Cyber Threat (CSOC) Engineer
Date: 27 Jul 2026
Location: Braddell, SG
Company: Network For Electronic Transfers (S)
BCS is NETS’ wholly owned subsidiary, and is an entity within the NETS Group. It manages and operates clearing and payment infrastructure for the Singapore Automated Clearing House, including Fast And Secure Transfers (FAST), Inter-bank GIRO (IBG), Cheque Truncation System (CTS), and provides services for PayNow and SGQR Central Repository.
About BCS:
BCS is NETS’ wholly owned subsidiary and is an entity within the NETS Group. It manages and operates clearing and payment infrastructure for the Singapore Automated Clearing House, including Fast And Secure Transfers (FAST), Inter-bank GIRO (IBG), Cheque Truncation System (CTS), and provides services for PayNow and SGQR Central Repository.
Team and Position Summary:
The IT Security Team at BCS ensures the security, availability and resilience of BCS systems, protecting data and mitigating emerging cyber threats in alignment with regulatory requirements.
The Cyber Security Operations Centre (CSOC) unit is a key function within IT Security, providing 24/7 monitoring, threat detection, and incident response to safeguard BCS’ critical assets.
The CSOC Engineer is responsible for monitoring, detecting, investigating, and responding to cybersecurity threats across the organization. This role focuses on operating and optimizing security monitoring technologies, conducting threat hunting activities, managing security incidents, and identifying vulnerabilities to strengthen the organization's security posture.
The engineer will work closely with IT and security teams to enhance detection capabilities, automate security operations through SIEM/SOAR platforms, support incident response and forensic investigations, and provide Tier 2/3 support for complex cybersecurity events within a 24/7 security operations environment
Responsibilities:
- Operate and manage cyber defence tools to continuously monitor and analyse system activities, identifying potential threats, vulnerabilities, and malicious behaviour.
- Review and enhance routine monitoring use cases to ensure effectiveness, relevance, and adequate coverage.
- Develop and implement improvements, including scripting and SIEM/SOAR tuning, to strengthen and automate monitoring, triaging, and analysis processes.
- Identify security weaknesses across systems and applications, and collaborate with IT teams to prioritise remediation, track progress, and ensure timely patching and risk mitigation.
- Perform proactive threat hunting to detect indicators of compromise (IOCs), and identify threat actor tactics, techniques, and procedures (TTPs) within the environment.
- Support 24x7 security operations by handling Tier 2/3 incident escalations, including investigation, response, and reporting of security events.
- Assist in digital forensic investigations, including collection, preservation, and analysis of evidence.
Requirements:
Education and Experience
- Degree or Diploma in Computer Science, Computer Engineering, or Information Security related fields.
- At least 6 years of experience in a Security Operations Centre (SOC), CERT/CIRT, or a similar incident response environment.
Skills and Knowledge
- Strong hands-on experience with SIEM/SOAR platforms and security controls across host and network layers.
- Familiarity with MAS Technology Risk Management Guidelines (TRMG), Cyber Hygiene Notice, and Cybersecurity Code of Practice (CCoP).
- Strong ability to analyse and interpret network diagnostic outputs (e.g. ping, traceroute, nslookup).
- Good understanding of frameworks and standards such as OWASP Top 10, CVSS, MITRE ATT&CK, and Cyber Kill Chain.
- Solid working knowledge of operating systems (Microsoft Windows, UNIX, Linux).
- Understanding of network architectures and communication protocols (LAN, WAN, WLAN, WWAN).
- Proficient in incident response methodologies and best practices.
- Experience in scripting (e.g. Python, Bash, PowerShell) and cloud environments is an advantage.
- Strong analytical and problem-solving skills, with the ability to handle complex security investigations.
- Resilient and able to perform effectively in a fast-paced, high-pressure environment.
- Good communication and presentation skills, including the ability to present findings clearly to stakeholders and management.
Professional Certifications
- Relevant industry certifications (e.g. GSEC, GCIH, GCIA, GCTI, GCFA, GCFE, GNFA) are advantageous.
Banking Computer Services Pte Ltd (a subsidiary of Network for Electronic Transfers (Singapore) Pte Ltd)