Velocity Operations Team Lead
- Sygnia
- Singapore, Singapore
- SGD 140,000 – SGD 180,000
Sygnia is a top tier cyber technology and services company, providing consulting and incident response support for organizations worldwide. Sygnia works with companies to proactively build their cyber resilience and to respond and defeat attacks within their networks. It is the trusted advisor and cybersecurity service provider of IT and security teams, senior managements, and boards of top organizations worldwide, including Fortune 100 companies.
The company draws on top talent from the ranks of elite military technology units and from across the cyber industry and has some of the world’s top talents in cyber security. Described by Forbes as a “cyber security delta force”, it applies technological supremacy, digital combat experience, data analytics and a business-driven mindset to cyber security, enabling organizations to excel in the age of cyber.
Sygnia is looking for an experienced MDR Site Team Lead to join our MDR Operations team in Singapore. This is a hands-on technical leadership role combining people management with advanced security operations. The Team Lead will manage and develop a team of MDR Analysts while serving as the senior technical authority on shift and the first point of escalation for complex investigations and high-severity security events. Working closely with the MDR Site Manager and Sygnia’s global MDR teams, the Team Lead will be responsible for maintaining high technical standards, meeting client SLAs, ensuring effective Follow-the-Sun operations, and continuously improving our detection and response capabilities.
Main Responsibilities
- Lead, manage, and professionally develop a team of MDR Analysts, providing ongoing technical coaching, mentoring, and performance feedback.
- Manage team scheduling, shift coverage, and on-call allocation to support 24/7 Follow-the-Sun operations.
- Serve as the senior technical escalation point for complex investigations and high-severity security events.
- Manage alert queues and priorities, ensuring acknowledgement, investigation, and escalation are handled in accordance with client SLAs.
- Monitor operational performance, identify potential SLA risks or bottlenecks, and proactively rebalance workloads when required.
- Ensure effective cross-region shift handovers, including open investigations, client communications, and outstanding operational tasks.
- Lead and support in-depth security investigations, including log-based forensic analysis across endpoint, network, identity, email, cloud, and application environments.
- Continuously improve detection capabilities by tuning existing logic, reducing false positives, and translating threat intelligence and post-incident findings into new or enhanced detections.
- Review analysts’ investigations, escalations, reports, and client communications to ensure technical accuracy, completeness, consistency, and professionalism.
- Act as a technical point of contact for clients during security events, clearly communicating findings, risks, status updates, and recommended actions to both technical and non-technical stakeholders.
- Produce and review client-ready incident and investigation reports, including timelines, root cause, impact assessments, and remediation recommendations.
- Serve as the focal point between MDR and Incident Response teams when critical events require transition to full Incident Response.
- Develop and maintain MDR procedures, runbooks, knowledge articles, and client-specific documentation.
- Identify opportunities to improve MDR processes, methodologies, and operational efficiency.
- Support the MDR Site Manager with ongoing operational activities and act on their behalf when required.
Requirements
Main Requirements
- 5+ years of hands-on experience in SOC, MDR, or MSSP environments, including security monitoring, investigation, detection, and incident response.
- 1+ years of experience leading or directly managing security analysts, including technical mentoring, performance management, and shift or resource planning.
- Strong hands-on investigation experience across SIEM, EDR/XDR, network, identity, email, cloud, and endpoint telemetry.
- Experience with forensic and incident response investigations, including host, network, and cloud log analysis.
- Strong understanding of security threats, attacker behavior, investigation methodologies, and incident response processes.
- Experience building, tuning, and improving detection scenarios and correlation logic.
- Hands-on experience investigating security events in at least one major cloud platform (AWS, Azure, or GCP).
- Experience analyzing network security telemetry, including firewalls, WAF, proxy, and DNS logs.
- Experience investigating EDR/XDR, Windows, Sysmon, identity, and email security telemetry.
- Familiarity with malware analysis and threat intelligence enrichment.
- Proven ability to produce high-quality incident and investigation reports for external clients.
- Experience working in a 24/7 or Follow-the-Sun operational environment.
- Strong leadership and coaching capabilities, with the ability to develop analysts while maintaining high technical and operational standards.
- Excellent written and verbal English, with the confidence to lead technical discussions with clients, including during high-pressure incidents.
- Strong judgment, prioritization, and decision-making skills, with the ability to manage multiple competing client priorities and SLAs.
- Proactive, accountable, and improvement-oriented mindset.
- Ability to support escalations and critical events outside regular working hours when required.
- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related field, or equivalent practical experience.
Advantages
- Previous experience working for an MSSP or MDR provider.
- Relevant cybersecurity certifications.
- Knowledge of Python for security automation and analysis.
- Experience with SQL for querying security, log, or case-management datasets.
Skills
- Security Operations
- Incident Response
- SIEM
- EDR
- Threat hunting
- Team Leadership
- Client SLA Management






