Lead / Senior Security Incident Responder

Central Provident Fund Board

Singapore

Hybrid

SGD 90,000 - 130,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Hybrid work model
Annual leave
Medical and dental benefits
Recreational activities

Job summary

Central Provident Fund Board is seeking a Security Incident Responder to lead active incidents within the Security Incident Response Team. The role involves coordinating containment, eradication, and recovery while guiding L1 SOC analysts and partners across infrastructure, networks, and applications.

You will contribute to threat intelligence, hunting exercises, and red/purple team engagements, applying ITIL-based processes and ensuring timely communications to stakeholders and authorities

Qualifications

  • Experience in security operations, incident response, or related cybersecurity roles.

Responsibilities

  • Act as technical lead during active security incidents.
  • Coordinate response actions across technical teams and stakeholders.
  • Lead post-incident reviews and root cause analyses.
  • Prepare incident reports and regulatory communications as required.
  • Provide guidance to L1 SOC analysts during high-severity incidents.

Skills

Security incident response
SIEM platforms
Incident management
Threat hunting
Red team / Purple team

Education

GCIH, GCFA, CISSP, CISM, OSCP or equivalent

Tools

EDR/XDR
WAF
NDR/IDS/IPS
Vulnerability management tools

Job description

What the role is:

At #TeamCPF, you’re not just joining a team; you are embracing a culture of excellence, collaboration, and meaningful impact. You will play a pivotal role in empowering over 4 million members to secure their retirement, healthcare, housing needs and better navigate life’s uncertainties.We thrive on sharp minds and insightful decisions. Your ability to analyse and think critically isn't just valued; it's essential. Every choice you make contributes to our collective success.Collaboration is our way of life. We believe in the power of effective partnerships and seamless communications across teams. Together, we amplify each other’s strengths and achieve remarkable results.Our learning never stops. We encourage your inquisitiveness and courage to embrace new challenges head-on. Your agility, readiness to challenge conventions, embrace of data-driven strategies, dedication to learning and applying new skills fuels our innovation and progress.At the core of everything we do lies a genuine desire to make a difference. We serve our community and support each other with compassion, empathy, and unwavering dedications. Every action we take is guided by a deep sense of purpose and a commitment to those we serve.Join us at #TeamCPF! Together, let's redefine possibilities and leave a legacy that echoes for generations.

What you will be working on:

As a Security Incident Responder in our Security Incident Response Team (SIRT), you will serve as the key technical lead in managing active security incidents. Beyond incident response, you will contribute to proactive security activities including threat intelligence, threat hunting, and red/purple team engagements. You will also work closely with project teams on security onboarding and provide leadership and guidance to L1 SOC Analysts.

In this role, you will:

Incident Response Leadership
  • Serve as the technical lead during active security incidents, working closely with the Incident Commander to coordinate and execute response actions across technical teams and stakeholders.
  • Manage end-to-end incident workstreams from initial triage and containment through to eradication, recovery, and post-incident review, in adherence with the organisation's Incident Management Framework and defined service level agreements.
  • Lead root cause analysis and post-incident reviews, translating findings into actionable improvements to prevent recurrence.
  • Prepare and maintain accurate incident reports, situation updates and timely communications for internal stakeholders and regulatory authorities, where required.
  • Act as the primary escalation point for L1 SOC analysts during high-severity or complex incidents, providing technical guidance and decision support.
Stakeholder Coordination & Communication
  • Work closely with the Incident Commander to ensure all internal and external stakeholders are kept informed, with clear roles, responsibilities, and communication channels maintained throughout the incident lifecycle.
  • Liaise with regulatory authorities and external parties as required during incident handling, reporting, and post-incident follow-up.
  • Collaborate with infrastructure, network, application, and data teams to drive effective containment, investigation, and remediation efforts.
  • Provide timely and accurate technical situation updates to the Incident Commander and security leadership.
Threat Intelligence & Proactive Security
  • Contribute to threat intelligence activities, including the analysis of threat actor Techniques, Tactics and Procedures (TTPs), Indicators of Compromise (IOC) management, and intelligence-led detection improvements.
  • Lead or support threat hunting exercises to proactively identify hidden threats, anomalous behaviours, and gaps in detection coverage across the environment.
  • Engage in red team and purple team activities to test and validate detection and response capabilities, translating findings into operational improvements.
Detection Engineering & SOC Development
  • Work closely with SIEM, Detection, and Workflow Engineers to develop, tune and optimise detection rules, correlation logic and automated response workflows.
  • Partner with project teams to onboard new systems and platforms into security monitoring, ensuring adequate detection coverage and logging standards.
  • Drive the development and refinement of incident response playbooks, standard operating procedures and escalation frameworks.
Operational Excellence & Improvement
  • Champion continuous service improvement initiatives, including post-incident reviews, trend analysis, metrics reporting and operational maturity assessments.
  • Apply AI-assisted tools and platforms, including GenAI-powered analytics and AI agents, to enhance threat detection, automate routine activities and improve incident investigation workflows.
  • Contribute to the evaluation and adoption of new security technologies, tools, and methodologies to strengthen the organisation's security posture.
What we are looking for:

We value the diverse talents and experiences that each individual brings to the table. While mastery of every requirement may not be necessary, familiarity and expertise in some of the following areas will position you for success within this team.

  • Relevant experience in security operations, incident response, or related cybersecurity roles.
  • Demonstrated ability to lead incident response workstreams in coordination with an Incident Commander, exercising sound judgement and composure in time-critical, high-pressure situations.
  • Hands-on experience with SIEM platforms, EDR/XDR, WAF, NDR/IDS/IPS, and vulnerability management tool.
  • In-depth knowledge of Incident Management Frameworks and practices, including ITIL processes, incident severity classification and escalation protocols.
  • Good understanding of the cyber threat landscape, including advanced attack vectors, TTPs, threat actor profiling, and the MITRE ATT&CK framework.
  • Ability to convey complex technical findings clearly to both technical and non-technical audiences, including senior stakeholders.
  • Familiarity with relevant cybersecurity regulatory requirements, standards and frameworks, such as CyberSecurity Code of Practice (CCoP), ISO 27001, NIST, CIS Controls.
  • Experience with threat intelligence, threat hunting methodologies, and/or red/purple team engagements would be advantageous.
  • Familiarity with network protocols, operating systems (Windows and Linux), and cloud environments (AWS and Azure) would be advantageous.
  • Experience with GenAI tools, AI-assisted security platforms or AI agents for security operations use cases would be advantageous.
  • Relevant cybersecurity certifications such as GCIH, GCFA, CISSP, CISM, OSCP or equivalent would be advantageous.
  • Ability to perform on-call and standby duties as part of a rostered 24/7 support arrangement, including call-out support during nights, weekends, and public holidays.

The seniority of appointment and actual corporate job title will commensurate with individual work experiences. Position is on a 2-year full-time contract directly under the payroll of CPF Board with potential for emplacement into a permanent position.

What you can expect

Being part of #TeamCPF means embarking on a challenging and rewarding career in a progressive workplace that values productivity and growth. Here’s what awaits you:

  • Opportunities to engage in a mix of formal and informal training, keeping your skills sharp in our ever-evolving technological landscape.
  • Promotion opportunities based on your capability and on-the-job performance.
  • A vibrant community of like-minded and friendly colleagues, where collaboration and creativity thrive.
  • A hybrid work model that offers flexibility for remote work, subject to exigencies of service.
  • A workplace with flexible dress code that empowers you to choose your appropriate outfit for the day.
  • A comprehensive rewards package that includes annual leave, pro-family leave, medical and dental benefits, and access to recreational activities.
About Central Provident Fund Board

