Key Responsibilities
Incident Response & Investigation
Lead and conduct end-to-end incident response across detection, triage, containment, eradication, and recovery.
Able to perform deep technical investigations across endpoints, network, identity, cloud, and application layers.
Analyze malware, attacker behaviors, and intrusion patterns to determine root cause and attack scope.
Handle high-severity and sophisticated cyber incidents, including APT, ransomware, and fraud-related attacks.
Maintain detailed documentation of incidents, actions taken, and lessons learned.
Security Incident Management
Act as Incident Commander during major security incidents, coordinating cross-functional teams (SOC, IR, IT, Legal, Risk, Communications).
Drive structured incident management processes, ensuring adherence to SLAs and playbooks.
Provide timely and clear communications to senior management and stakeholders.
Lead post-incident reviews (PIRs) and ensure remediation actions are tracked to closure.
SOC Operations & Escalation
Serve as the highest technical escalation point within SOC for complex investigations.
Support SOC analysts in triage and response for high-priority alerts.
Improve escalation processes and decision-making frameworks during incidents.
Playbooks, Processes & Readiness
Develop, maintain, and continuously improve incident response playbooks and runbooks.
Ensure readiness for various threat scenarios including ransomware, data exfiltration, and insider threats.
Conduct and support tabletop exercises and incident simulations.
Align incident response processes with industry frameworks (e.g., MAS TRMG, CCoP, NIST, ISO 27035).
Threat Intelligence & Detection Feedback Loop
Leverage threat intelligence to enhance incident response effectiveness.
Provide feedback to detection engineering and threat hunting teams to improve use cases and monitoring coverage.
Identify detection gaps exposed during incidents and drive remediation.
Digital Forensics & Evidence Handling
Perform or oversee forensic data acquisition and analysis (disk, memory, logs).
Ensure proper chain of custody and evidence handling for legal and regulatory needs.
Support investigations that may require regulatory reporting or legal actions.
Automation & Tooling
Drive the use of automation and SOAR playbooks to accelerate response actions.
Recommend and implement tools to improve investigation speed and accuracy.
Stakeholder & Regulatory Engagement
Liaise with internal stakeholders including Fraud, Risk, Compliance, and IT.
Support regulatory incident reporting requirements relevant to financial/payment systems.
Act as a trusted advisor during cyber crisis situations.
Required Qualifications & Experience
10–15+ years of cybersecurity experience, with:
5+ years in incident response / digital forensics / SOC operations
3+ years in a lead or incident management capacity
Strong hands-on experience in:
Incident response methodologies and frameworks
EDR/XDR platforms
SIEM platforms
Network and endpoint investigation techniques
Deep understanding of:
Threat actor tactics, techniques, and procedures (TTPs)
MITRE ATT&CK framework
Malware behavior and attack lifecycle
Experience in:
Crisis management and incident command
Cross-functional coordination during high-pressure scenarios
Strong technical skills in:
OS internals (Windows/Linux)
Networking (TCP/IP, DNS, HTTP/S, etc.)
Log analysis and correlation
Preferred Qualifications
Experience in financial services, payments, or critical infrastructure environments
Hands-on malware analysis and reverse engineering (basic to advanced)
Familiarity with:
Cloud security incident response (AWS, Azure, GCP)
Identity-based attacks and investigations
Exposure to fraud-related cybersecurity incidents
Preferred Certifications
GIAC certifications (GCFA, GCIH, GNFA, GREM)
CISSP, CISM
Certified Incident Handler / Forensics certifications
Vendor certifications (Microsoft, CrowdStrike, Google Mandiant, Elastic, etc.)
Key Competencies
Strong technical depth and investigative skills
Ability to lead during high-pressure incidents
Excellent communication and stakeholder management
Structured and analytical thinking
Decisiveness and accountability
Mentorship and team leadership
What Success Looks Like
Rapid and effective containment of high-impact security incidents
Reduced MTTR (Mean Time to Respond) and improved response quality
Well-executed and coordinated incident management processes
Continuous improvement of IR playbooks and readiness
Strong trust and confidence from executive leadership and stakeholders
The NETS Group
The NETS Group is a leading payments services group, enabling digital payments for merchants, consumers and banks across the entire payments value chain.
The Group operates Singapore’s national debit scheme enabling customers of DBS Bank/POSB, HSBC, Maybank, OCBC Bank, Standard Chartered Bank and UOB to make payments using their ATM cards or mobile devices at more than 102,000 acceptance points in the country as well as online payments.
The NETS network also accepts NETSPay, UnionPay and BCA cards, and includes 40,000 Unified POS terminals and 55,000 QR acceptance points. NETS is also the issuer of CashCard and Flashpay cards.
The NETS Group manages and operates the clearing and payment infrastructure for the Singapore Clearing House Association and core electronic transfer services FAST, Inter-bank GIRO and PayNow.
It is the market leader for payment and clearing solutions (Real-Time Gross Settlement system and Cheque Truncation System) in the region with some S$1 trillion in transaction value processed through its systems every year.
NETS is a member of the Asian Payment Network and a council member of UnionPay International.
Towards a cashless society
In 1985, Singapore embarked on an ambitious plan to push the country towards becoming a cashless society.
The introduction of Interbank GIRO (enabling the public to pay their bills electronically) and the implementation of the NETS debit scheme (allowing consumers to make purchases at retail stores with just a card and PIN) were the start of a more-than-30-year journey that has seen numerous cashless payment innovations added to Singapore’s economy.
Today, NETS is an integral part of daily life in Singapore. From shopping to transport, paying bills and fees, or transferring money, NETS ensures that payments are made swiftly and securely each and every time.