[LTA-ITCD] LEAD / PRINCIPAL / SENIOR CYBER THREAT INTEL ANALYST

Land Transport Authority

Singapore

On-site

SGD 120,000 - 180,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Land Transport Authority in Singapore seeks a Lead/Principal/Senior Cyber Threat Intel Analyst to lead the Threat Intelligence function across the transport sector.

You will perform proactive threat research, track actors, manage IOC lists for SIEM/EDR, and develop detection artefacts (YARA, Sigma, Snort) to enable proactive hunting.

Strong MITRE ATT&CK, Diamond Model, and cyber risk reporting skills are essential, along with mentoring and clear leadership for cross‑functional teams.

Qualifications

  • 8+ years in cybersecurity with at least 4 years in Threat Intelligence or IR.
  • Bachelor’s degree in Computer Science, Information Security or related field.
  • GIAC GCTI or CISSP (or equivalent) certifications.
  • Mentoring junior analysts and uplifting SOC/CERT capabilities.
  • Strong technical writing and ability to brief executives.
  • Cross‑matrix and fast‑paced operational setting experience.

Responsibilities

  • Intelligence Programme Development: lead TI function, SOPs, and CTI solutions.
  • Threat Research & Actor Tracking: research TTPs in APAC and ICS contexts.
  • Monitoring List Management: curate IOC lists for SIEM/EDR analytics.
  • Detection Engineering Support: translate findings into YARA/Sigma/Snort rules.
  • Incident Response Integration: Tier-3 intel lead during critical incidents.
  • Vulnerability Intelligence: monitor CVEs and advise patching teams.
  • TTP Mapping: align with MITRE ATT&CK framework.
  • Stakeholder Reporting: produce executive‑level threat updates.
  • OSINT & Investigation: open-source investigations across deep/dark web.
  • Automation: scripting for TIP workflows and data handling.
  • Log Analysis: correlate TI with internal telemetry.
  • Framework Knowledge: MITRE ATT&CK, Diamond Model, Cyber Kill Chain.

Skills

Threat intelligence
Incident response
OSINT
Log analysis
Scripting
MITRE ATT&CK
Threat hunting
Detection engineering

Education

Bachelor’s degree in Computer Science/Information Security
GIAC Cyber Threat Intelligence (GCTI) or CISSP

Tools

YARA
Sigma
Snort
SIEM
EDR
Threat Intelligence Platform (TIP)

Job description

[LTA-ITCD] LEAD / PRINCIPAL / SENIOR CYBER THREAT INTEL ANALYST

Land Transport Authority

04-12 year(s)

Fixed Terms, Full-time

Closing on 16 Sep 2026

0 Applicant(s)

What the role is

[LTA-ITCD] LEAD / PRINCIPAL / SENIOR CYBER THREAT INTEL ANALYST

What you will be working on

The Cyber Threat Intelligence Analyst will be responsible for identifying, tracking, and analysing emerging cyber threats, with a focus on protecting critical IT/OT systems in the land transportation sector. This role goes beyond passive news consumption and emphasises active threat research, transforming global threat data into localised, actionable monitoring strategies and detection logic.

