Deputy Head, Security Operations Centre (SOC)
The Digital and Intelligence Service DIS
Job Description
Open to Singapore Citizens OnlyDeputy Head, SOC - Cyber Defence Group
As Deputy Head, you will lead and guide SOC in monitoring, investigation, and response activities, while driving operational discipline. You will also review and advise on the design and optimisation of SOC infrastructure while working with various stakeholders, ensuring alignment with organisational security and governance requirements. You will build a high-performing SOC team equipped to operate effectively in a dynamic threat environment.
What You Will Do1. Leadership & SOC Capability DevelopmentPartner the Section Head in guiding the development and expansion of the SOC’s capabilities and operating model.Build, mentor, and develop a high-calibre SOC team through performance management, and leadership development.Define and implement Key Performance Indicators (KPIs) to measure operational effectiveness, readiness, and exercise performance.Conduct after-action reviews and formal documentation of incidents and lessons learned to strengthen organisational knowledge and resilience.Foster a culture of accountability, continuous improvement, and professional excellence within the SOC.Lead SOC-related Capability Development Projects and detection engineering effort.
- Operational Oversight & Incident LeadershipProvide oversight and direction during cyber incidents and escalations, ensuring timely, coordinated, and effective response actions.Lead and support incident management across containment, eradication, remediation, and recovery phases.Ensure Standard Operating Procedures (SOPs) remain current and aligned with emerging threat vectors and organisational policies.Support Section Head to oversee 24/7 monitoring duties, maintaining operational vigilance and command presence.
- SOC Architecture, Tools & Performance OptimisationReview and advise on the design, placement, and coverage of intrusion detection capabilities and endpoint hardening agents across host and network environments.Ensure SOC tools meet baseline operational and security requirements, and drive continuous optimisation of detection efficacy and resource utilisation.Oversee the integration of complex security systems and ensure interoperability across platforms.Stay informed of emerging cyber threats and evolving tool capabilities to strengthen detection and response effectiveness.
- Stakeholder Engagement & GovernanceEngage internal and external stakeholders to align SOC requirements with enterprise priorities.Oversee coordination for system integrations, project trials, and security enhancements to ensure SOC requirements are embedded from design through deployment.Provide informed advice on operational risks, capability gaps, and mitigation measures to leadership and system owners.
What You Will BringEducation in Cybersecurity, Computer Engineering, Information Systems or an equivalent disciplineAt least 6 years of working experience in cybersecurity roles, including a minimum of 2 years in a senior or supervisory roles within a SOC or Cyber Emergency Response TeamRelevant technical certification, e.g. GIAC Security Operations Certified (GSOC), GIAC Certified Incident Handler (GCIH), Certified Information Systems Security Professional (CISSP) and/or Certified Information System Manager (CISM))Proficiency in tools, e.g. Security Information and Event Management, Intrusion Detection System, Intrusion Prevention System, and Endpoint Detection and ResponseFamiliarity in evaluating cybersecurity tools
Join us in shaping the future of defence technology. Apply today!