Search Jobs

Search by job, company or skills

Manager, Cyber Threat Management & Security Operations

Manager, Cyber Threat Management & Security Operations

kwe-apll technology services pte ltd
10-12 Years
Early Applicant
  • Posted 3 days ago
  • Be among the first 10 applicants

Job Description

Position Summary

The Manager, Cyber Threat Management & Security Operations is responsible for leading the organization's proactive cybersecurity capabilities to identify, assess, prioritize, and mitigate cyber threats and exposures before they result in business impact.

This role owns Cyber Threat Intelligence, Threat Hunting, Detection Engineering, Vulnerability Management, Attack Surface Management, Threat Exposure Management, Security Analytics, and Security Operations governance. The position works closely with the Security Operations Center (SOC), Infrastructure, Network, Cloud, and Application teams to strengthen the organization's cyber resilience and security posture.

The successful candidate will establish a threat-informed security program that leverages intelligence, automation, analytics, and continuous assessment to reduce organizational cyber risk.

Key Responsibilities

1. Cyber Threat Management

  • Lead and mature the enterprise Cyber Threat Management program.
  • Establish threat-informed defense strategies based on emerging threat intelligence, adversary tactics, and business risk.
  • Identify and assess cyber threats relevant to the organization's technology landscape and industry.
  • Translate threat intelligence into actionable security controls, detection content, and risk mitigation initiatives.
  • Maintain awareness of evolving threat actors, attack campaigns, and emerging attack techniques.
  • Provide strategic threat reporting and recommendations to Information Security leadership.

2. Threat Intelligence & Threat Hunting

  • Establish and manage Cyber Threat Intelligence (CTI) capabilities.
  • Develop intelligence requirements aligned to organizational risks and critical assets.
  • Lead proactive threat hunting activities acrossendpoints, cloud environments, networks, and enterprise systems.
  • Correlate intelligence from internal and external sources to identify potential compromises and emerging threats.
  • Develop adversary profiles and threat scenarios relevant to the business.
  • Maintain alignment with MITRE ATT&CK and other threat intelligence frameworks.

3. Detection Engineering & Security Analytics

  • Own enterprise detection engineering processes and standards.
  • Develop and continuously improve detection use cases based on intelligence, vulnerabilities, incidents, and emerging threats.
  • Ensure effective integration of security telemetry across cloud, endpoint, network, identity, and application environments.
  • Measure and improve detection coverage against MITRE ATT&CK techniques.
  • Lead the creation and optimization of security analytics and detection logic.
  • Partner with SOC teams to improve detection quality and reduce false positives.

4. Vulnerability & Threat Exposure Management

  • Own the enterprise vulnerability management program.
  • Establish risk-based vulnerability prioritization using threat intelligence, exploitability, business criticality, and attack path analysis.
  • Oversee vulnerability remediation governance and reporting.
  • Drive remediation accountability across infrastructure, cloud, application, and business technology teams.
  • Implement and mature Continuous Threat Exposure Management (CTEM) practices.
  • Track external exploit trends and evaluate organizational exposure.

5. Attack Surface Management

  • Lead External Attack Surface Management (EASM) and Internal Attack Surface Management initiatives.
  • Identify internet-facing assets, shadow IT, exposed services, and security misconfigurations.
  • Oversee continuous security assessments of external-facing infrastructure.
  • Develop metrics and reporting related to enterprise attack surface reduction.
  • Drive remediation programs to reduce organizational exposure.

6. Security Validation & Adversary Simulation

  • Lead security control validation initiatives across critical environments.
  • Coordinate threat-led testing, purple team exercises, breach and attack simulations, and adversary emulation activities.
  • Validate effectiveness of preventive and detective controls.
  • Identify detection gaps and control weaknesses.
  • Work closely with infrastructure and engineering teams to improve defensive capabilities.

