Back to all jobs

- Seniority
- Lead
About the role
<p><span class="TextRun SCXW98557482 BCX0" lang="EN-SG" data-contrast="auto"><span class="NormalTextRun SCXW98557482 BCX0">The Government Technology Agency (GovTech) is the lead agency driving Singapore’s Smart Nation initiatives and public sector digital transformation. As the Centre of Excellence for </span><span class="NormalTextRun SpellingErrorV2Themed SCXW98557482 BCX0">Infocomm</span><span class="NormalTextRun SCXW98557482 BCX0"> Technology and Smart Systems (ICT & SS), GovTech develops the Singapore Government’s capabilities in Data Science & Artificial Intelligence, Application Development, Smart City Technology, Digital Infrastructure, and Cybersecurity. </span></span><span class="LineBreakBlob BlobObject DragDrop SCXW98557482 BCX0"><span class="SCXW98557482 BCX0"> </span><br class="SCXW98557482 BCX0"></span><span class="LineBreakBlob BlobObject DragDrop SCXW98557482 BCX0"><span class="SCXW98557482 BCX0"> </span><br class="SCXW98557482 BCX0"></span><span class="TextRun SCXW98557482 BCX0" lang="EN-SG" data-contrast="auto"><span class="NormalTextRun SCXW98557482 BCX0">At GovTech, we offer you a purposeful career to make lives better. We empower our people to master their craft through continuous and robust learning and development opportunities all year round. Our </span><span class="NormalTextRun SpellingErrorV2Themed SCXW98557482 BCX0">GovTechies</span><span class="NormalTextRun SCXW98557482 BCX0"> embody our Agile, </span><span class="NormalTextRun SCXW98557482 BCX0">Bold</span><span class="NormalTextRun SCXW98557482 BCX0"> and Collaborative values to deliver impactful solutions. GovTech aims to transform the delivery of Government digital services by taking an "outside-in" view, putting citizens and businesses at the heart of everything we do. Play a part in Singapore’s vision to build a Smart Nation and embark on your meaningful journey to build tech for public good. Join us to advance our mission and shape your future with us today! </span></span><span class="LineBreakBlob BlobObject DragDrop SCXW98557482 BCX0"><span class="SCXW98557482 BCX0"> </span><br class="SCXW98557482 BCX0"></span><span class="LineBreakBlob BlobObject DragDrop SCXW98557482 BCX0"><span class="SCXW98557482 BCX0"> </span><br class="SCXW98557482 BCX0"></span><span class="TextRun SCXW98557482 BCX0" lang="EN-SG" data-contrast="auto"><span class="NormalTextRun SCXW98557482 BCX0">Learn more about GovTech at tech.gov.sg.</span></span><span class="EOP SCXW98557482 BCX0" data-ccp-props="{}"> </span></p>
<p> </p>
<p><strong><span data-contrast="auto">Job Description</span></strong><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">Join us and you will play a key role in the Cyber Defense Ops & Intelligence (CDOI) of Cyber Security Group (CSG) as Cybersecurity Operations Specialist (Incident Response) to manage and investigate cybersecurity incidents.</span><span data-ccp-props="{"335551550":6,"335551620":6}"> </span></p>
<p><span data-contrast="auto">The successful candidate will ensure the delivery of cybersecurity operations services across all stages of the incident response lifecycle. This encompasses triaging potential security events, conducting in-depth investigations and advising on containment, eradication and recovery strategies. Candidate must possess strong log analysis and digital forensics skills to drive effective responses to cybersecurity incidents that ensure secure delivery of applications and infrastructure services. Critical thinking and great communication skills are required to articulate technical concepts and guide decision makers towards optimal courses of action. This is a key position in the Cyber Incident Response Team (CIRT).</span><span data-ccp-props="{"335551550":6,"335551620":6}"> </span></p>
<p><strong><span data-contrast="auto">What you will be working on:</span></strong><span data-ccp-props="{}"> </span></p>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Lead incident response activities through all phases of an incident:</span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="o" data-font="Courier New" data-listid="7" data-list-defn-props="{"335552541":1,"335559685":1440,"335559991":360,"469769226":"Courier New","469769242":[9675],"469777803":"left","469777804":"o","469777815":"multilevel"}" data-aria-posinset="1" data-aria-level="2"><span data-contrast="auto">Conduct triage and investigation of potential cybersecurity incidents to determine incident scope and severity</span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="o" data-font="Courier New" data-listid="7" data-list-defn-props="{"335552541":1,"335559685":1440,"335559991":360,"469769226":"Courier