[LTA-ITCD] LEAD / PRINCIPAL / SENIOR CYBER THREAT INTEL ANALYST

Land Transport Authority (LTA)

Singapore

On-site

SGD 120,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

The Land Transport Authority (LTA) is seeking a Lead / Principal / Senior Cyber Threat Intel Analyst to identify, track, and analyse threats targeting critical transport IT/OT systems. The role focuses on turning global threat data into localised monitoring strategies and detection logic for our sector.

You will lead TI program development, perform proactive threat research in APAC and ICS, and coordinate with CERT to strengthen detection and incident response.

Qualifications

  • Bachelor's degree in Computer Science, Information Security, or related field.
  • At least 8 years in cybersecurity with at least 4 years in Threat Intelligence, Advanced SOC Operations, or Incident Response.
  • Professional Certifications: GIAC GCTI or CISSP.
  • Desirable certifications: GCIH, GCFA, GREM.
  • Proven mentoring of junior analysts and uplifting SOC/CERT capabilities.
  • Strong technical writing and communication, with leadership briefing skills.
  • Ability to operate in cross‑matrix and fast-paced environments.

Responsibilities

  • Intelligence Programme Development: Lead the development and continuous improvement of the Threat Intelligence (TI) function, including SOPs and CTI solution implementation.
  • Threat Research & Actor Tracking: Proactive research into TTPs in APAC and ICS.
  • Monitoring List Management: Curate and maintain high‑fidelity monitoring lists and IOCs for SIEM/EDR/Network tools.
  • Detection Engineering Support: Create YARA, Sigma, or Snort rules for detection.
  • Incident Response Integration: Act as Tier‑3 intelligence lead during critical incidents with CERT.
  • Vulnerability Intelligence: Monitor CVEs and provide risk‑based assessments to patching.
  • TTP Mapping: Map adversary behaviours to MITRE ATT&CK.
  • Stakeholder Reporting: Produce intelligence reports and monthly strategic summaries.

Skills

OSINT
Automation
Log Analysis
MITRE ATT&CK

Education

Bachelor's degree in Computer Science / Information Security
GIAC GCTI
CISSP
GCIH
GCFA
GREM

Tools

SIEM
EDR
YARA
Sigma
Snort
TIP

Job description

[What the role is]

[LTA-ITCD] LEAD / PRINCIPAL / SENIOR CYBER THREAT INTEL ANALYST

[What you will be working on]

The Cyber Threat Intelligence Analyst will be responsible for identifying, tracking, and analysing emerging cyber threats, with a focus on protecting critical IT/OT systems in the land transportation sector. This role goes beyond passive news consumption and emphasises active threat research, transforming global threat data into localised, actionable monitoring strategies and detection logic.

