
Lead Consultant, IT Security
- Singapore
- Permanent
- Full-time
- Lead and mentor SOC analysts (L1–L3), engineers, and threat hunters.
- Develop and maintain shift coverage for 24x7 or follow-the-sun SOC operations.
- Oversee training, certifications (e.g., GCIA, GCIH, OSCP), and career progression.
- Evaluate and implement next-gen SOC technologies (SIEM, SOAR, EDR, XDR, UEBA, etc.).
- Mentor SOC analysts and engineers, developing career paths and skill matrices.
- Ensure adequate staffing, training, and cross-coverage for critical operations.
- Oversee training, certifications (e.g., GCIA, GCIH, OSCP), and career progression.
- Develop and maintain shift coverage for 24x7 or follow-the-sun SOC operations.
- Oversee onboarding of new MSSP clients — log ingestion, use case development, tuning, integration.
- Ensure timely detection, triage, escalation, and resolution of security incidents.
- Maintain and improve SOPs, runbooks, and incident response workflows.
- Act as escalation point for major incidents, threat trends, or client concerns.
- Participate in client briefings, security reviews, compliance audits, and incident post-mortems.
- Track and report SOC KPIs: MTTD, MTTR, alert volumes, false positive rates, SLA adherence.
- Maintain SOC documentation, incident response processes, and audit-readiness (e.g., ISO 27001, PCI-DSS, SOC 2).
- Support compliance needs of clients (e.g., MAS TRM, HIPAA, GDPR).
- Interface with clients, senior executives, or business units to communicate SOC effectiveness, threat posture, and incident handling.
- Support onboarding of new customers, including use cases and rules tuning.
- Participate in audits, tabletop exercises, and post-incident reviews.
- Bachelor’s degree in Cybersecurity, Computer Science, or related field.
- Minimum 10 years of cybersecurity experience, including at least 3 years of leading SOC teams or MSS operations.
- Expertise with SIEM/SOAR platforms (e.g., Splunk, QRadar, Google SecOps, Sentinel, XSOAR).
- Hands-on understanding of network forensics, endpoint detection, cloud security, and TTPs.
- Strong knowledge of network security, endpoint defense, malware analysis, and TTPs.
- Familiar with frameworks such as MITRE ATT&CK, NIST CSF, ISO 27001.
- Proven ability to manage clients across various industries with different risk profiles.
- Certifications preferred: CISSP, GCIH, GCIA, GMON, OSCP, CISM.
- Experience running SOCs in MSSP or hybrid environments (cloud/on-prem).
- Experience in project management
- Ability to translate technical alerts into business risk language.
- Familiarity with cloud-native security (AWS/Azure/Google), log pipelines, and automation.
- Passion for mentoring and upskilling SOC staff.
- Business acumen and ability to align cyber strategy to business goals.
- Experience working in regulated industries (finance, healthcare, government).
- Experience working with MSSPs, vendors, or global teams.