Enable job alerts via email!

Manager, Cyber Security (Threat Mgmt)

SMRT Trains

Singapore

On-site

SGD 80,000 - 120,000

Full time

15 days ago

Job summary

A leading public transport operator in Singapore is seeking cybersecurity professionals to enhance security measures and manage incidents. Candidates should have at least 6 years of experience and relevant certifications. Key responsibilities include managing cybersecurity projects, detecting threats, and ensuring compliance with regulations. This role offers an opportunity to contribute to the organization's operational resilience while working in a dynamic environment.

Qualifications

  • At least 6 years of experience in Cybersecurity or related fields.
  • Experience in cybersecurity SOC operations and/or threat hunting.
  • Cybersecurity credentials such as CISSP, CISM, GCIH, and GCFE are a plus.

Responsibilities

  • Serve as a cybersecurity expert for project teams.
  • Conduct detection, triage, and analysis of potential cybersecurity threats.
  • Manage cybersecurity incidents from opening to closure.

Skills

Cybersecurity principles
Incident response
Data analysis
Leadership skills
Effective communication

Education

Degree in Information Systems or Computer Science
Job description
Company Overview

SMRT Trains Ltd was incorporated in 1987 and operates Singapore's first mass rapid transit system. Today, we manage and operate train services on the North-South Line, East-West Line, the Circle Line, the Thomson-East Coast Line, and the Bukit Panjang Light Rail Transit. With over 5,000 employees, more than 250 trains, and 141 km of rail tracks across 108 stations, we serve millions of commuters daily.

Job Purpose

Security, privacy and operational resilience are critical issues facing all organizations today. We are currently looking for qualified and capable security minded individuals to be the driving force behind SMRT's cyber security measures with the goal of enabling ongoing, secure and reliable operations across the enterprise.

Responsibilities
  • Serving as a cybersecurity expert in helping project teams comply with enterprise and cybersecurity security policies, industry regulations, and best practices.
  • Detection, triage, escalation and analysis of potential cybersecurity threats, events and incidents.
  • Management and tracking of cybersecurity incidents from opening to closure and staffing of relevant updates to SMRT management.
  • Leading cybersecurity incident after-action reviews.
  • Developing cybersecurity incident handling practices, standards and guidelines, playbooks and solutions aligned with technical and industry best practices.
  • Staying updated with the latest cybersecurity monitoring incident management tools and recommending solutions when required.
  • Leading response to existing and emerging cybersecurity threats.
  • Conducting host forensics, network forensics, and log analysis in support of incident response investigations.
  • Using tools to continuously monitor organization's digital assets to identify and remediate potential points of attack.
  • Managing and implementing cybersecurity projects assigned by GCISO.
  • Staying informed about the latest cybersecurity threats and trends.
Qualifications & Work Experience
  • Degree in Information Systems, Computer Science or equivalent.
  • At least 6 years of experience in Cybersecurity with experience in cybersecurity SOC operations and/or threat hunting.
  • Possess good understanding of OT fundamentals and OT cybersecurity practices, including but not limited to distributed control system (DCS) and supervisory control and data acquisition (SCADA) architecture, and the role of common system components.
  • Cybersecurity credentials such as CISSP, CISM, GCIH and GCFE will be advantageous.
Technical Skills
  • Good understanding of managed security services, network security, monitoring and incident response.
  • Good understanding of cybersecurity principles, governance and risk management.
  • Good understanding, and ability to translate cybersecurity threats or risk to impacts on the ICT/OT environment and appropriate mitigation techniques will be advantageous.
  • Good knowledge of cybersecurity operations, incident handling, forensic investigation.
  • Ability to analyse and interpret data from various sources to identify potential cyber security threats.
  • Strong understanding of MITRE ATT&CK and IEC/ICS MITRE frameworks.
  • Familiarity with regulatory frameworks such as the Cybersecurity Code of Practice (CCoP).
  • Experience with PLQ programming or SCADA implementation will be advantageous.
  • Ability to demonstrate good understanding of IT/OT infrastructure and security controls.
Generic Skills
  • Excellent verbal and written communication skills.
  • Strong leadership, communication, interpersonal, analytical and problem-solving skills.
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.