We are seeking a Security Operations Lead (Microsoft Sentinel) in Singapore. You will strengthen detection and incident response for a lean hedge fund environment, owning Sentinel tuning, triaging escalations and driving vendor-led SOC operations. You will turn alerts, vulnerabilities and posture data into clear actions and reporting that improves security outcomes.
Responsibilities
- Own Microsoft Sentinel detections including analytics rules, workbooks and Kusto Query Language (KQL) queries
- Lead day-to-day SOC and incident operations with an outsourced SOC/MDR vendor including SLAs, escalations and service reviews
- Validate log source coverage across endpoint, identity, network, cloud and critical business systems
- Triage and coordinate incident response from assessment through containment, remediation and closure in Jira Service Management
- Improve signal quality by reducing false positives and tracking Mean Time to Detect and Mean Time to Respond
- Run post-incident reviews and update detections, runbooks and incident response playbooks
- Own vulnerability scanning cadence, maintain a remediation register and track patching against agreed SLAs
- Mentor and support the Security Operations Analyst while building repeatable, audit-ready processes
Requirements
- Proven experience leading security operations in a hands-on capacity
- Strong background in Microsoft Sentinel including rule tuning, workbooks, hunting and detection engineering
- Hands-on experience with Microsoft Defender for Endpoint and Microsoft Defender for Cloud
- Demonstrated ability to manage an outsourced SOC/MDR service including escalations and performance governance
- Knowledge of incident response practices including severity assessment, coordination and post-incident reviews
- Experience with Jira Service Management and end-to-end ticket lifecycle ownership
- Strong understanding of Vulnerability Management including scanning, remediation tracking and patch governance
- Clear communication with confidence translating operational metrics into management-ready reporting
Nice to have
- Experience in a regulated environment such as financial services, asset management or a hedge fund
- Tenable Nessus or comparable vulnerability scanning tooling
- Darktrace or network anomaly detection tooling