Lead Cybersecurity Incident Response Specialist

Government Technology Agency

Singapore

On-site

SGD 120,000 - 180,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Flexible work arrangements
Total rewards
Employee wellness programmes

Job summary

GovTech in Singapore seeks a seasoned Cybersecurity Operations Specialist (Incident Response) to join the Cyber DefenseOps & Intelligence team. You will lead incident response activities, triage events, and conduct in-depth investigations to contain and recover from cybersecurity incidents across systems and cloud environments.

The role requires strong log analysis skills and familiarity with Splunk/ELK and forensic tools, with the ability to communicate findings to decision makers.

Qualifications

  • Bachelor’s Degree in Computer Science/Information Security or equivalent.
  • Professional certifications such as GCFA, GREM, GNFA, GCTI, CISSP preferred.
  • 5+ years experience as incident responder/digital forensics/malware analysis.
  • Strong OS and networking knowledge (Windows/Linux), with basic cloud awareness.
  • Proficient in log analysis with Splunk/ELK and forensic tools AXIOM/FTK/Autopsy.
  • Excellent communication and ability to correlate events across sources.
  • Knowledge of cloud/containers is a plus.

Responsibilities

  • Lead incident response activities through all phases of an incident.
  • Triage and investigate security incidents to determine scope and severity.
  • Develop and execute containment strategies.
  • Perform investigations and root cause analysis to identify attack vectors.
  • Conduct comprehensive security event log analysis across endpoints, networks, apps, and cloud.
  • Conduct digital forensic acquisition and analysis of artifacts.
  • Maintain stakeholder communications and prepare post-incident reports with preventive recommendations.
  • Provide expert input for automating Security Operations (SOAR playbooks).
  • Develop and test incident response playbooks and processes.
  • Maintain situational awareness of cyber security landscape and threat actor TTPs.

Skills

Incident response
Digital forensics
Log analysis
Cybersecurity operations
Root cause analysis
Threat hunting
Communication
Team collaboration

Education

Bachelor's in Computer Science / Information Security

Tools

Splunk
ELK Stack
AXIOM
FTK
Autopsy
EDR

Job description

Job Description

The Government Technology Agency (GovTech) is the lead agency driving Singapore’s Smart Nation initiatives and public sector digital transformation. As the Centre of Excellence for Infocomm Technology and Smart Systems (ICT & SS), GovTech develops the Singapore Government’s capabilities in Data Science & Artificial Intelligence, Application Development, Smart City Technology, Digital Infrastructure, and Cybersecurity.

At GovTech, we offer you a purposeful career to make lives better. We empower our people to master their craft through continuous and robust learning and development opportunities all year round. Our GovTechies embody our Agile, Bold and Collaborative values to deliver impactful solutions. GovTech aims to transform the delivery of Government digital services by taking an "outside-in" view, putting citizens and businesses at the heart of everything we do. Play a part in Singapore’s vision to build a Smart Nation and embark on your meaningful journey to build tech for public good. Join us to advance our mission and shape your future with us today!

Learn more about GovTech at tech.gov.sg.

Join us and you will play a key role in the CyberDefenseOps & Intelligence (CDOI) of Cyber Security Group (CSG) as Cybersecurity Operations Specialist (Incident Response) to manage and investigate cybersecurity incidents.

The successful candidate will ensure the delivery of cybersecurity operations services across all stages of the incident response lifecycle. This encompasses triaging potential security events, conducting in-depth investigations and advising on containment, eradication and recovery strategies. Candidate must possess strong log analysis and digital forensics skills to drive effective responses to cybersecurity incidents that ensure secure delivery of applications and infrastructure services. Critical thinking and great communication skills are required to articulate technical concepts and guide decision makers towards optimal courses of action. This is a key position in the Cyber Incident Response Team (CIRT).

