Principal Incident Responder

2 days ago


Singapore LSEG (London Stock Exchange Group) Full time

LSEG Security Operations is a central function employing people, process and technology to continuously monitor and respond to cyber security incidents. Security Operations spans multiple domains including cyber threat intelligence, cyber threat detection, data loss prevention and cyber incident response.

This role will act help to protect the Group from cyber threats that seek to impact business operations.

LSEG (London Stock Exchange Group) is more than a diversified global financial markets infrastructure and data business. We are dedicated, open-access partners with a dedication to excellence in delivering the services our customers expect from us. With extensive experience, deep knowledge and worldwide presence across financial markets, we enable businesses and economies around the world to fund innovation, manage risk and create jobs.

It’s how we’ve contributed to supporting the financial stability and growth of communities and economies globally for more than 300 years. Through a comprehensive suite of trusted financial market infrastructure services - and our open-access model - we provide the flexibility, stability and trust that enable our customers to pursue their ambitions with confidence and clarity.

Responsibilities
- Lead and be the people leader for the Incident Response team in the APAC region.
- Act as a focal technical lead on incident events and incidents.
- Provide technical, hands-on incident investigation and support and serve as a main point of contact with management.
- Conduct complex digital forensics and advanced malware analysis investigations.
- Preserve, harvest and analyse data from computer systems including desktops, servers (virtual/physical) and mobiles.
- Handle the chain of custody for all evidence collected during incidents, security, and forensic investigations.
- Build and enhance defensive capabilities using monitoring technologies including SIEM and EDR.
- Perform proactive threat hunting to identify cyber threats.
- Train Attack Monitoring analysts in the steps to take to investigate and resolve computer security incidents.
- Serve as an escalation point for security incidents.
- Facilitate, document and manage root cause analysis and post-mortem process including tracking all action items and lessons learned through to implementation.
- Enhance the defensive capabilities of the GSOC through detection use case engineering and threat modelling.

Experience
- Must have significant experience of working in incident response such as within SOCs, digital forensics, or equivalent roles.
- Experience performing complex digital forensic and incident response investigations.
- Must have proven experience of leading teams.
- Deep knowledge of common operating systems (e.g. macOS, Windows, Unix, Linux) and their associated file systems.
- Proficient with industry-standard incident response toolsets such as EnCase, X-Ways, FTK and Volatility.
- Knowledge of cloud technologies and cloud infrastructures such as AWS, GCP, Azure, O365.
- Experience with conducting log analysis across different components of a typical organisation estate (e.g. OS, network, cloud).
- Deep understanding of advanced cyber adversary tools, techniques and procedures.
- Strong understand of Security Operations Centre (SOC) practices, processes and procedures.
- Incident response process and procedures including common frameworks (e.g. NIST, SANS).
- Automating and refining incident response procedures/playbooks to maximise SOC efficiencies.
- Policies, standards and security frameworks, NIST, CIS.

Preferred
- Preferred experience and knowledge of cyber security in global financial services and/or regulated environments.
- Experience in driving cyber incident response capabilities using domain-expertise and through constant innovation.
- Digital forensics/incident response certification(s) such as SANS, CREST or equivalent.
- Competent with one or more programming languages (e.g. Python, PowerShell, Java, C#).
- Ability to work with a sense of urgency while remaining calm under pressure.
- Strong verbal and written communication and collaboration skills.
- Delivers feedback in a way useful for an individual and a team for growth.
- Adapts messaging and presentation styles to the needs of a different audiences.
- Ability to understand and weigh business risks and communicate appropriate information and security measures.

Join us and be part of a team that values innovation, quality, and continuous improvement. If you're ready to take your career to the next level and make a significant impact, we'd love to hear from you.

LSEG is a leading global financial markets infrastructure and data provider. Our purpose is driving financial stability, empowering economies and enabling customers to create sustainable growth.

Our purpose is the foundation on which our culture is built. Our values of Integrity, Partnership, Excellence and Change underpin our purpose and set the standard for everything we do, eve



  • Singapore London Stock Exchange Group Full time $100,000 - $150,000 per year

    Principal Incident Responder (GSOC)LSEG Security Operations is a central function employing people, process and technology to continuously monitor and respond to cyber security incidents. Security Operations spans multiple domains including cyber threat intelligence, cyber threat detection, data loss prevention and cyber incident response.This role will act...


  • Singapore LSEG (London Stock Exchange Group) Full time $100,000 - $150,000 per year

    Principal Incident Responder (GSOC)LSEG Security Operations is a central function employing people, process and technology to continuously monitor and respond to cyber security incidents. Security Operations spans multiple domains including cyber threat intelligence, cyber threat detection, data loss prevention and cyber incident response.This role will act...


  • Singapore UBS Full time

    Singapore Risk Group Functions **Job Reference #** 247495BR **City** Singapore **Job Type** Full Time **Your role** Are you from the World of Cyber? Are you the one to defend the organization against advance threat? Do you have what it takes to coordinate and respond to cyber-attacks? - respond to cyber security incidents covering all phases...


  • Singapore UBS Full time

    Singapore - Information Technology (IT) - Group Functions **Job Reference #** - 263525BR **City** - Singapore **Job Type** - Full Time **Your role** - Are you from the World of Cyber? Are you the one to defend the organization against advance threat? Do you have what it takes to coordinate and respond to cyber-attacks? - respond to cyber security...


  • Central Singapore BNP Paribas Full time

    **POSITION PURPOSE**: APAC Production Security teams are responsible for multiple IT Security activities for BNP Paribas in Asia Pacific region, such as: IT Production Security Governance, PMO & Risks Network Security and Security Design & Architecture Vulnerability & Compliance Management IAM Production Production CSIRT, Detection & SIEM...


  • Singapore UBS Full time

    Singapore - Information Technology (IT) - Group Functions **Job Reference #** - 326168BR **City** - Singapore **Job Type** - Full Time **Your role** - Are you keen on working in world class Cyber Security Operations Center for one of the best Swiss private banks? Do you have related experience and are willing to take it further by learning how to defend...


  • Singapore SIX FINANCIAL INFORMATION SINGAPORE PTE. LTD. Full time

    SIX operates the infrastructure underpinning the Swiss financial sector and offers a comprehensive range of services around the world in the fields of securities trading and settlement, financial information and payment transactions.- **JJob Introduction The SIX Security Monitoring & Incident Response (SMIR) is the central incident response team for the SIX...


  • Singapore Ministry of Defence Singapore Full time $60,000 - $120,000 per year

    Info-communications Media Development AuthorityFixed TermsWhat the role is.ResponsibilitiesWork with current team and ensure smooth operations of daily operationsWork with DFIR analysts to ensure timely response to security incidents, root cause analysis and closure of incidentInvestigate cybersecurity incidents that may involve digital forensic analysis,...


  • Singapore Xcellink Pte Ltd Full time

    Lead the response to cybersecurity incidents, including malware infections, data breaches, and insider threats. Perform real-time and retrospective analysis of security events to identify threats Coordinate with MSSP Security Operations Centre (SOC) teams for monitoring and alerting. Develop and document incident response plans and playbooks. Should be...


  • Singapore Palo Alto Networks Full time

    Palo Alto Networks is committed to our mission of protecting the digital way of life. We are a company built on challenging and disrupting the way things are done, and we’re looking for innovators who are as committed to shaping the future of cybersecurity as we are. Your Career As a Principal Consultant in Unit 42, the individual will be responsible for...