Search Jobs

Search by job, company or skills

AI Cyber Defence Specialist

AI Cyber Defence Specialist

Singtel
5-7 Years
  • Posted 15 hours ago
  • Be among the first 10 applicants

Job Description

We are seeking an Artificial Intelligence (AI) Cyber Defence Specialist to lead the organisation's threat management capabilities across Security Operations, Vulnerability Management, Threat Hunting and Digital Forensics & Incident Response (DFIR) by leveraging AI.

Reporting to the CISO Office, the candidate will be accountable for the responsibilities as stated below. The candidate will ensure these capabilities are intelligence-led using AI, measurable and aligned with applicable regulatory and industry expectations, including (but not limited to) the Cybersecurity Act and applicable Cybersecurity Codes of Practice (CCoP).

Roles and Responsibilities:

  • Lead and manage the 24x7 Security Operations Centre (SOC) operations, including any Managed Security Service Provider (MSSP) or MDR partner, ensuring security events are monitored, triaged, escalated and resolved within defined Service Level Agreements (SLAs).
  • Own the SOC operating model and its associated processes – tiered analyst structure, shift roster, playbooks, runbooks and escalation matrix – and drive measurable improvement in SOC maturity using AI.
  • Drive detection engineering across SIEM, EDR/XDR, identity and cloud-native security tooling; develop, tune and retire use cases mapped to MITRE ATT&CK to increase detection coverage and reduce false positives.
  • Ensure log source coverage across critical assets – endpoints, servers and networks.
  • Oversee SOAR automation to accelerate alert enrichment, triage and containment actions.
  • Define and report SOC KPIs and KRIs (e.g. MTTD, MTTR, ATT&CK coverage, alert severity, SLA adherence) to the CISO and senior management.
  • Lead the organisation's response to critical zero-day and emerging vulnerabilities, including rapid exposure assessment, compensating controls and emergency patching coordination.
  • Establish and lead a structured, hypothesis-driven threat hunting programme based on threat intelligence, MITRE ATT&CK and anomalies observed in environment telemetry.
  • Develop hypotheses and techniques and execute hunts to identify undetected threats across the environment; convert hunt findings into new or improved detections.
  • Gather and analyse cyber threat information and intelligence from commercial feeds, government sources (e.g. CSA / Sectoral Lead) and open sources to derive insights on attack tactics, techniques and procedures (TTPs), campaigns and threat actor profiles relevant to the organisation and its sector.
  • Operationalise threat intelligence, including IOC ingestion and management of the threat intelligence platform (TIP).
  • Act as a security incident responder for cyber incidents, coordinating technical response, containment, eradication and recovery across internal teams and external partners.
  • Manage vendor relationships, contracts and performance for MSSP/MDR, IR retainer, maintenance of the cybersecurity technology stack and security tooling providers; plan and manage the cyber defence budget.
  • Present the organisation's threat landscape, incident trends and cyber defence posture to the CISO.
  • Support internal and external audits and regulatory inspections, providing evidence of control design and operating effectiveness.
  • Proactively coordinate with technical and business stakeholders and manage internal and external partnerships during a security incident.
  • Any other assigned duties when there is a change in business requirements and scope of work.

What we're looking for...

You embrace continuous learning and use lessons from challenges to improve future outcomes. You can inspire and motivate others to deliver the organisation's vision. You view obstacles as problems to be solved. You are driven by the desire to deliver positive outcomes for your internal customer – Singtel Digital InfraCo.

What you need to have:

  • A degree in Computer Science, Information Technology, Cybersecurity or a related discipline.
  • At least 5 years of cybersecurity experience, with substantial hands-on experience in SOC operations, incident response and digital forensics, including at least 3 years leading a team.
  • Proven track record of leading the response to significant incidents (e.g. ransomware, targeted intrusions, data breaches) from detection through to recovery and post-incident review.
  • Hands-on expertise with SIEM (e.g. Elastic, Microsoft Sentinel, Google SecOps, QRadar), EDR/XDR (e.g. CrowdStrike, Microsoft Defender, Trend Micro, Trellix), and SOAR platforms.
  • Experience with vulnerability management platforms (e.g. Tenable Nessus) and risk-based prioritisation approaches.
  • Highly analytical, with strong attention to detail and outstanding problem-solving skills; able to work independently and under pressure in a fast-paced environment.
  • Willingness to be on call and respond outside office hours during major incidents and/or as and when the need arises.
  • Relevant cybersecurity certifications.
  • Strong knowledge of frameworks and regulations such as MITRE ATT&CK, CIS Controls v8.1, ISO/IEC 27001:2022, Cybersecurity Act and PDPA.
  • Familiarity with AI-enabled security operations and threats targeting AI/LLM workloads.

More Info

Job Type:
Industry:
Function:
Employment Type:

Key Skills

PDPA

vulnerability management platforms

XDR

CIS Controls v8.1

Cybersecurity Act

About Company