368,941open jobs
9,452companies
47,951added this week
Browse all
Salary
$89k – $220k per year (Estimated)
Location
In office (Singapore)
Seniority
Principal · 8+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
GovTech Singapore (Government Technology Agency) is the statutory board under the Smart Nation and Digital Government Group (SNDGG) responsible for driving Singapore's digital government transformation. The agency develops and manages key national digital infrastructure and public platforms, including Singpass, LifeSG, and the CODEX government tech stack. By building in-house capabilities in software engineering, cybersecurity, data science, and AI, GovTech delivers secure, citizen-centric digital services to modernize public administration.

[What the role is]

[LTA-ITCD] LEAD / PRINCIPAL / SENIOR CYBER THREAT INTEL ANALYST

[What you will be working on]

The Cyber Threat Intelligence Analyst will be responsible for identifying, tracking, and analysing emerging cyber threats, with a focus on protecting critical IT/OT systems in the land transportation sector. This role goes beyond passive news consumption and emphasises active threat research, transforming global threat data into localised, actionable monitoring strategies and detection logic.

Key Responsibilities

  • Intelligence Programme Development: Lead the development and continuous improvement of the Threat Intelligence (TI) function, including the implementation of of Standard Operating Procedures (SOPs) and CTI solution for intelligence collection, analysis, and dissemination.
  • Threat Research & Actor Tracking : Conduct proactive research into the Tactics, Techniques, and Procedures (TTPs) of threat actors, with particular focus on the Asia-Pacific region and Industrial Control Systems (ICS).
  • Monitoring List Management : Curate, validate, and maintain high-fidelity monitoring lists, including Indicators of Compromise (IOCs), for ingestion into SIEM, EDR, and Network Traffic Analysis tools.
  • Detection Engineering Support : Translate research findings into technical detection artefacts, such as YARA, Sigma, or Snort rules, to strengthen proactive threat hunting and detection capabilities.
  • Incident Response Integration : Act as the Tier- 3 intelligence lead during critical incidents, providing real-time threat context, infrastructure pivoting, and attribution support to the CERT team.
  • Vulnerability Intelligence : Monitor and prioritise newly disclosed CVEs based on the organisation’s technology stack, providing actionable, risk-based assessments to patching and infrastructure teams.
  • TTP Mapping : Map observed adversary behaviours to the MITRE ATT&CK framework to identify visibility gaps and areas for improvement in existing security controls.
  • Stakeholder Reporting : Produce high-quality intelligence report/ update (including Flash Alerts) for emerging or imminent threats and monthly strategic summaries for management and public transport operators.

Technical Skills & Competencies

  • OSINT & Investigation - Strong capability in conducting open-source investigations across surface, deep, and dark web sources, including forums, code repositories, and social media, to identify leaked credentials or planned threat campaigns.
  • Automation - Proficiency in scripting to build custom scrapers, automate Threat Intelligence Platform (TIP) workflows, and manage large-scale intelligence datasets.
  • Log Analysis - Ability to correlate threat intelligence with internal telemetry (e.g. proxy, firewall, EDR logs) to validate malicious activity and identify early indicators of compromise.
  • Framework Knowledge - Strong understanding of MITRE ATT&CK, Diamond Model of Intrusion Analysis, and Cyber Kill Chain.

[What we are looking for]

  • Knowledge in Computer Science, Computer Engineering, Information Technology or related field.
  • At least 8 years of experience in cybersecurity, with at least 4 years in Threat Intelligence, Advanced SOC Operations, or Incident Response roles.
  • Education - Bachelor’s degree in Computer Science, Information Security, or a related discipline.
  • Professional Certifications - GIAC Cyber Threat Intelligence (GCTI) or Certified Information Systems Security Professional (CISSP)
  • Desired Technical Certifications - Relevant technical certifications such as GIAC Certified Incident Handler (GCIH), GIAC Certified Forensic Analyst (GCFA) or GIAC Reverse Engineering Malware (GREM) would be advantageous.
  • Demonstrated track record in mentoring junior analysts and uplifting SOC/CERT capabilities.
  • Strong technical writing and communication skills, with the ability to brief senior leadership and executive stakeholders on complex cyber risk matters.
  • Ability to operate effectively in a cross-matrix environment, as well as independently and decisively in a fast-paced, high-impact operational setting.
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,941 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Singapore
$26k – $64k per year (Estimated) • In office • Full-Time • 12+ years exp • Bachelor's Degree • Hyderabad
DevOps
AWS
Azure
GCP
Cybersecurity
Cyber Kill Chain
Diamond Model
MITRE ATT&CK
Apply
$32k – $72k per year (Estimated) • In office • Full-Time • 6+ years exp • Bengaluru
C++
Java
Python
YARA
Databases
Amazon Aurora
DevOps
Azure
GCP
Kubernetes
Cybersecurity
MITRE ATT&CK
Suricata
YARA
Zeek
Apply
up to $37k per year (gross) • In office • Full-Time • 3+ years exp • Novosibirsk
Bash
PowerShell
Python
AI/ML
Red Teaming
DevOps
AWS
IAM
Cybersecurity
Least Privilege
Metasploit
MITRE ATT&CK
Nessus
Nmap
OpenVAS
Snort
Suricata
Wazuh
Management
Slack
Apply
$32k – $78k per year (Estimated) • In office • Full-Time • Bengaluru
Python
AI/ML
Anomaly Detection
LLM
PyTorch
Reinforcement Learning
TensorFlow
Tokenization
DevOps
AWS
Azure
GCP
IAM
Kubernetes
Cybersecurity
ISO 27001
MITRE ATT&CK
Threat Modeling
Apply
$67k – $171k per year (Estimated) • In office • Bachelor's Degree • Singapore
JavaScript
Python
SQL
YARA
DevOps
AWS
AWS Lambda
Azure
VMWare
Cybersecurity
Ghidra
IDA Pro
Wireshark
YARA
Apply
$77k – $215k per year (Estimated) • In office • Contractor • 3+ years exp • Singapore
JavaScript
Python
TypeScript
Python
Django
FastAPI
Databases
PostgreSQL
Redis
AI/ML
AI Agents
LangGraph
LLM
Prompt Engineering
LangChain
Edge AI
Frontend
Angular
React.js
Vue.js
Apply
Apply
$110k – $239k per year (Estimated) • In office • Contractor • 3+ years exp • Singapore
AI/ML
ChatGPT
Claude
Claude Code
Copilot
Apply
$93k – $210k per year (Estimated) • In office • Contractor • 8+ years exp • Bachelor's Degree • Singapore
DevOps
CI/CD
Apply
$95k – $215k per year (Estimated) • In office • Contractor • 5+ years exp • Singapore
Cybersecurity
OWASP Top 10
Apply
$90k – $241k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • Singapore
C++
Python
Ruby
Apply
In office • Internship • Bachelor's Degree • Singapore
Python
AI/ML
AI Agents
Prompt Engineering
RAG
Apply
$47k – $165k per year (Estimated) • Remote/Hybrid • Full-Time • 1+ year exp • Bachelor's Degree • Singapore
DevOps
CI/CD
Apply
In office • Full-Time • Bachelor's Degree • Singapore
Cybersecurity
SBOM
Apply
$117k – $251k per year (Estimated) • Remote/Hybrid • Full-Time • Singapore
Apply
See all jobs
This is one of many
368,941 more open roles from verified company boards, updated every day.