SOC Tier 3 Analyst (GTS - Command Centre)

OCBC Bank

Singapore

On-site

SGD 120,000 - 180,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Competitive base salary
Holistic benefits package
Learning and development opportunities
Community initiatives

Job summary

OCBC Bank is seeking an experienced Cyber Engineering - Risk professional to safeguard systems and networks against cyber threats in Singapore. You will guide Tier 1/2 SOC staff, manage daily operations and lead investigations with coordination across stakeholders.

You will develop repeatable runbooks, refine detection use cases and contribute to AI-assisted SOC workflows, leveraging SIEM, SOAR, EDR/XDR and related tools. Banking expertise is a plus.

Qualifications

  • 8+ years in a SOC or related cybersecurity field.
  • 3+ years as a senior SOC analyst, cyber incident responder, threat hunter, or equivalent.
  • Hands-on experience with SOC tools SIEM, SOAR, EDR, XDR or UEBA.
  • Strong proficiency in SIEM, network/host log analysis.
  • Knowledge of Windows, Linux, AD, cloud/SaaS logs, endpoint artefacts and attacker techniques.
  • Experience investigating cyber threats and incident response.
  • Experience developing detection content and SIEM/SOAR use cases or playbooks.
  • Ability to write clear technical and management-facing reports.
  • Familiarity with AI-assisted security operations a plus.
  • Experience in banking/financial services or regulated environments a plus.

Responsibilities

  • Provide guidance to Tier 1 and Tier 2 SOC analysts.
  • Assist in managing daily SOC operations.
  • Collaborate with stakeholders to support cyber defence strategy.
  • Lead investigations of incidents and coordinate response activities.
  • Prepare incident summaries, timelines, post-incident reports and lessons‑learned docs.
  • Develop runbooks, playbooks and analyst guides for monitoring and remediation.
  • Review detection effectiveness and coverage gaps; propose improvements.
  • Support development and finetuning of detection use cases and AI-assisted workflows.
  • Optimize usage of SOC tools and evaluate new technologies.

Skills

SOC experience
Incident response
Threat hunting
Tabletop exercises

Education

Cybersecurity certifications (GCIH/GCIA/GCFA/GNFA/GREM/OSCP)

Tools

SIEM
SOAR
EDR
XDR
UEBA
MITRE ATT&CK

Job description

WHO WE ARE

As Singapore’s longest established bank, we have been dedicated to enabling individuals and businesses to achieve their aspirations since 1932. By taking the time to truly understand people, we provide support, services, solutions, and career paths that meet their individual needs and desires. Today, we’re on a journey of transformation. Leveraging technology and creativity to become a future‑ready learning organisation. Our strategic ambition is to be Asia’s leading financial services partner for a sustainable future. Build the bank of the future. Innovate the way we deliver financial services. Work in friendly, supportive teams. Build lasting value in your community. Help people grow their assets, business, and investments. Take your learning as far as you can or simply enjoy a vibrant, future‑ready career. Your Opportunity Starts Here.

We offer private banking services through our wholly‑owned subsidiary, Bank of Singapore, which operates on a unique open‑architecture product platform to source for the best‑in‑class products to meet its clients’ goals. Our insurance subsidiary, Great Eastern Holdings, is the oldest and most established life insurance group in Singapore and Malaysia.

Why Join Protecting our customers' assets and data is at the heart of everything we do at OCBC.

As a Cyber Engineering - Risk professional, you'll play a critical role in safeguarding our systems and networks from cyber threats. You'll be part of a team that's shaping the future of cybersecurity in the financial industry.

