Singlife is a leading homegrown financial services company, offering consumers a better way to financial freedom. Through innovative, technology-enabled solutions and a wide range of products and services, Singlife provides consumers control over their financial wellbeing at every stage of their lives.
In addition to a comprehensive suite of insurance plans, employee benefits, partnerships with financial adviser channels and bancassurance, Singlife offers investment and advisory solutions through its GROW with Singlife platform. It also offers the Singlife Account, a mobile-first insurance savings plan.
Singlife is the exclusive insurance provider for the Ministry of Defence, Ministry of Home Affairs and Public Officers Group Insurance Scheme. Singlife is also an official signatory of the United Nations Principles for Sustainable Insurance and the United Nations-supported Principles for Responsible Investment, affirming its commitment to finding a better way to sustainability.
The merger of Aviva Singapore and Singlife was announced in September 2020 and created one of the largest homegrown financial services companies in Singapore in a deal valued at S$3.2 billion. It was the largest insurance deal in Singapore at the time. Singlife was subsequently acquired by Sumitomo Life in March 2024, one of Japan's leading life insurers, which valued Singlife at S$4.6 billion, making the transaction one of the largest insurance deals in Southeast Asia.
About The Role
Cyber threats are growing more sophisticated by the day, and at Singlife we are building a cyber defence capability that stays a step ahead. As our Vice President, Information Security (Managed Detection and Response), you will be the senior technical authority behind how we detect, hunt, investigate and respond to threats across the Group.
You will lead our Managed Detection and Response (MDR), Digital Forensics and Incident Response (DFIR), Threat Hunting, Detection Engineering and Security Operations capabilities, and act as incident commander when it matters most.
This is a hands-on, high-impact individual-contributor role for someone who thrives in the moments that test an organisation's resilience, and who wants to shape a modern, automation-driven, AI-enabled defence strategy aligned to MAS TRM, NIST CSF v2.0 and ISO/IEC 27001:2022.
Responsibilities
- Take command of major cyber incidents and own the end-to-end DFIR lifecycle — from detection and containment through eradication, recovery and post-incident review.
- Set and drive the Group's cyber defence and detection-and-response strategy, aligned to MAS TRM, NIST CSF v2.0 and ISO/IEC 27001:2022.
- Govern and optimise our SIEM, SOAR, EDR and DLP platforms to maximise detection coverage, efficacy and value.
- Lead detection engineering and proactive, intelligence-led threat hunting mapped to the MITRE ATT&CK framework.
- Shape our security telemetry and logging strategy, prioritising log source onboarding for comprehensive coverage.
- Build security automation and orchestration that make detection and response faster, more consistent and higher quality.
- Adopt and govern AI-enabled capabilities to strengthen security operations while keeping the right guardrails in place.
- Develop, maintain and regularly test incident response playbooks, runbooks and cyber crisis and tabletop exercises.
- Manage external forensic, MDR and threat-intelligence partners, including onboarding, performance and SLA oversight.
- Define, track and report detection-and-response metrics (such as MTTD and MTTR) to drive continuous improvement.
- Mentor analysts and engineers, sharing your expertise to build a high-performing, resilient and collaborative team.
- Support audits, regulatory engagements and executive/Board reporting, and represent Singlife in industry threat-sharing communities.
Requirements
- 8+ years in cyber security, with deep, hands-on expertise in DFIR, Detection Engineering, Threat Hunting, SIEM, SOAR, EDR, DLP, security automation and AI-enabled Security Operations.
- A proven track record leading major cyber incidents and complex forensic investigations from start to finish.
- Strong working knowledge of MAS TRM, NIST CSF v2.0, ISO/IEC 27001:2022 and the MITRE ATT&CK framework.
- Hands-on experience across cloud (AWS/Azure), endpoint, network and identity telemetry, detection-as-code and automation.
- Experience in a regulated financial services or insurance environment (strongly preferred).
- A Bachelor's degree in Computer Science, Information Security or a related field, or equivalent professional experience.
- One or more relevant certifications — CISSP, GCFA, GCIH, GNFA, GREM, GCTI or equivalent.
- Calm, decisive leadership under pressure, sharp analytical thinking, and the ability to translate technical risk clearly for management and stakeholders.