Job Description
Lead / Senior Security Incident Responder
Posting Start Date:  16/09/2026
Job Category:  Experienced
Job Family:  Infocomm Technology & Smart Systems

What the role is

What the role is
At #TeamCPF, you’re not just joining a team; you are embracing a culture of excellence, collaboration, and meaningful impact. You will play a pivotal role in empowering over 4 million members to secure their retirement, healthcare, housing needs and better navigate life’s uncertainties.

We thrive on sharp minds and insightful decisions. Your ability to analyse and think critically isn't just valued; it's essential. Every choice you make contributes to our collective success.

Collaboration is our way of life. We believe in the power of effective partnerships and seamless communications across teams. Together, we amplify each other’s strengths and achieve remarkable results.

Our learning never stops. We encourage your inquisitiveness and courage to embrace new challenges head-on. Your agility, readiness to challenge conventions, embrace of data-driven strategies, dedication to learning and applying new skills fuels our innovation and progress.

At the core of everything we do lies a genuine desire to make a difference. We serve our community and support each other with compassion, empathy, and unwavering dedications. Every action we take is guided by a deep sense of purpose and a commitment to those we serve.

Join us at #TeamCPF! Together, let's redefine possibilities and leave a legacy that echoes for generations.

What you will be working on
As a Security Incident Responder in our Security Incident Response Team (SIRT), you will serve as the key technical lead in managing active security incidents. Beyond incident response, you will contribute to proactive security activities including threat intelligence, threat hunting, and red/purple team engagements. You will also work closely with project teams on security onboarding and provide leadership and guidance to L1 SOC Analysts.

In this role, you will:

Incident Response Leadership

  • Serve as the technical lead during active security incidents, working closely with the Incident Commander to coordinate and execute response actions across technical teams and stakeholders.
  • Manage end-to-end incident workstreams from initial triage and containment through to eradication, recovery, and post-incident review, in adherence with the organisation's Incident Management Framework and defined service level agreements.
  • Lead root cause analysis and post-incident reviews, translating findings into actionable improvements to prevent recurrence.
  • Prepare and maintain accurate incident reports, situation updates and timely communications for internal stakeholders and regulatory authorities, where required.
  • Act as the primary escalation point for L1 SOC analysts during high-severity or complex incidents, providing technical guidance and decision support.

 

Stakeholder Coordination & Communication

  • Work closely with the Incident Commander to ensure all internal and external stakeholders are kept informed, with clear roles, responsibilities, and communication channels maintained throughout the incident lifecycle.
  • Liaise with regulatory authorities and external parties as required during incident handling, reporting, and post-incident follow-up.
  • Collaborate with infrastructure, network, application, and data teams to drive effective containment, investigation, and remediation efforts.
  • Provide timely and accurate technical situation updates to the Incident Commander and security leadership.

 

Threat Intelligence & Proactive Security

  • Contribute to threat intelligence activities, including the analysis of threat actor Techniques, Tactics and Procedures (TTPs), Indicators of Compromise (IOC) management, and intelligence-led detection improvements.
  • Lead or support threat hunting exercises to proactively identify hidden threats, anomalous behaviours, and gaps in detection coverage across the environment.
  • Engage in red team and purple team activities to test and validate detection and response capabilities, translating findings into operational improvements.

 

Detection Engineering & SOC Development

  • Work closely with SIEM, Detection, and Workflow Engineers to develop, tune and optimise detection rules, correlation logic and automated response workflows.
  • Partner with project teams to onboard new systems and platforms into security monitoring, ensuring adequate detection coverage and logging standards.
  • Drive the development and refinement of incident response playbooks, standard operating procedures and escalation frameworks.

 

Operational Excellence & Improvement

  • Champion continuous service improvement initiatives, including post-incident reviews, trend analysis, metrics reporting and operational maturity assessments.
  • Apply AI-assisted tools and platforms, including GenAI-powered analytics and AI agents, to enhance threat detection, automate routine activities and improve incident investigation workflows.
  • Contribute to the evaluation and adoption of new security technologies, tools, and methodologies to strengthen the organisation's security posture.

 

What we are looking for
We value the diverse talents and experiences that each individual brings to the table. While mastery of every requirement may not be necessary, familiarity and expertise in some of the following areas will position you for success within this team.

  • Relevant experience in security operations, incident response, or related cybersecurity roles.
  • Demonstrated ability to lead incident response workstreams in coordination with an Incident Commander, exercising sound judgement and composure in time-critical, high-pressure situations.
  • Hands-on experience with SIEM platforms, EDR/XDR, WAF, NDR/IDS/IPS, and vulnerability management tool.
  • In-depth knowledge of Incident Management Frameworks and practices, including ITIL processes, incident severity classification and escalation protocols.
  • Good understanding of the cyber threat landscape, including advanced attack vectors, TTPs, threat actor profiling, and the MITRE ATT&CK framework.
  • Ability to convey complex technical findings clearly to both technical and non-technical audiences, including senior stakeholders.
  • Familiarity with relevant cybersecurity regulatory requirements, standards and frameworks, such as  CyberSecurity Code of Practice (CCoP), ISO 27001, NIST, CIS Controls.
  • Experience with threat intelligence, threat hunting methodologies, and/or red/purple team engagements would be advantageous.
  • Familiarity with network protocols, operating systems (Windows and Linux), and cloud environments (AWS and Azure) would be advantageous.
  • Experience with GenAI tools, AI-assisted security platforms or AI agents for security operations use cases would be advantageous.
  • Relevant cybersecurity certifications such as GCIH, GCFA, CISSP, CISM, OSCP or equivalent would be advantageous.
  • Ability to perform on-call and standby duties as part of a rostered 24/7 support arrangement, including call-out support during nights, weekends, and public holidays.

 

The seniority of appointment and actual corporate job title will commensurate with individual work experiences.

Position is on a 2-year full-time contract directly under the payroll of CPF Board with potential for emplacement into a permanent position

 

What you can expect

What you can expect
Being part of #TeamCPF means embarking on a challenging and rewarding career in a progressive workplace that values productivity and growth. Here’s what awaits you:

  • Opportunities to engage in a mix of formal and informal training, keeping your skills sharp in our ever-evolving technological landscape. 
  • Promotion opportunities based on your capability and on-the-job performance. 
  • A vibrant community of like-minded and friendly colleagues, where collaboration and creativity thrive. 
  • A hybrid work model that offers flexibility for remote work, subject to exigencies of service. 
  • Flexible dress code that empowers you to choose your appropriate outfit for the day. 
  • A comprehensive rewards package that includes annual leave, pro-family leave, medical and dental benefits, and access to recreational activities.