Lead / Senior Security Incident Responder

CPF Board

Singapore

Hybrid

SGD 85,000 - 140,000

Full time

6 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Annual leave
Medical benefits
Pro-family leave
Dental benefits

Job summary

CPF Board is seeking a Security Incident Responder to lead the Security Incident Response Team (SIRT) in managing active security incidents and proactive security activities. You will drive incident coordination, threat intelligence, and blue-team improvements while mentoring L1 SOC analysts.

The role emphasizes collaboration across infrastructure, networks, and applications, with a 2-year full-time contract and a hybrid work model to balance on-site and remote work.

Qualifications

  • Experience in security operations or incident response.
  • Ability to coordinate with Incident Commander during critical events.
  • Hands-on with SIEM, EDR/XDR and vulnerability management.

Responsibilities

  • Lead end-to-end incident response workstreams from triage to recovery.
  • Prepare incident reports, situation updates, and regulatory communications.
  • Provide guidance to L1 SOC analysts during high-severity incidents.
  • Collaborate with cross-functional teams for containment and remediation.

Skills

Incident response
SIEM expertise
EDR/XDR
ITIL knowledge
Regulatory awareness

Tools

SIEM tools
WAF

Job description

What the role is

At #TeamCPF, you’re not just joining a team; you are embracing a culture of excellence, collaboration, and meaningful impact. You will play a pivotal role in empowering over 4 million members to secure their retirement, healthcare, housing needs and better navigate life’s uncertainties. We thrive on sharp minds and insightful decisions. Your ability to analyse and think critically isn't just valued; it's essential. Every choice you make contributes to our collective success. Collaboration is our way of life. We believe in the power of effective partnerships and seamless communications across teams. Together, we amplify each other’s strengths and achieve remarkable results. Our learning never stops. We encourage your inquisitiveness and courage to embrace new challenges head‑on. Your agility, readiness to challenge conventions, embrace of data-driven strategies, dedication to learning and applying new skills fuels our innovation and progress. At the core of everything we do lies a genuine desire to make a difference. We serve our community and support each other with compassion, empathy, and unwavering dedications. Every action we take is guided by a deep sense of purpose and a commitment to those we serve. Join us at #TeamCPF! Together, let's redefine possibilities and leave a legacy that echoes for generations.

What you will be working on

As a Security Incident Responder in our Security Incident Response Team (SIRT), you will serve as the key technical lead in managing active security incidents. Beyond incident response, you will contribute to proactive security activities including threat intelligence, threat hunting, and red/purple team engagements. You will also work closely with project teams on security onboarding and provide leadership and guidance to L1 SOC analysts.

In this role, you will:

Incident Response Leadership
  • Serve as the technical lead during active security incidents, working closely with the Incident Commander to coordinate and execute response actions across technical teams and stakeholders.
  • Manage end-to-end incident workstreams from initial triage and containment through to eradication, recovery, and post-incident review, in adherence with the organisation's Incident Management Framework and defined service level agreements.
  • Lead root cause analysis and post-incident reviews, translating findings into actionable improvements to prevent recurrence.
  • Prepare and maintain accurate incident reports, situation updates and timely communications for internal stakeholders and regulatory authorities, where required.
  • Act as the primary escalation point for L1 SOC analysts during high‑severity or complex incidents, providing technical guidance and decision support.
Stakeholder Coordination & Communication
  • Work closely with the Incident Commander to ensure all internal and external stakeholders are kept informed, with clear roles, responsibilities, and communication channels maintained throughout the incident lifecycle.
  • Liaise with regulatory authorities and external parties as required during incident handling, reporting, and post‑incident follow‑up.
  • Collaborate with infrastructure, network, application, and data teams to drive effective containment, investigation, and remediation efforts.
  • Provide timely and accurate technical situation updates to the Incident Commander and security leadership.
Threat Intelligence & Proactive Security
  • Contribute to threat intelligence activities, including the analysis of threat actor Techniques, Tactics and Procedures (TTPs), Indicators of Compromise (IOC) management, and intelligence‑led detection improvements.
  • Lead or support threat hunting exercises to proactively identify hidden threats, anomalous behaviours, and gaps in detection coverage across the environment.
  • Engage in red team and purple team activities to test and validate detection and response capabilities, translating findings into operational improvements.
Detection Engineering & SOC Development
  • Work closely with SIEM, Detection, and Workflow Engineers to develop, tune and optimise detection rules, correlation logic and automated response workflows.
  • Partner with project teams to onboard new systems and platforms into security monitoring, ensuring adequate detection coverage and logging standards.
  • Drive the development and refinement of incident response playbooks, standard operating procedures and escalation frameworks.
Operational Excellence & Improvement
  • Champion continuous service improvement initiatives, including post‑incident reviews, trend analysis, metrics reporting and operational maturity assessments.
  • Apply AI‑assisted tools and platforms, including GenAI‑powered analytics and AI agents, to enhance threat detection, automate routine activities and improve incident investigation workflows.
  • Contribute to the evaluation and adoption of new security technologies, tools, and methodologies to strengthen the organisation's security posture.
What We Are Looking For
  • Relevant experience in security operations, incident response, or related cybersecurity roles.
  • Demonstrated ability to lead incident response workstreams in coordination with an Incident Commander, exercising sound judgement and composure in time‑critical, high‑pressure situations.
  • Hands‑on experience with SIEM platforms, EDR/XDR, WAF, NDR/IDS/IPS, and vulnerability management tool.
  • In‑depth knowledge of Incident Management Frameworks and practices, including ITIL processes, incident severity classification and escalation protocols.
  • Good understanding of the cyber threat landscape, including advanced attack vectors, TTPs, threat actor profiling, and the MITRE ATT&CK framework.
  • Ability to convey complex technical findings clearly to both technical and non‑technical audiences, including senior stakeholders.
  • Familiarity with relevant cybersecurity regulatory requirements, standards and frameworks, such as CyberSecurity Code of Practice (CCoP), ISO 27001, NIST, CIS Controls.
  • Experience with threat intelligence, threat hunting methodologies, and/or red/purple team engagements would be advantageous.
  • Familiarity with network protocols, operating systems (Windows and Linux), and cloud environments (AWS and Azure) would be advantageous.
  • Experience with GenAI tools, AI‑assisted security platforms or AI agents for security operations use cases would be advantageous.
  • Relevant cybersecurity certifications such as GCIH, GCFA, CISSP, CISM, OSCP or equivalent would be advantageous.
  • Ability to perform on‑call and standby duties as part of a rostered 24/7 support arrangement, including call‑out support during nights, weekends, and public holidays.