Key Responsibilities
  • Intelligence Programme Development: Lead the development and continuous improvement of the Threat Intelligence (TI) function, including the implementation of of Standard Operating Procedures (SOPs) and CTI solution for intelligence collection, analysis, and dissemination.
  • Threat Research & Actor Tracking : Conduct proactive research into the Tactics, Techniques, and Procedures (TTPs) of threat actors, with particular focus on the Asia‑Pacific region and Industrial Control Systems (ICS).
  • Monitoring List Management : Curate, validate, and maintain high‑fidelity monitoring lists, including Indicators of Compromise (IOCs), for ingestion into SIEM, EDR, and Network Traffic Analysis tools.
  • Detection Engineering Support : Translate research findings into technical detection artefacts, such as YARA, Sigma, or Snort rules, to strengthen proactive threat hunting and detection capabilities.
  • Incident Response Integration : Act as the Tier- 3 intelligence lead during critical incidents, providing real‑time threat context, infrastructure pivoting, and attribution support to the CERT team.
  • Vulnerability Intelligence : Monitor and prioritise newly disclosed CVEs based on the organisation’s technology stack, providing actionable, risk‑based assessments to patching and infrastructure teams.
  • TTP Mapping : Map observed adversary behaviours to the MITRE ATT&CK framework to identify visibility gaps and areas for improvement in existing security controls.
  • Stakeholder Reporting : Produce high‑quality intelligence report/ update (including Flash Alerts) for emerging or imminent threats and monthly strategic summaries for management and public transport operators.
Technical Skills & Competencies
  • OSINT & Investigation - Strong capability in conducting open‑source investigations across surface, deep, and dark web sources, including forums, code repositories, and social media, to identify leaked credentials or planned threat campaigns.
  • Automation - Proficiency in scripting to build custom scrapers, automate Threat Intelligence Platform (TIP) workflows, and manage large‑scale intelligence datasets.
  • Log Analysis - Ability to correlate threat intelligence with internal telemetry (e.g. proxy, firewall, EDR logs) to validate malicious activity and identify early indicators of compromise.
  • Framework Knowledge - Strong understanding of MITRE ATT&CK, Diamond Model of Intrusion Analysis, and Cyber Kill Chain.
[What we are looking for]
  • Knowledge in Computer Science, Computer Engineering, Information Technology or related field.
  • At least 8 years of experience in cybersecurity, with at least 4 years in Threat Intelligence, Advanced SOC Operations, or Incident Response roles.
  • Education - Bachelor’s degree in Computer Science, Information Security, or a related discipline.
  • Professional Certifications - GIAC Cyber Threat Intelligence (GCTI) or Certified Information Systems Security Professional (CISSP)
  • Desired Technical Certifications - Relevant technical certifications such as GIAC Certified Incident Handler (GCIH), GIAC Certified Forensic Analyst (GCFA) or GIAC Reverse Engineering Malware (GREM) would be advantageous.
  • Demonstrated track record in mentoring junior analysts and uplifting SOC/CERT capabilities.
  • Strong technical writing and communication skills, with the ability to brief senior leadership and executive stakeholders on complex cyber risk matters.
  • Ability to operate effectively in a cross‑matrix environment, as well as independently and decisively in a fast‑paced, high‑impact operational setting.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

[LTA-ITCD] LEAD / PRINCIPAL / SENIOR CYBER THREAT INTEL ANALYST
[LTA-ITCD] LEAD / PRINCIPAL / SENIOR CYBER THREAT INTEL ANALYST

Land Transport Authority (LTA) Singapore • Singapore

On-site
SGD 140,000 - 210,000
[LTA-ITCD] PRINCIPAL / SENIOR / EXECUTIVE CYBERSECURITY ENGINEER
[LTA-ITCD] PRINCIPAL / SENIOR / EXECUTIVE CYBERSECURITY ENGINEER

Land Transport Authority (LTA) Singapore • Singapore

On-site
SGD 120,000 - 180,000
[LTA-ITCD] LEAD / PRINCIPAL / SENIOR CYBER THREAT INTEL ANALYST
[LTA-ITCD] LEAD / PRINCIPAL / SENIOR CYBER THREAT INTEL ANALYST

Land Transport Authority • Singapore

On-site
SGD 120,000 - 180,000
Threat Intelligence Analyst
Threat Intelligence Analyst

SCIENTE • Singapore

On-site
SGD 120,000 - 180,000
Incident Manager and Cyber Intelligence
Incident Manager and Cyber Intelligence

Commerzbank Aktiengesellschaft • Singapore

On-site
SGD 120,000 - 180,000
[LTA-ITCD] PRINCIPAL / SENIOR / EXECUTIVE CYBERSECURITY ENGINEER
[LTA-ITCD] PRINCIPAL / SENIOR / EXECUTIVE CYBERSECURITY ENGINEER

Land Transport Authority (LTA) • Singapore

On-site
SGD 110,000 - 190,000
Threat Intelligence Analyst
Threat Intelligence Analyst

IMDA • Singapore

On-site
SGD 90,000 - 150,000
Threat Intelligence Analyst (JD#11198)
Threat Intelligence Analyst (JD#11198)

SCIENTE INTERNATIONAL PTE. LTD. • Singapore

On-site
SGD 120,000 - 180,000
Vice President, Cyber Threat Analyst
Vice President, Cyber Threat Analyst

Singapore Exchange Limited • Singapore

On-site
SGD 120,000 - 170,000
Senior Analyst, Threat Detection and Response
Senior Analyst, Threat Detection and Response

SATS Ltd. • Singapore

On-site
SGD 110,000 - 140,000