • Singapore

On-site
SGD 120,000 - 200,000
Head of Security Operations & Incident Response
Head of Security Operations & Incident Response

Morgan Mckinley Pte Ltd • Singapore

On-site
SGD 180,000 - 280,000
Security Operations, Consultant
Security Operations, Consultant

aia • Singapore

On-site
SGD 120,000 - 180,000
Deputy Cyber Security Manager
Deputy Cyber Security Manager

woh hup group • Singapore

On-site
SGD 90,000 - 150,000