Job Opportunities API

The Public Ledger of Openings

← Back to the ledger

Lead Cybersecurity Incident Response Specialist

GovTech
CompanyGovTech
CategoryUncategorised
LocationSingapore
RemoteOn-site (inferred)
EmploymentNot stated
LevelNot stated
SalaryNot stated by the employer
Posted19 Jun 2026
Last verified9 Aug 2026
SourceEmployer ATS (greenhouse)
Applications are handled by the employer, not by us.Apply on the employer's site →
Description
The Government Technology Agency (GovTech) is the lead agency driving Singapore’s Smart Nation initiatives and public sector digital transformation. As the Centre of Excellence for  Infocomm  Technology and Smart Systems (ICT & SS), GovTech develops the Singapore Government’s capabilities in Data Science & Artificial Intelligence, Application Development, Smart City Technology, Digital Infrastructure, and Cybersecurity.         At GovTech, we offer you a purposeful career to make lives better. We empower our people to master their craft through continuous and robust learning and development opportunities all year round. Our  GovTechies  embody our Agile,  Bold  and Collaborative values to deliver impactful solutions.   GovTech aims to transform the delivery of Government digital services by taking an "outside-in" view, putting citizens and businesses at the heart of everything we do.   Play a part in Singapore’s vision to build a Smart Nation and embark on your meaningful journey to build tech for public good. Join us to advance our mission and shape your future with us today!         Learn more about GovTech at tech.gov.sg.     Job Description   Join us and you will play a key role in the Cyber Defense Ops & Intelligence (CDOI) of Cyber Security Group (CSG) as  Cybersecurity Operations Specialist (Incident Response) to manage and investigate cybersecurity incidents.   The successful candidate will ensure the delivery of cybersecurity operations services across all stages of the incident response lifecycle. This encompasses triaging potential security events, conducting in-depth investigations and advising on containment, eradication and recovery strategies. Candidate must possess strong log analysis and digital forensics skills to drive effective responses to cybersecurity incidents that ensure secure delivery of applications and infrastructure services. Critical thinking and great communication skills are required to articulate technical concepts and guide decision makers towards optimal courses of action. This is a key position in the Cyber Incident Response Team (CIRT).   What you will be working on:   Lead incident response activities through all phases of an incident:   Conduct triage and investigation of potential cybersecurity incidents to determine incident scope and severity   Develop and execute containment strategies   Perform investigations and root cause analysis to identify attack vectors, tactics, and impact   Conduct comprehensive security event log analysis to validate security detections, investigate alerts, and identify attacks across multiple data sources including:   Endpoint system logs or Endpoint detection and response (EDR) telemetry   Network traffic logs   Application logs    Cloud service logs and audit trails   Conduct digital forensic acquisition and analysis of artifacts from various sources including:   Endpoint systems and servers   Network devices and logs   Cloud environments   Mobile devices and storage media   Maintain clear stakeholder communication throughout incident lifecycle and prepare comprehensive post-incident reports with preventive recommendations   Provide expert input for automating Security Operations (E.g Implement SOAR playbooks)   Develop and test incident response playbooks and processes   Maintain situational awareness of cyber security landscape