7. Security Operations Governance

  • Define Security Operations standards, procedures, and operational effectiveness measures.
  • Establish Key Risk Indicators (KRIs), Key Performance Indicators (KPIs), and cyber resilience metrics.
  • Drive security automation and orchestration opportunities to improve operational efficiency.
  • Develop executive reporting on cyber threats, exposure trends, and security posture.
  • Manage security technology roadmaps related to threat management capabilities.

8. Infrastructure & Network Security Partnership

  • Provide security oversight and guidance for network, cloud, and infrastructure security initiatives.
  • Support the secure implementation of technologies including firewalls, VPNs, network segmentation, SD-WAN, proxy, and security monitoring platforms.
  • Work with infrastructure teams to ensure security controls remain aligned with business and threat requirements.
  • Advise on security architecture and risk mitigation strategies.

9. Leadership & Stakeholder Management

  • Lead and develop Security Engineers and cybersecurity specialists.
  • Manage strategic security initiatives and transformation programs.
  • Partner with Infrastructure, Cloud, Architecture, Risk, Compliance, and Business leaders.
  • Present cyber risk, threat landscape information, and security posture updates to senior management.
  • Manage relationships with security vendors, service providers, and threat intelligence partners.

Qualifications

Education

  • Bachelor's Degree in Cybersecurity, Computer Science, Information Technology, Engineering, or related discipline.
  • Master's Degree in Cybersecurity or Information Security preferred.

Experience

  • 10+ years of cybersecurity experience.
  • 5+ years of experience in Cyber Threat Management, Threat Intelligence, Security Operations, Detection Engineering, or Vulnerability Management.
  • 3+ years of people leadership experience.
  • Experience developing threat-informed defense strategies and cyber risk reduction programs.
  • Experience working within enterprise network, infrastructure, cloud, and cybersecurity environments.
  • Experience managing cross-functional cybersecurity initiatives and executive stakeholders.

More Info

Job Type:
Industry:
Function:
Employment Type:

Key Skills

Security automation and orchestration

Attack Surface Management

Security Operations governance

Cyber Threat Management

Detection Engineering

Security Analytics

Security control validation

Similar Jobs

10-12 yrs
SGD 9,000 - 11,500 per month
Singapore, Beach Road
Skills:
Threat Hunting, Vulnerability Management, Network security, Threat Intelligence, Infrastructure Security, Security automation and orchestration, Attack Surface Management, Security Operations governance, Security Analytics, Cyber Threat Management, Detection Engineering
10-12 yrs
Singapore
Skills:
Business Intelligence Tools, Data Analytics, change management, Iot, digital operations, Security, restaurant technology, project management tools
8-10 yrs
Singapore
Skills:
red teaming , network security, Penetration Testing, security assessment, cybersecurity controls, offensive security, technical security assessments
8-11 yrs
SGD 9,000 - 12,000 per month
Middle Road, Singapore
Skills:
network security, Penetration Testing, cybersecurity controls, offensive security, technical security assessments, attack techniques
5-10 yrs
Singapore
Skills:
team performance , security consulting , Security Management, Incident Management, Incident Response, Microsoft Office, Operations Security, Physical Security, Security Operations, Security Risk Management, Risk Mitigation, Security Team Management, Security Officer Management, Security Leadership, Access Management, Access Control, alarm management, Life Safety, Risk Assessment, Facility Risk Assessment, Security Patrol, Security Systems, Security Equipment, Security Audits, Internal Audit, Quality Control, Compliance, security training, Security Drills, Performance Management, Security Process Improvement, Security Projects, Security Systems Projects, Regional Security Management, business resilience, Operational Resilience, Crisis Management, Emergency Response, Security Advisory, Analytical Skills, Decision Making, Communication Skills, Negotiation Skills, Claims Management Systems, Stakeholder Management, Confidential Information Management, Global Security, Office Security, Workplace Security, SEA Security Operations, 24/7 Security Operations, Security Governance