New","469769242":[9675],"469777803":"left","469777804":"o","469777815":"multilevel"}" data-aria-posinset="2" data-aria-level="2"><span data-contrast="auto">Develop and execute containment strategies</span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="o" data-font="Courier New" data-listid="7" data-list-defn-props="{"335552541":1,"335559685":1440,"335559991":360,"469769226":"Courier New","469769242":[9675],"469777803":"left","469777804":"o","469777815":"multilevel"}" data-aria-posinset="3" data-aria-level="2"><span data-contrast="auto">Perform investigations and root cause analysis to identify attack vectors, tactics, and impact</span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="2" data-aria-level="1"><span data-contrast="auto">Conduct comprehensive security event log analysis to validate security detections, investigate alerts, and identify attacks across multiple data sources including:</span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="o" data-font="Courier New" data-listid="7" data-list-defn-props="{"335552541":1,"335559685":1440,"335559991":360,"469769226":"Courier New","469769242":[9675],"469777803":"left","469777804":"o","469777815":"multilevel"}" data-aria-posinset="1" data-aria-level="2"><span data-contrast="auto">Endpoint system logs or Endpoint detection and response (EDR) telemetry</span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="o" data-font="Courier New" data-listid="7" data-list-defn-props="{"335552541":1,"335559685":1440,"335559991":360,"469769226":"Courier New","469769242":[9675],"469777803":"left","469777804":"o","469777815":"multilevel"}" data-aria-posinset="2" data-aria-level="2"><span data-contrast="auto">Network traffic logs</span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="o" data-font="Courier New" data-listid="7" data-list-defn-props="{"335552541":1,"335559685":1440,"335559991":360,"469769226":"Courier New","469769242":[9675],"469777803":"left","469777804":"o","469777815":"multilevel"}" data-aria-posinset="3" data-aria-level="2"><span data-contrast="auto">Application logs </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="o" data-font="Courier New" data-listid="7" data-list-defn-props="{"335552541":1,"335559685":1440,"335559991":360,"469769226":"Courier New","469769242":[9675],"469777803":"left","469777804":"o","469777815":"multilevel"}" data-aria-posinset="4" data-aria-level="2"><span data-contrast="auto">Cloud service logs and audit trails</span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="3" data-aria-level="1"><span data-contrast="auto">Conduct digital forensic acquisition and analysis of artifacts from various sources including:</span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="o" data-font="Courier New" data-listid="7" data-list-defn-props="{"335552541":1,"335559685":1440,"335559991":360,"469769226":"Courier New","469769242":[9675],"469777803":"left","469777804":"o","469777815":"multilevel"}" data-aria-posinset="1" data-aria-level="2"><span data-contrast="auto">Endpoint systems and servers</span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="o" data-font="Courier New" data-listid="7" data-list-defn-props="{"335552541":1,"335559685":1440,"335559991":360,"469769226":"Courier New","469769242":[9675],"469777803":"left","469777804":"o","469777815":"multilevel"}" data-aria-posinset="2" data-aria-level="2"><span data-contrast="auto">Network devices and logs</span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="o" data-font="Courier New" data-listid="7" data-list-defn-props="{"335552541":1,"335559685":1440,"335559991":360,"469769226":"Courier New","469769242":[9675],"469777803":"left","469777804":"o","469777815":"multilevel"}" data-aria-posinset="3" data-aria-level="2"><span data-contrast="auto">Cloud environments</span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="o" data-font="Courier New" data-listid="7" data-list-defn-props="{"335552541":1,"335559685":1440,"335559991":360,"469769226":"Courier New","469769242":[9675],"469777803":"left","469777804":"o","469777815":"multilevel"}" data-aria-posinset="4" data-aria-level="2"><span data-contrast="auto">Mobile devices and storage media</span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="4" data-aria-level="1"><span data-contrast="auto">Maintain clear stakeholder communication throughout incident lifecycle and prepare comprehensive post-incident reports with preventive recommendations</span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="5" data-aria-level="1"><span data-contrast="auto">Provide expert input for automating Security Operations (E.g Implement SOAR playbooks)</span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="6" data-aria-level="1"><span data-contrast="auto">Develop and test incident response playbooks and processes</span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="7" data-aria-level="1"><span data-contrast="auto">Maintain situational awareness of cyber security landscape and emerging threat actor TTPs</span><span data-ccp-props="{}"> </span></li>