What you will be working on:
  • Lead incident response activities through all phases of an incident:
  • Conduct triage and investigation of potential cybersecurity incidents to determine incident scope and severity
  • Develop and execute containment strategies
  • Perform investigations and root cause analysis to identify attack vectors, tactics, and impact
  • Conduct comprehensive security event log analysis to validate security detections, investigate alerts, and identify attacks across multiple data sources including:
  • Endpoint system logs or Endpoint detection and response (EDR) telemetry
  • Network traffic logs
  • Application logs
  • Cloud service logs and audit trails
  • Conduct digital forensic acquisition and analysis of artifacts from various sources including:
  • Endpoint systems and servers
  • Network devices and logs
  • Cloud environments
  • Mobile devices and storage media
  • Maintain clear stakeholder communication throughout incident lifecycle and prepare comprehensive post-incident reports with preventive recommendations
  • Provide expert input for automating Security Operations (E.g Implement SOAR playbooks)
  • Develop and test incident response playbooks and processes
  • Maintain situational awareness of cyber security landscape and emerging threat actor TTPs
What we are looking for:
  • Bachelor’s Degree in Computer Science/Information Security or equivalent
  • Professional certifications, including GCFA, GREM, GNFA, GCTI, CISSP or other relevant certifications will be preferred
  • Preferably 5 years or more of experience as a full-time incident responder/digital forensic/malware analysis or related discipline
  • Understanding of operating systems and platform (e.g. Windows, Linux) and knowledge of computer networking, LAN, and server
  • Strong ability with log analysis techniques, familiarity with platforms (e.g., Splunk, ELK Stack, Google SecOps) and analytical skills to correlate events across multiple log sources to identify attack patterns
  • Proficient in Forensic Tools such as AXIOM, FTK or Autopsy
  • Ability to perform basic static and dynamic malware analysis and to analyse network and application logs
  • Good working knowledge of Cloud and Container technologies are a plus
  • Familiarity with good security practices
  • Good communication and interpersonal skills, with the ability to multitask and prioritise
  • Meticulous and demonstrate a high degree of integrity, initiative, energy and endurance

GovTech is an equal opportunity employer committed to fostering an inclusive workplace that values diverse voices and perspectives, as we believe that diversity is the foundation to innovation.

  • Our employee benefits are based on a total rewards approach, offering a holistic and market-competitive suite of perks.
  • These include leave benefits to meet your work-life needs and employee wellness programmes.
  • We champion flexible work arrangements (subject to your job role) and trust that you will manage your own time to deliver your best, wherever you are, and whatever works best for you.

Learn more about life inside GovTech at go.gov.sg/GovTechCareers.

Stay connected with us on social media at go.gov.sg/ConnectWithGovTech.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Lead Cybersecurity Incident Response Specialist
Lead Cybersecurity Incident Response Specialist

GovTech Singapore • Singapore

On-site
SGD 120,000 - 180,000
Senior Cybersecurity Operations Specialist
Senior Cybersecurity Operations Specialist

GovTech Singapore • Singapore

On-site
SGD 180,000 - 240,000
Cybersecurity Engineer, BCA
Cybersecurity Engineer, BCA

GovTech Singapore • Singapore

On-site
SGD 60,000 - 100,000
Senior Cybersecurity Operations Specialist
Senior Cybersecurity Operations Specialist

Government Technology Agency • Singapore

On-site
SGD 150,000 - 190,000
Senior/ Lead Cybersecurity Engineer, TradeNet
Senior/ Lead Cybersecurity Engineer, TradeNet

GovTech Singapore • Singapore

On-site
SGD 120,000 - 180,000
Cybersecurity Engineer, BCA
Cybersecurity Engineer, BCA

Government Technology Agency • Singapore

Hybrid
SGD 90,000 - 120,000
Flexible work arrangements
Wellness programs
Total rewards approach
Lead, Cybersecurity Operations Specialist, Singpass
Lead, Cybersecurity Operations Specialist, Singpass

Government Technology Agency • Singapore

Hybrid
SGD 180,000 - 260,000
Flexible work arrangements
Leave benefits and wellness programs
Senior Cyber Incident Response Leader
Senior Cyber Incident Response Leader

Government Technology Agency • Singapore

On-site
SGD 120,000 - 180,000
Flexible work arrangements
Total rewards
Employee wellness programmes
Senior Digital Forensics & Threat Intelligence Responder
Senior Digital Forensics & Threat Intelligence Responder

Government Technology Agency (GovTech) • Singapore

On-site
SGD 90,000 - 150,000
Digitial Forensic Incident Responder, Threat Intelligence & Repsonse Division
Digitial Forensic Incident Responder, Threat Intelligence & Repsonse Division

Government Technology Agency (GovTech) • Singapore

On-site
SGD 90,000 - 150,000