Central Provident Fund (CPF) Board is the cornerstone of Singapore's social security system, committed to serving and empowering over 4 million members in securing their retirement, healthcare, and housing needs. As an employer, we believe in developing our people to do their life’s best work through the 3Ps: Purposeful Work, Professional Growth, People & Culture. Purposeful Work – Beyond being a pension fund, we are unique in being a national social security organisation, and we serve CPF members knowing that our work we make a difference. Professional Growth – At CPF Board, you will have the opportunity to learn on the job, acquire new skills, and broaden your knowledge. Although you are joining one organisation, you will have access to many career paths in the years ahead. People and Culture – When you join CPF Board, you become part of a mission-oriented organisation with a strong culture of teamwork, collaboration, and innovation. Our people are our greatest asset, and we champion a culture of respect, diversity, and inclusivity, where every voice is heard and contributions are recognised and celebrated. We are a recipient of the Enabling Mark (Platinum) by SG Enable, we welcome candidates with disabilities and are committed to providing an inclusive and supportive work environment. Come and be a part of #TeamCPF today, to make a difference in the lives of others and in the future of Singapore. To learn more about CPF Board, visit our website at www.cpf.gov.sg.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Lead / Senior Security Incident Responder
Lead / Senior Security Incident Responder

CPF Board • Singapore

Hybrid
SGD 85,000 - 140,000
Annual leave
Medical benefits
Pro-family leave
+1
Senior / IT Security Consultant (Cybersecurity Governance & Assurance)
Senior / IT Security Consultant (Cybersecurity Governance & Assurance)

Central Provident Fund Board • Singapore

Hybrid
SGD 120,000 - 180,000
Hybrid work model
Annual leave
Pro-family leave
+1
Senior/Lead Consultant (Quality Engineering)
Senior/Lead Consultant (Quality Engineering)

Central Provident Fund Board • Singapore

On-site
SGD 120,000 - 180,000
Hybrid work model
Medical and dental benefits
Annual leave
[2027 H1 Term-time Internship] Cloud Infra Engineer Intern
[2027 H1 Term-time Internship] Cloud Infra Engineer Intern

Central Provident Fund Board • Singapore

Hybrid
SGD 13,000 - 27,000
Hybrid work model
Annual leave
Medical benefits
+3
Senior Business Auditor
Senior Business Auditor

Central Provident Fund Board • Singapore

Hybrid
SGD 80,000 - 140,000
Hybrid work
Annual leave
Medical benefits
+3
[2027 H1 Term-time Internship] Leadership Development Intern
[2027 H1 Term-time Internship] Leadership Development Intern

Central Provident Fund Board • Singapore

Hybrid
SGD 20,000 - 26,000
Annual leave
Pro-family leave
Medical and dental benefits
+1
Graduate Technology Consultant (NextGen Programme)
Graduate Technology Consultant (NextGen Programme)

Central Provident Fund Board • Singapore

Hybrid
SGD 42,000 - 56,000
Hybrid work model
Medical and dental benefits
Annual leave & pro-family leave
[2027 H1 Term-time Internship] Data Analytics Intern
[2027 H1 Term-time Internship] Data Analytics Intern

Central Provident Fund Board • Singapore

On-site
SGD 20,000 - 27,000
Hybrid work model
Formal and informal training
Annual leave
+1
[2027 H1 Term-time Internship] Application Developer Intern (CDS)
[2027 H1 Term-time Internship] Application Developer Intern (CDS)

Central Provident Fund Board • Singapore

Hybrid
SGD 18,000 - 24,000
Hybrid work model
Annual leave
Medical and dental benefits
[2027 H1 Term-time Internship] Strategy & International Engagement Intern
[2027 H1 Term-time Internship] Strategy & International Engagement Intern

Central Provident Fund Board • Singapore

Hybrid
SGD 10,000 - 17,000
Formal and informal training
Promotion opportunities
Hybrid work model
+4