What you do
  • Provide guidance to Tier 1 and Tier 2 SOC analysts.
  • Assist in managing daily SOC operations.
  • Collaborate with other stakeholders to support the overall cyber defence strategy.
  • Prioritise tasks appropriately and formulate clear responses or recommendations to stakeholders in a fast‑paced environment.
  • Lead investigation of cyber security incidents and support coordinated response activities.
  • Prepare incident summaries, technical timelines, post‑incident reports and lessons‑learnt documentation for technical and non‑technical audiences.
  • Develop repeatable and efficient processes, runbooks and analyst guides to monitor, detect, analyse and remediate potential cyber security incidents.
  • Review detection effectiveness, false positives, coverage gaps and recurring alert patterns, and recommend improvements to prevention, detection and response capabilities.
  • Support development, validation and finetuning of detection use cases, SOAR playbooks and AI‑assisted SOC workflows.
  • Optimise usage of SOC tools, including SIEM, SOAR, EDR/XDR and AI‑enabled SOC platforms, and evaluate new technologies where required.
  • Support threat hunting across security‑relevant data sets based on threat intelligence, MITRE ATT&CK techniques, emerging attacker behaviours and identified control gaps.
  • Identify opportunities where AI‑assisted triage, automation or agentic workflows can safely reduce analyst effort, improve investigation consistency or accelerate response.
  • Participate in tabletop exercises, purple team activities, detection reviews, operating reviews and post‑incident retrospectives.
  • Identify opportunities for SOC improvements, including metrics definition, after‑action reviews, playbook enhancements, AI‑assisted workflow improvements and analyst capability uplift.
Who you are
  • 8 or more years of experience in a SOC environment or related cybersecurity field.
  • At least 3 years of experience as a senior SOC analyst, Tier 3 analyst, cyber incident responder, threat hunter, or equivalent escalation role.
  • Strong hands‑on experience with SOC tools such as SIEM, SOAR, EDR, XDR or UEBA.
  • Strong proficiency in SIEM, network traffic, host event, and security event log analysis.
  • Strong understanding of Windows, Linux, Active Directory, identity compromise, network protocols, cloud/SaaS logs, endpoint artefacts, and common attacker techniques.
  • Experience investigating cyber threats and managing cyber security incidents, including hands‑on log analysis and host/network forensic analysis in support of incident response.
  • Experience designing, developing, deploying, and finetuning security monitoring use cases based on frameworks such as MITRE ATT&CK.
  • Experience developing threat detection content and SIEM/SOAR use cases or playbooks.
  • Ability to write clear technical and management‑facing reports.
  • Ability to prioritise effectively, manage competing operational demands, and make sound escalation decisions.
  • Familiarity with AI‑assisted security operations, SOC copilots, automated enrichment, agentic workflows or machine‑assisted triage is a plus.
  • Experience in banking, financial services, critical infrastructure, or highly regulated environments is a plus.
  • Relevant certifications such as GCIH, GCIA, GCFA, GNFA, GREM, OSCP or equivalent are preferred.
What we offer
  • Competitive base salary.
  • A suite of holistic, flexible benefits to suit every lifestyle.
  • Community initiatives.
  • Industry‑leading learning and professional development opportunities.
  • Your wellbeing, growth and aspirations are every bit as cared for as the needs of our customers.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

SOC Tier 3 Analyst (GTS - Command Centre)
SOC Tier 3 Analyst (GTS - Command Centre)

OCBC • Singapore

On-site
SGD 80,000 - 120,000
Flexible benefits to suit every lifestyle
Professional development opportunities
Community initiatives
SOC Tier 3 Analyst (GTS - Command Centre)
SOC Tier 3 Analyst (GTS - Command Centre)

OCBC company • Singapore

On-site
SGD 80,000 - 120,000
Competitive base salary
Flexible benefits
Professional development opportunities
Senior SOC Engineer (GTS - Command Centre)
Senior SOC Engineer (GTS - Command Centre)

OCBC company • Singapore

On-site
SGD 80,000 - 120,000
Competitive base salary
Holistic flexible benefits
Professional development opportunities
Red Team Analyst (AVP)
Red Team Analyst (AVP)

OCBC Group • Singapore

On-site
SGD 140,000 - 210,000
Competitive salary
Flexible benefits
Learning & development opportunities
+1
Cyber Threat Analyst
Cyber Threat Analyst

OCBC company • Singapore

On-site
SGD 60,000 - 80,000
Competitive base salary
Holistic, flexible benefits
Industry-leading learning and professional development opportunities
Threat Hunting Analyst (AVP)
Threat Hunting Analyst (AVP)

OCBC (Singapore) • Singapore

On-site
SGD 120,000 - 180,000
Cyber Security Specialist (Application/Infrastructure/Cloud)
Cyber Security Specialist (Application/Infrastructure/Cloud)

OCBC • Singapore

On-site
SGD 90,000 - 130,000
Competitive base salary
Flexible benefits
Professional development opportunities
Threat Hunting Analyst (AVP)
Threat Hunting Analyst (AVP)

OCBC Bank • Singapore

On-site
SGD 120,000 - 180,000
Competitive salary
Flexible benefits
Community initiatives
+2
Cyber Threat Analyst
Cyber Threat Analyst

OCBC Bank • Singapore

On-site
SGD 90,000 - 130,000
Competitive base salary
Holistic benefits package
Community initiatives
+2
Cyber Security Architect (Application/Infrastructure/Cloud)
Cyber Security Architect (Application/Infrastructure/Cloud)

OCBC Bank • Singapore

On-site
SGD 120,000 - 180,000
Competitive base salary
Holistic, flexible benefits
Learning opportunities
+1