Senior Information Security Incident Response Lead
6 days ago
**Make an impact with NTT DATA**
Join a company that is pushing the boundaries of what is possible. We are renowned for our technical excellence and leading innovations, and for making a difference to our clients and society. Our workplace embraces diversity and inclusion - it’s a place where you can grow, belong and thrive.
We are seeking an experienced Senior Incident Response Specialist to lead and execute advanced cybersecurity investigations. This is not an entry-level SOC role. You will be responsible for detecting, analyzing, and responding to security incidents, proactively hunting for threats, conducting forensic investigations, and contributing to vulnerability management through red teaming or penetration testing where applicable. Strong proficiency with EDR solutions, SIEM log platforms, incident case management tools, and forensic analysis tools is essential.
**Key Responsibilities**
- Lead and manage complex security incidents, acting as a key contact for stakeholders.
- Perform deep analysis of security alerts to identify, mitigate, and remediate threats.
- Conduct forensic investigations on compromised hosts, networks, and cloud environments.
- Proactively hunt for adversarial activity and anomalous behaviors across large datasets.
- Analyze malware samples (basic level) to determine functionality, impact, and mitigation strategies.
- Develop and refine detection rules, improving alert fidelity and response workflows.
- Contribute to threat intelligence gathering, analyzing attack patterns, and enhancing defensive strategies.
- Participate in red teaming or penetration testing activities to identify and remediate vulnerabilities.
- Provide strategic recommendations for improving the organization’s security posture.
- Create detailed incident reports, threat intelligence assessments, and executive summaries.
- Mentor and provide guidance to junior analysts, fostering continuous improvement in IR methodologies.
**Qualifications & Requirements**
**Education & Experience**:
- Bachelor's or Master's degree in Computer Science, Cybersecurity, or a related field.
- Minimum of 5 years of experience in cybersecurity, with at least 2 years in incident response, threat hunting, or forensic analysis.
**Technical Expertise**:
- Extensive experience responding to targeted attacks from APT groups, cybercriminals, and nation-state actors.
- Strong forensic analysis skills across Windows, Linux, and macOS systems.
- Expertise in network forensics, traffic analysis, and packet inspection (Wireshark, Zeek).
- Proficiency in SIEM platforms (Splunk, Sentinel, QRadar) and EDR solutions (CrowdStrike, Microsoft Defender ATP).
- Knowledge of malware analysis techniques, including static and dynamic analysis.
- Familiarity with cloud security investigations (AWS, Azure, GCP).
- Strong scripting skills in Python, PowerShell, or similar languages for automation.
- Understanding of security architecture, authentication mechanisms, and enterprise IT operations is a plus.
- Experience with vulnerability management, red teaming, or penetration testing is a plus.
- Familiarity with MITRE ATT&CK framework and various cyber threat intelligence methodologies.
**Preferred Certifications**:
- GIAC (GCFA, GNFA, GCIH, GCIA, GREM)
- CISSP (Certified Information Systems Security Professional)
- CEH (Certified Ethical Hacker)
- OSCP (Offensive Security Certified Professional)
- Cloud Security Certifications (AWS Security Specialty, Microsoft Azure Security)
**Key Competencies**:
- Strong analytical and problem-solving skills in high-pressure situations.
- Ability to manage multiple investigations efficiently while meeting deadlines.
- Excellent verbal and written communication skills, with the ability to convey technical details to varied audiences.
- Strong team collaboration and leadership skills, with a proactive approach to knowledge sharing.
- Ability to work in a fast-paced environment and adapt to evolving threats and challenges.
**Workplace type**:
**About NTT DATA**
**Equal Opportunity Employer
-
Consultant, Cyber Hunt
6 days ago
Kallang, Singapore Ensign InfoSecurity Full timeEnsign is hiring ! **Responsibilities**: - Collaborate with the team and be responsible for the delivery of client engagements, providing updates to the engagement and/or team lead - Contribute to the project delivery of the Ensign Consulting - Threat Hunting & Response business; aligns with the project schedule for deliverables and milestones; adaptable...
-
Security Officer
2 days ago
Kallang, Singapore Elitez Security Pte Ltd Full timeTiming: 8 to 8 Basic Security officer role - FCC Duties - Loading Bay duties - Patrol/clocking - Incident management **Job Types**: Full-time, Permanent, Freelance **Salary**: Up to $2,700.00 per month **Benefits**: - Professional development Schedule: - Day shift - Night shift
-
IT Security Manager
2 days ago
Kallang, Singapore Ensign InfoSecurity Full timeEnsign is hiring ! The professional will be joining a top team in delivering complex Cyber Security solutions to defend against cyber threats of the world. We are looking for a dedicated team player who wants to make a career in the Vulnerability Management (VM), Data Protection or Governance, Risk and Compliance (GRC) domain. You will be the second line...
-
Security Platform Engineer
2 days ago
Kallang, Singapore NTT DATA Full time**Make an impact with NTT DATA** Join a company that is pushing the boundaries of what is possible. We are renowned for our technical excellence and leading innovations, and for making a difference to our clients and society. Our workplace embraces diversity and inclusion - it’s a place where you can grow, belong and thrive. **Your day at NTT DATA** This...
-
Incident Manager
2 weeks ago
Kallang, Singapore Jobline Resources Pte Ltd Full time**Responsibilities**: - Manages technology incidents impacting group businesses. - Work with relevant business & technology group/units to comply with the Incident and Problem Management processes and procedures, to facilitate and improve incident recognition, logging, assignment, tracking, status notification, escalation, documentation, and management...
-
Lead Consultant, Cyber Security
10 hours ago
Kallang, Singapore Ingram Micro Full timeCome join our team where you’ll make technology happen in surprising ways. Let’s shape tomorrow - it’ll be a fun journey! **Delivery Responsibilities**: - Lead technical teams and mentor junior consultants, internal stakeholders, and clients while driving internal initiatives and strategic projects - Facilitate and lead design and business workshops...
-
Senior Security Analyst L3
4 days ago
Kallang, Singapore Ensign InfoSecurity Full timeEnsign is hiring ! **Responsibilities**: - Baseline for normal operations and detect abnormalities - Perform hunt for anomalous events and investigate compromised systems. - Manage research related to threat hunting adversaries in our environments. - Participate effectively in investigations related to threat hunting adversaries in our environments -...
-
Security Analyst L3
1 week ago
Kallang, Singapore Ensign InfoSecurity Full timeEnsign is hiring ! **Responsibilities**: - Setup and operating Managed Endpoint and Detection Response (MDR) program and proposing enhancement to achieve better efficiency/ effectiveness - Operating Network Traffic Analytics (NTA) program, identification of abnormalities in client’s environment - Performs threat hunting within the clients’ technology...
-
Senior Team Lead, Technical Services
1 week ago
Kallang, Singapore NTT DATA Full time**Make an impact with NTT DATA** Join a company that is pushing the boundaries of what is possible. We are renowned for our technical excellence and leading innovations, and for making a difference to our clients and society. Our workplace embraces diversity and inclusion - it’s a place where you can grow, belong and thrive. **Your day at NTT DATA** The...
-
Associate Cyber Security Operations Engineer
2 weeks ago
Kallang, Singapore Ensign InfoSecurity (Singapore) Pte. Ltd. Full timeResponsibilitiesProvide day-to-day operational support and maintenance of the Cyber Security service in a 24/7 staffed OperationsEnsure all incident escalation are properly tracked, escalated and with proper closureImplement configuration changes and process requests from clientsManage and maintain the security policies for the serviceManage device tuning...