Key Responsibilities
  • Intelligence Programme Development: Lead the development and continuous improvement of the Threat Intelligence (TI) function, including the implementation of of Standard Operating Procedures (SOPs) and CTI solution for intelligence collection, analysis, and dissemination.
  • Threat Research & Actor Tracking : Conduct proactive research into the Tactics, Techniques, and Procedures (TTPs) of threat actors, with particular focus on the Asia‑Pacific region and Industrial Control Systems (ICS).
  • Monitoring List Management : Curate, validate, and maintain high‑fidelity monitoring lists, including Indicators of Compromise (IOCs), for ingestion into SIEM, EDR, and Network Traffic Analysis tools.
  • Detection Engineering Support : Translate research findings into technical detection artefacts, such as YARA, Sigma, or Snort rules, to strengthen proactive threat hunting and detection capabilities.
  • Incident Response Integration : Act as the Tier- 3 intelligence lead during critical incidents, providing real‑time threat context, infrastructure pivoting, and attribution support to the CERT team.
  • Vulnerability Intelligence : Monitor and prioritise newly disclosed CVEs based on the organisation’s technology stack, providing actionable, risk‑based assessments to patching and infrastructure teams.
  • TTP Mapping : Map observed adversary behaviours to the MITRE ATT&CK framework to identify visibility gaps and areas for improvement in existing security controls.
  • Stakeholder Reporting : Produce high‑quality intelligence report/ update (including Flash Alerts) for emerging or imminent threats and monthly strategic summaries for management and public transport operators.
  • OSINT & Investigation - Strong capability in conducting open‑source investigations across surface, deep, and dark web sources, including forums, code repositories, and social media, to identify leaked credentials or planned threat campaigns.
  • Automation - Proficiency in scripting to build custom scrapers, automate Threat Intelligence Platform (TIP) workflows, and manage large‑scale intelligence datasets.
  • Log Analysis - Ability to correlate threat intelligence with internal telemetry (e.g. proxy, firewall, EDR logs) to validate malicious activity and identify early indicators of compromise.
  • Framework Knowledge - Strong understanding of MITRE ATT&CK, Diamond Model of Intrusion Analysis, and Cyber Kill Chain.
What we are looking for
  • Knowledge in Computer Science, Computer Engineering, Information Technology or related field.
  • At least 8 years of experience in cybersecurity, with at least 4 years in Threat Intelligence, Advanced SOC Operations, or Incident Response roles.
  • Education - Bachelor’s degree in Computer Science, Information Security, or a related discipline.
  • Professional Certifications - GIAC Cyber Threat Intelligence (GCTI) or Certified Information Systems Security Professional (CISSP)
  • Desired Technical Certifications - Relevant technical certifications such as GIAC Certified Incident Handler (GCIH), GIAC Certified Forensic Analyst (GCFA) or GIAC Reverse Engineering Malware (GREM) would be advantageous.
  • Demonstrated track record in mentoring junior analysts and uplifting SOC/CERT capabilities.
  • Strong technical writing and communication skills, with the ability to brief senior leadership and executive stakeholders on complex cyber risk matters.
  • Ability to operate effectively in a cross‑matrix environment, as well as independently and decisively in a fast‑paced, high‑impact operational setting.
About Land Transport Authority

The Land Transport Authority (LTA) is a statutory board under Ministry of Transport that spearheads land transport developments in Singapore. We are seeking dynamic, energetic, highly motivated, passionate and qualified professionals to join us.Many opportunities & challenges await those who are keen on an exciting career to realise our commitment to envision & implement an integrated transport system.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

[LTA-TRO] CYBERSECURITY ENGINEER, INTELLIGENT TRANSPORT SYSTEMS DEVELOPMENT
[LTA-TRO] CYBERSECURITY ENGINEER, INTELLIGENT TRANSPORT SYSTEMS DEVELOPMENT

Land Transport Authority • Singapore

On-site
SGD 60,000 - 90,000
Senior Cyber Threat Intelligence Strategist
Senior Cyber Threat Intelligence Strategist

Land Transport Authority (LTA) Singapore • Singapore

On-site
SGD 140,000 - 210,000
[LTA-ITCD] LEAD / PRINCIPAL / SENIOR CYBER THREAT INTEL ANALYST
[LTA-ITCD] LEAD / PRINCIPAL / SENIOR CYBER THREAT INTEL ANALYST

Land Transport Authority (LTA) • Singapore

On-site
SGD 120,000 - 180,000
Threat Intelligence Lead — Cyber & ICS Security
Threat Intelligence Lead — Cyber & ICS Security

Land Transport Authority (LTA) • Singapore

On-site
SGD 120,000 - 180,000
[LTA-ITCD] PRINCIPAL / SENIOR / EXECUTIVE CYBERSECURITY ENGINEER
[LTA-ITCD] PRINCIPAL / SENIOR / EXECUTIVE CYBERSECURITY ENGINEER

Land Transport Authority (LTA) Singapore • Singapore

On-site
SGD 120,000 - 180,000
[LTA-ITCD] LEAD / PRINCIPAL / SENIOR CYBER THREAT INTEL ANALYST
[LTA-ITCD] LEAD / PRINCIPAL / SENIOR CYBER THREAT INTEL ANALYST

Land Transport Authority (LTA) Singapore • Singapore

On-site
SGD 140,000 - 210,000
[LTA-TRO] MANAGER, INTELLIGENCE
[LTA-TRO] MANAGER, INTELLIGENCE

Land Transport Authority • Singapore

On-site
SGD 60,000 - 90,000
[LTA-ITCD] PRINCIPAL / SENIOR / EXECUTIVE CYBERSECURITY ENGINEER
[LTA-ITCD] PRINCIPAL / SENIOR / EXECUTIVE CYBERSECURITY ENGINEER

Land Transport Authority (LTA) • Singapore

On-site
SGD 110,000 - 190,000
Senior Cyber Threat Intel Lead
Senior Cyber Threat Intel Lead

Land Transport Authority • Singapore

On-site
SGD 120,000 - 180,000
Principal Cybersecurity Incident Response Lead
Principal Cybersecurity Incident Response Lead

Land Transport Authority (LTA) Singapore • Singapore

On-site
SGD 120,000 - 180,000