Head of Security Operations & Incident Response

Morgan McKinley

Singapore

On-site

SGD 120,000 - 190,000

Full time

30 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Morgan McKinley is seeking a senior cybersecurity leader to head Security Operations and Incident Management in Singapore. The role focuses on monitoring, investigation and rapid response to incidents, with a mandate to coordinate technical teams and stakeholders through containment and recovery.

Key responsibilities include root-cause analysis, post-incident reviews and ongoing improvement of frameworks, playbooks, and escalation processes.

Qualifications

  • Experience managing significant cybersecurity incidents end-to-end: investigation, containment, remediation, recovery, root-cause analysis.
  • Leadership of SOC/Security Operations or Incident Response teams is highly regarded.
  • Strong understanding of SIEM, EDR/XDR, threat detection and incident-response tech and frameworks (MITRE ATT&CK, NIST CSF).
  • Excellent stakeholder management and communication with senior management during major incidents.

Responsibilities

  • Lead Security Operations and Incident Management with monitoring, investigation, escalation and response to cybersecurity events.
  • Act as senior escalation point for major and complex cyber incidents, coordinating technical teams and stakeholders.
  • Perform root-cause analyses and post-incident reviews to close gaps and implement corrective actions.
  • Drive continuous improvement of incident response frameworks, SOPs, playbooks and escalation processes.
  • Oversee SOC capabilities across monitoring, detection, investigation and response.
  • Collaborate with Threat Intelligence, Threat Hunting, Infrastructure, Cloud, Applications and Cybersecurity teams to strengthen detection and response.

Skills

Security operations
Incident response
Escalation management
Root-cause analysis
Stakeholder management
Cybersecurity leadership

Education

CISSP or equivalent
Security certifications (GCIH/GCIA/GCFE/GREM)

Tools

SIEM
EDR/XDR
Threat intel tools
Threat hunting platforms

Job description

Job Responsibilities:

  • Lead Security Operations and Incident Management, ensuring effective monitoring, investigation, escalation and response to cybersecurity events and incidents.
  • Act as the senior escalation point for major and complex cyber incidents, coordinating technical teams and relevant stakeholders through containment, remediation and recovery.
  • Lead root-cause analysis and post-incident reviews, identifying control, technology and process gaps and ensuring corrective actions are implemented.
  • Drive continuous improvement of Incident Response frameworks, SOPs, playbooks and escalation processes.
  • Oversee and strengthen SOC/Security Operations capabilities across monitoring, detection, investigation and response.
  • Partner with Threat Intelligence, Threat Hunting, Infrastructure, Cloud, Application and Cybersecurity teams to improve detection and response capabilities.
  • Support digital forensic investigations where required; deep forensic specialisation is advantageous but not mandatory.
  • Identify opportunities to improve security operations through automation, SIEM, EDR/XDR, security analytics and emerging technologies.
  • Lead cyber incident exercises and simulations to strengthen organisational readiness and resilience.
  • Establish operational metrics and reporting covering incident trends, response effectiveness, root causes and areas of improvement.
  • Lead, mentor and develop Cybersecurity Operations and Incident Response professionals.
  • Engage senior management and business stakeholders during significant cybersecurity incidents and clearly communicate technical risks and business impact.

Requirements:

  • Candidates should have experience managing significant cybersecurity incidents and a strong understanding of the end-to-end incident lifecycle, including investigation, containment, remediation, recovery and root-cause analysis.
  • Experience leading a SOC, Security Operations, Cyber Defence or Incident Response team would be highly regarded.
  • Good understanding of SIEM, EDR/XDR, security monitoring, threat detection and incident-response technologies, together with frameworks such as MITRE ATT&CK, Cyber Kill Chain and NIST CSF.
  • Strong stakeholder management and communication skills, including the ability to coordinate multiple technical teams and communicate effectively with senior management during major incidents.
  • Relevant certifications such as CISSP, GCIH, GCIA, GCFE, GREM or equivalent are advantageous.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Head of Security Operations & Incident Response
Head of Security Operations & Incident Response

Morgan Mckinley Pte Ltd • Singapore

On-site
SGD 180,000 - 280,000
Senior Cyber Security Consultant
Senior Cyber Security Consultant

Singtel • Singapore

On-site
Confidential
Assistant Lead Engineer - Security Operations (Cyber Defence & Resilience)
Assistant Lead Engineer - Security Operations (Cyber Defence & Resilience)

Synapxe • Singapore

On-site
SGD 90,000 - 150,000
Senior Analyst, Threat Detection and Response
Senior Analyst, Threat Detection and Response

WhiteCrow Research • Singapore

On-site
SGD 120,000 - 180,000
Senior Specialist, Security Operations - Cybersecurity
Senior Specialist, Security Operations - Cybersecurity

SIA Engineering Company • Singapore

On-site
SGD 120,000 - 180,000
Cyber Security Resident Engineer - Incident Response & SIEM
Cyber Security Resident Engineer - Incident Response & SIEM

Ensign InfoSecurity • Singapore

On-site
SGD 70,000 - 100,000
Security Operations, Consultant
Security Operations, Consultant

aia • Singapore

On-site
SGD 120,000 - 180,000
Senior Cybersecurity Operations Specialist (JD#11242)
Senior Cybersecurity Operations Specialist (JD#11242)

SCIENTE INTERNATIONAL PTE. LTD. • Singapore

On-site
SGD 150,000 - 210,000
Senior SOC Engineer, Digital Infrastructure
Senior SOC Engineer, Digital Infrastructure

Kerry Consulting • Singapore

On-site
SGD 110,000 - 180,000
IT Security Officer
IT Security Officer

PCCW SOLUTIONS INSYS PTE. LTD. • Singapore

On-site
SGD 100,000 - 150,000