Head of Cyber Defence (SecOps)

Job Type:  Full Time
Category:  Technology & Digital Innovation

About Us

SPH Media’s mission is to be the trusted source of news and lifestyle content in Singapore and Asia. 

One of our core purposes is to produce credible, balanced, and objective news and analysis, always with a view to uphold the public good and fostering an informed, engaged citizenry.

We welcome talented individuals to join us and grow a career in a vibrant and collaborative environment built around a culture of respect and inclusivity.

As an employer, we are committed to rewarding our people fairly and developing them in their careers. 

About the Role

We are seeking a highly skilled and strategic Head of Security Operations (SecOps) to lead our enterprise cyber defence capabilities in a dynamic and fast-paced media environment. This role is pivotal in ensuring the security and resilience of our infrastructure, content, and digital assets across on-premise and cloud environments.

The ideal candidate is a hands-on security leader with deep expertise in security incident response and management (SIRM), including leading the investigation, containment, remediation, and recovery of complex security incidents. The candidate should also possess strong experience in threat hunting, threat intelligence, security monitoring, and managing both internal security analysts and third-party Security Operations Centre (SOC) providers. Familiarity with security operations and incident response across cloud and on-premises environments is essential. The successful candidate will strengthen and modernise our cyber defence capabilities and ensure the timely and effective management of security incidents across the enterprise.

Key Responsibilities

The scope of responsibilities includes the following:  

  • Lead and manage a team of 4–5 security analysts, as well as external MSSPs and SOC providers.

  • Own and continuously enhance threat detection, investigation, and response processes using modern tooling and automation. 

  • Oversee real-time threat monitoring, threat hunting, and incident triage to identify and mitigate risks promptly. 

  • Develop and integrate proactive threat intelligence into SecOps processes and security technologies.

  • Serve as a key escalation point (role of SIRM) for security incidents and lead incident response, root cause analysis, and post-incident reporting. 

  • Lead the continuous improvement of detection rules, correlation logic, and threat-hunting techniques across SIEM and EDR platforms.

  • Collaborate with Cloud, DevOps, and IT teams to ensure security is embedded in enterprise systems and media production workflows.

  • Stay ahead of emerging threats, TTPs, and relevant threat actor campaigns, especially those targeting the media industry.

  • Define, track, and report operational metrics and KPIs to senior leadership.

  • Ensure compliance with relevant frameworks, standards, and regulations (e.g., NIST, ISO/IEC 27001, GDPR, SOC 2).

  • Work with Infrastructure teams on the design, implementation, and maintenance of security solutions, including firewalls, intrusion detection systems, encryption technologies, and identity management systems.

  • Establish and regularly test incident response playbooks, escalation procedures, crisis management processes, and recovery plans. 

  • Cyber Threat Intelligence:

    • Lead efforts to continuously monitor the threat landscape and provide timely insights on emerging threats and vulnerabilities.

    • Build relationships with external stakeholders, including threat intelligence sharing communities, government agencies, and security vendors, to strengthen organisational defences.

  • Own and manage relevant security contracts, procurement activities, and projects, including collaborating with other teams to implement and roll out new tools under the Cyber Defence Team.

  • Perform other duties as assigned by the CISO. 

Required Qualifications

  • 7+ years of experience in cybersecurity with at least 3 years in a leadership or managerial role within a SecOps function.

  • Proven experience in threat hunting, threat intelligence integration, and managing security incidents at scale. 

  • Hands-on expertise in modern SIEM platforms (e.g., Splunk, Sentinel), SOAR platforms, EDR tools, and threat intelligence feeds.

  • Experience managing hybrid or outsourced SOC environments, including managing service providers against agreed performance standards and SLAs. 

  • Solid understanding of cloud-native security (AWS, GCP, or Azure), preferably within media streaming or content distribution environments. 

  • Strong grasp of MITRE ATT&CK framework and experience building detection coverage around it.

  • Strong communication and leadership skills, with the ability to brief senior stakeholders and collaborate cross-functionally.

  • Familiarity with scripting (e.g., Python, PowerShell) and modern searc and query languages (e.g., KQL, SPL).

  • Proven experience leading teams in security incident response and management, threat management, and cyber crisis management. 

  • Preferably holds a relevant professional certification, such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), GIAC Certified Incident Handler (GCIH), EC-Council Certified Incident Handler (ECIH), or Certified Cloud Security Professional (CCSP). 

  • Additional cloud or platform-specific security certifications, such as AWS Certified Security – Specialty or Microsoft Certified: Azure Security Engineer Associate, would be advantageous.