Manager, Cyber Threat Management & Security Operations
kwe-apll technology services pte ltd- Posted 3 days ago
- Be among the first 10 applicants
Job Description
Position Summary
The Manager, Cyber Threat Management & Security Operations is responsible for leading the organization's proactive cybersecurity capabilities to identify, assess, prioritize, and mitigate cyber threats and exposures before they result in business impact.
This role owns Cyber Threat Intelligence, Threat Hunting, Detection Engineering, Vulnerability Management, Attack Surface Management, Threat Exposure Management, Security Analytics, and Security Operations governance. The position works closely with the Security Operations Center (SOC), Infrastructure, Network, Cloud, and Application teams to strengthen the organization's cyber resilience and security posture.
The successful candidate will establish a threat-informed security program that leverages intelligence, automation, analytics, and continuous assessment to reduce organizational cyber risk.
Key Responsibilities
1. Cyber Threat Management
- Lead and mature the enterprise Cyber Threat Management program.
- Establish threat-informed defense strategies based on emerging threat intelligence, adversary tactics, and business risk.
- Identify and assess cyber threats relevant to the organization's technology landscape and industry.
- Translate threat intelligence into actionable security controls, detection content, and risk mitigation initiatives.
- Maintain awareness of evolving threat actors, attack campaigns, and emerging attack techniques.
- Provide strategic threat reporting and recommendations to Information Security leadership.
2. Threat Intelligence & Threat Hunting
- Establish and manage Cyber Threat Intelligence (CTI) capabilities.
- Develop intelligence requirements aligned to organizational risks and critical assets.
- Lead proactive threat hunting activities acrossendpoints, cloud environments, networks, and enterprise systems.
- Correlate intelligence from internal and external sources to identify potential compromises and emerging threats.
- Develop adversary profiles and threat scenarios relevant to the business.
- Maintain alignment with MITRE ATT&CK and other threat intelligence frameworks.
3. Detection Engineering & Security Analytics
- Own enterprise detection engineering processes and standards.
- Develop and continuously improve detection use cases based on intelligence, vulnerabilities, incidents, and emerging threats.
- Ensure effective integration of security telemetry across cloud, endpoint, network, identity, and application environments.
- Measure and improve detection coverage against MITRE ATT&CK techniques.
- Lead the creation and optimization of security analytics and detection logic.
- Partner with SOC teams to improve detection quality and reduce false positives.
4. Vulnerability & Threat Exposure Management
- Own the enterprise vulnerability management program.
- Establish risk-based vulnerability prioritization using threat intelligence, exploitability, business criticality, and attack path analysis.
- Oversee vulnerability remediation governance and reporting.
- Drive remediation accountability across infrastructure, cloud, application, and business technology teams.
- Implement and mature Continuous Threat Exposure Management (CTEM) practices.
- Track external exploit trends and evaluate organizational exposure.
5. Attack Surface Management
- Lead External Attack Surface Management (EASM) and Internal Attack Surface Management initiatives.
- Identify internet-facing assets, shadow IT, exposed services, and security misconfigurations.
- Oversee continuous security assessments of external-facing infrastructure.
- Develop metrics and reporting related to enterprise attack surface reduction.
- Drive remediation programs to reduce organizational exposure.
6. Security Validation & Adversary Simulation
- Lead security control validation initiatives across critical environments.
- Coordinate threat-led testing, purple team exercises, breach and attack simulations, and adversary emulation activities.
- Validate effectiveness of preventive and detective controls.
- Identify detection gaps and control weaknesses.
- Work closely with infrastructure and engineering teams to improve defensive capabilities.
7. Security Operations Governance
- Define Security Operations standards, procedures, and operational effectiveness measures.
- Establish Key Risk Indicators (KRIs), Key Performance Indicators (KPIs), and cyber resilience metrics.
- Drive security automation and orchestration opportunities to improve operational efficiency.
- Develop executive reporting on cyber threats, exposure trends, and security posture.
- Manage security technology roadmaps related to threat management capabilities.
8. Infrastructure & Network Security Partnership
- Provide security oversight and guidance for network, cloud, and infrastructure security initiatives.
- Support the secure implementation of technologies including firewalls, VPNs, network segmentation, SD-WAN, proxy, and security monitoring platforms.
- Work with infrastructure teams to ensure security controls remain aligned with business and threat requirements.
- Advise on security architecture and risk mitigation strategies.
9. Leadership & Stakeholder Management
- Lead and develop Security Engineers and cybersecurity specialists.
- Manage strategic security initiatives and transformation programs.
- Partner with Infrastructure, Cloud, Architecture, Risk, Compliance, and Business leaders.
- Present cyber risk, threat landscape information, and security posture updates to senior management.
- Manage relationships with security vendors, service providers, and threat intelligence partners.
Qualifications
Education
- Bachelor's Degree in Cybersecurity, Computer Science, Information Technology, Engineering, or related discipline.
- Master's Degree in Cybersecurity or Information Security preferred.
Experience
- 10+ years of cybersecurity experience.
- 5+ years of experience in Cyber Threat Management, Threat Intelligence, Security Operations, Detection Engineering, or Vulnerability Management.
- 3+ years of people leadership experience.
- Experience developing threat-informed defense strategies and cyber risk reduction programs.
- Experience working within enterprise network, infrastructure, cloud, and cybersecurity environments.
- Experience managing cross-functional cybersecurity initiatives and executive stakeholders.
More Info
Key Skills
Security automation and orchestration
Attack Surface Management
Security Operations governance
Cyber Threat Management
Detection Engineering
Security Analytics
Security control validation


