Tier 2 SOC Analyst / GRC Specialist
INSYGHTS SECURITY PTE. LTD.
We are looking for a Tier 2 SOC Analyst/Engineer to serve as the escalation point for our Tier 1 SOC team. This role owns in-depth investigation of escalated alerts, performs root cause analysis, leads incident response activities, and provides Governance, Risk and Compliance (GRC) consultancy to clients pursuing ISO/IEC 27001 certification and the Singapore Cyber Trust Mark. You will be a technical anchor for the SOC — turning raw alerts into confirmed incidents and confirmed incidents into stronger, audit-ready security postures for the clients we support.
Department: Security Operations Center (SOC) & Governance, Risk & Compliance (GRC) team
Reports to: SOC Manager (with parallel reporting to GRC Lead)
Works closely with: Tier 1 SOC Analysts (escalation point), Detection Engineering, IT Infrastructure, Application Development
## Key Responsibilities
Escalation & Investigation
- Serve as the primary technical escalation point for Tier 1 analysts on alerts requiring deeper analysis
- Conduct in-depth investigations across endpoint, network, cloud, identity, and application telemetry
- Correlate data across multiple tools/log sources (SIEM, EDR, NDR, cloud logs, identity providers) to determine scope and impact
- Distinguish true positives from false positives and refine triage logic accordingly
Root Cause Analysis
- Perform root cause analysis on confirmed incidents to determine initial vector, method, and any control gaps
- Document attack timelines/kill chains and produce clear technical findings for stakeholders
- Identify systemic issues (misconfigurations, missing patches, process gaps) surfaced during investigations
Incident Response
- Lead or co-lead containment, eradication, and recovery activities for security incidents
- Coordinate with IT, engineering, legal, and management during active incidents per the IR plan
- Author incident reports, timelines, and post-incident/lessons-learned reviews
- Support tabletop exercises and continuous improvement of IR playbooks and runbooks
Governance, Risk and Compliance (Client Consultancy)
- Provide consultancy services to clients pursuing ISO/IEC 27001 certification, including gap analysis, ISMS design/implementation guidance, and Statement of Applicability (SoA) support
- Advise and support clients through the Singapore Cyber Trust Mark certification process, including preparation, control implementation guidance, and readiness assessments
- Conduct risk assessments and help clients build/maintain risk registers and risk treatment plans
- Develop and review client-facing security policies, standards, and procedures aligned to ISO 27001 Annex A and Cyber Trust Mark requirements
- Support clients through internal audits, certification audits, and surveillance audits, including evidence preparation and audit findings remediation
- Manage multiple client engagements concurrently, including scoping, timelines, and client communication
Mentorship & Process
- Mentor and provide technical guidance to Tier 1 analysts, including escalation reviews and knowledge transfer
- Contribute to and maintain SOC playbooks, runbooks, and standard operating procedures
- Support onboarding of new log sources, tools, and data feeds into the SOC's monitoring scope
- Participate in an on-call/escalation rotation as needed
## Required Qualifications
- 3+ years of hands-on SOC experience, with demonstrated progression into Tier 2/senior analyst responsibilities
- Strong understanding of the attack lifecycle, common TTPs, and the MITRE ATT&CK framework
- Hands-on experience with SIEM platforms (e.g., Splunk, Sentinel, QRadar, Elastic) for investigation and reporting
- Experience with EDR/XDR tools (e.g., CrowdStrike, Microsoft Defender, SentinelOne) for endpoint investigation
- Working knowledge of ISO/IEC 27001 (Annex A controls, ISMS requirements) and ability to guide clients through gap analysis and certification prep
- Familiarity with Singapore's Cyber Trust Mark scheme and its control/assessment requirements
- Comfortable communicating directly with clients — running workshops, presenting findings, and writing client-facing reports
- Solid grasp of networking fundamentals (TCP/IP, DNS, HTTP/S, proxies) and ability to read packet captures
- Experience with incident response processes: containment, eradication, recovery, and post-incident reporting
- Familiarity with cloud security monitoring (AWS/Azure/GCP logs, IAM, CloudTrail or equivalent)
- Scripting/automation skills (Python, PowerShell, or similar) for detection logic, parsing, or workflow automation
- Excellent written and verbal communication skills — able to translate technical findings for non-technical stakeholders
- Ability to remain calm and methodical under pressure during active incidents
## Preferred Qualifications
- Certifications such as GCIH, GCIA, GCFA, CySA+, ISO 27001 Lead Implementer/Lead Auditor, CISA, or CRISC
- Direct experience supporting clients through Cyber Trust Mark or Cyber Essentials Mark certification
- Experience leading or supporting ISO 27001 certification/surveillance audits as a consultant or internal practitioner
- Familiarity with digital forensics tools and techniques (memory/disk forensics)
- Prior experience mentoring or training junior analysts
## What Success Looks Like
- Reduced mean-time-to-detect (MTTD) and mean-time-to-respond (MTTR) for escalated incidents
- Well-documented incidents with clear root cause and remediation tracking
- Clients successfully achieving ISO 27001 certification and Cyber Trust Mark certification on schedule
- High client satisfaction with GRC consultancy engagements, from gap analysis through audit
- Stronger, more capable Tier 1 team through consistent mentorship and escalation feedback
For employers only
Is this your company's job post? Verify ownership to manage this listing and receive applications directly.
Claim this listingLooking to apply for this job? Use the Apply button above.
See more jobs in Singapore, Singapore