The seniority of appointment and actual corporate job title will commensurate with individual work experiences. Position is on a 2‑year full‑time contract directly under the payroll of CPF Board with potential for emplacement into a permanent position.

What you can expect
  • Opportunities to engage in a mix of formal and informal training, keeping your skills sharp in our ever‑evolving technological landscape.
  • Promotion opportunities based on your capability and on‑the‑job performance.
  • A vibrant community of like‑minded and friendly colleagues, where collaboration and creativity thrive.
  • A hybrid work model that offers flexibility for remote work, subject to exigencies of service.
  • Flexible dress code that empowers you to choose your appropriate outfit for the day.
  • A comprehensive rewards package that includes annual leave, pro‑family leave, medical and dental benefits, and access to recreational activities.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Lead / Senior Security Incident Responder
Lead / Senior Security Incident Responder

Central Provident Fund Board • Singapore

Hybrid
SGD 90,000 - 130,000
Hybrid work model
Annual leave
Medical and dental benefits
+1
Senior / IT Security Consultant (Cybersecurity Governance & Assurance)
Senior / IT Security Consultant (Cybersecurity Governance & Assurance)

Central Provident Fund Board • Singapore

Hybrid
SGD 120,000 - 180,000
Hybrid work model
Annual leave
Pro-family leave
+1
Lead/ Senior Java Application Consultant
Lead/ Senior Java Application Consultant

Central Provident Fund Board • Singapore

Hybrid
SGD 90,000 - 150,000
Lead Cybersecurity Incident Response Specialist
Lead Cybersecurity Incident Response Specialist

GovTech Singapore • Singapore

On-site
SGD 120,000 - 180,000
[2027 H1 Term-time Internship] Cloud Security and TechOps Intern
[2027 H1 Term-time Internship] Cloud Security and TechOps Intern

re-zoo-me • Singapore

Hybrid
SGD 13,000 - 18,000
Hybrid work model
Health benefits
Annual leave
+2
Red Team Analyst (AVP)
Red Team Analyst (AVP)

OCBC Group • Singapore

On-site
SGD 140,000 - 210,000
Competitive salary
Flexible benefits
Learning & development opportunities
+1
Senior/Lead Consultant (Quality Engineering)
Senior/Lead Consultant (Quality Engineering)

cpf board • Singapore

On-site
SGD 120,000 - 180,000
Annual leave
Medical and dental benefits
Hybrid work model
+1
AI Cyber Defence Specialist
AI Cyber Defence Specialist

Singtel • Singapore

On-site
Confidential
Senior Detection & Response Engineer (APAC)
Senior Detection & Response Engineer (APAC)

Sopra Steria • Singapore

Hybrid
SGD 120,000 - 180,000
Health & insurance
Annual bonus
Training programs & certification
+2
Lead Cybersecurity Specialist (Security Operations)
Lead Cybersecurity Specialist (Security Operations)

JJ Consulting Services • Singapore

On-site
SGD 80,000 - 120,000