About the Team
The Cybersecurity function is being built out under the Head of Cybersecurity, across four pillars: Architecture and Engineering, Security Operations, Security Governance, and Security Threat and Incident Management. It is a lean, senior team working in close partnership with IT Infrastructure, Compliance, and Legal.
This role owns the Security Operations pillar and provides full operational and technical support to the Incident Response Manager for the firm's incident response capability. 24/7 monitoring coverage is provided by an external managed SOC. You own that relationship, hold it to its service levels, and own all operational matters the service cannot resolve. Day-to-day delivery across monitoring and detection, threat intelligence, vulnerability management, security awareness, and posture reporting, supported by a Security Operations Analyst who reports into this role.
The Incident Response Manager leads material incidents and owns scoping, containment decisions, stakeholder coordination, regulatory notification workflows, and post-incident reviews. The Security Operations Lead provides full support throughout, including investigation, evidence collection, technical analysis, containment execution, tooling, and coordination with the managed SOC and IT Infrastructure under the Incident Response Manager's direction. Our environment is Microsoft-centric, built on Sentinel, Defender XDR, Entra ID, and Intune, alongside Darktrace, Cisco Umbrella, and Nessus. This is a lean team, so the role is a working lead rather than a pure manager. Security decisions can stop trading, so judgement about business impact matters as much as technical depth.
Key Responsibilities
- Own delivery of the Security Operations pillar, covering monitoring and detection, threat intelligence, vulnerability management, security awareness, and posture reporting.
- Own the managed SOC relationship, including service level governance, escalation and alert quality, the joint detection backlog, and vendor performance reporting with supporting evidence.
- Provide full operational and technical support to the Incident Response Manager across the incident response lifecycle, including severity assessment, playbook maintenance, investigation, evidence collection, containment execution, and recovery activities.
- Support the Incident Response Manager during major incidents by directing technical investigation workstreams when delegated, executing containment actions, and coordinating operational inputs from the managed SOC and IT Infrastructure.
- Provide the Incident Response Manager, Compliance, and the Head of Cybersecurity with accurate technical facts, timelines, impact assessments, and supporting evidence for crisis communications and regulatory, investor, and counterparty notification workflows.
- Support the Incident Response Manager in delivering the annual tabletop exercise programme and scenario-based response simulations, and implement agreed lessons learned through playbook, detection, and control improvements.
- Set detection strategy and coverage direction, including MITRE ATT&CK mapping, detection engineering priorities, and threat intelligence operationalisation.
- Own vulnerability and patch service level governance across the estate, escalating breaches to infrastructure owners and to management with evidence.
- Manage and develop the Security Operations Analyst, own the on-call rota, and remain hands-on in the tooling as a working lead in a small team.
- Own security operations metrics and reporting to the COO and executive committee, maintain audit-ready evidence aligned to MAS Technology Risk Management guidelines, MAS Notice 658, and NIST CSF 2.0, and validate disaster recovery and backup recovery testing with IT Infrastructure.
Requirements
- 8 or more years in security operations, including at least 2 years leading a function or team in a regulated environment and substantial experience supporting major incident response. Financial services, hedge fund, or asset management experience is advantageous.
- Demonstrable experience providing technical and operational support during material security incidents, from detection and investigation through containment, recovery, and post-incident review, under an Incident Response Manager.
- Experience owning an outsourced SOC or managed detection and response provider, including holding the service to its contractual commitments.
- Microsoft Sentinel and Defender XDR at operational depth, including KQL, detection rule strategy, and advanced hunting.
- Detection strategy and coverage management using MITRE ATT&CK, with the ability to set direction for detection engineering and threat intelligence.
- Vulnerability management governance, including service level enforcement and driving remediation across infrastructure teams that do not report to you.
- Experience preparing technical evidence and impact assessments to support regulatory incident notification under MAS Technology Risk Management guidelines and MAS Notice 658, or an equivalent regime.
- Cloud and identity security operations, including Azure logging, Defender for Cloud, Entra ID, conditional access, and privileged access.
- Line management or structured mentoring of security analysts, including workload prioritisation and development.
- Able to brief the Incident Response Manager and senior stakeholders clearly during and after an incident, remain calm and structured under pressure, follow the Incident Response Manager's direction, and participate in an on-call rota. This is a working lead role, and hands-on technical currency is required.
Preferred certifications: SC-200 Microsoft Security Operations Analyst. GCIH, GCIA, GCFA, or GCTI are advantageous, as are CISSP or CISM.
With well over a decade of a solid and enviable track record behind us, headquartered in Hong Kong, Pinpoint Asia Infotech Pte Ltd (EA License: 16C8291) is the go-to IT Search Firm for several top Investment Banks and Financial Institutions.
If you are interested in the above position, please send your CV to Charlie Kim @ [Confidential Information] (EA Registration number: Reg No: R23112483) and include the Security Operations Lead - Global Hedge Fund - J13140 in the subject title.