</ul>
<p><strong><span data-contrast="auto">What we are looking for:</span></strong><span data-ccp-props="{}"> </span></p>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="5" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Bachelor’s Degree in Computer Science/Information Security or equivalent</span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="5" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="2" data-aria-level="1"><span data-contrast="auto">Professional certifications, including GCFA, GREM, GNFA, GCTI, CISSP or other relevant certifications will be preferred</span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="5" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="3" data-aria-level="1"><span data-contrast="auto">Preferably 5 years or more of experience as a full-time incident responder/digital forensic/malware analysis or related discipline</span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="5" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="4" data-aria-level="1"><span data-contrast="auto">Understanding of operating systems and platform (e.g. Windows, Linux) and knowledge of computer networking, LAN, and server</span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="5" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="5" data-aria-level="1"><span data-contrast="auto">Strong ability with log analysis techniques, familiarity with platforms (e.g., Splunk, ELK Stack, Google SecOps) and analytical skills to correlate events across multiple log sources to identify attack patterns</span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="5" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="6" data-aria-level="1"><span data-contrast="auto">Proficient in Forensic Tools such as AXIOM, FTK or Autopsy</span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="5" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="7" data-aria-level="1"><span data-contrast="auto">Ability to perform basic static and dynamic malware analysis and to analyse network and application logs</span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="5" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="8" data-aria-level="1"><span data-contrast="auto">Good working knowledge of Cloud and Container technologies are a plus</span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="5" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="9" data-aria-level="1"><span data-contrast="auto">Familiarity with good security practices</span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="5" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="10" data-aria-level="1"><span data-contrast="auto">Good communication and interpersonal skills, with the ability to multitask and priortise</span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="5" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="11" data-aria-level="1"><span data-contrast="auto">Meticulous and demonstrate a high degree of integrity, initiative, energy and endurance</span><span data-ccp-props="{}"> </span></li>
</ul>
<p><span data-contrast="auto"> </span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">GovTech is an equal opportunity employer committed to fostering an inclusive workplace that values diverse voices and perspectives, as we believe that diversity is the foundation to innovation. </span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">Our employee benefits are based on a total rewards approach, offering a holistic and market-competitive suite of perks. These include leave benefits to meet your work-life needs and employee wellness programmes. </span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">We champion flexible work arrangements (subject to your job role) and trust that you will manage your own time to deliver your best, wherever you are, and whatever works best for you.</span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">Learn more about life inside GovTech at go.gov.sg/GovTechCareers.</span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">Stay connected with us on social media at go.gov.sg/ConnectWithGovTech.</span><span data-ccp-props="{}"> </span></p>
758,000+ hidden jobs like this
GovTech and thousands of companies post here first — often days before LinkedIn or Indeed. Your first 5 applications are free; go Pro to apply without limits.
Everything Pro unlocks:
- Unlimited applications — free stops at 5
- Track every application in one place
- Apply straight to the source, one click
- Save & organize roles you love
- Roles pulled from company boards before the big sites