Senior Security Operations Lead

Dymon AsiaSingaporeJob.bofoilsithe 23/09/2026
Riachtanach:AzureCloudSecuritySeniorLead

Location: Singapore

About Us

Dymon Asia Capital (“Dymon Asia”), founded in 2008, is a leading alternative investment firm with assets across public and private markets. The firm’s flagship hedge fund product is the Multi-Strategy Investment Fund (MSIF), an Asia-focused multi-manager multi-strategy fund that seeks to generate absolute consistent uncorrelated returns from emerging and developed markets.

Headquartered in Singapore, Dymon Asia operates from nine offices across the Middle East and Asia, including Hong Kong, Tokyo, Dubai, Shanghai, Mumbai, and Kuala Lumpur. Our platform is built on our people. We bring together diverse perspectives, expertise, and experience across our multi-strategy and private markets businesses. Maintaining a collaborative culture where our people are set up to do their best work is central to how we operate.

We are looking for a Security Operations Lead to own the Security Operations pillar within our Cybersecurity function, working alongside Architecture and Engineering, Security Governance, and Security Threat and Incident Management. This is a lean, senior team working in close partnership with IT Infrastructure, Compliance, and Legal. The role owns day-to-day delivery across monitoring and detection, threat intelligence, vulnerability management, security awareness, and posture reporting, supported by a Security Operations Analyst, and manages the relationship with an external managed SOC that provides 24/7 monitoring coverage.

This role provides full operational and technical support to the Incident Response Manager, who leads material incidents and owns scoping, containment decisions, stakeholder coordination, regulatory notification, and post-incident reviews. Our environment is Microsoft-centric, built on Sentinel, Defender XDR, Entra ID, and Intune, alongside Darktrace, Cisco Umbrella, and Nessus. This is a working lead role rather than a pure management position in a small team, where security decisions can affect trading — so judgement about business impact matters as much as technical depth.

Key Responsibilities

Own delivery of the Security Operations pillar, covering monitoring and detection, threat intelligence, vulnerability management, security awareness, and posture reporting.

Own the managed SOC relationship, including service level governance, escalation and alert quality, the joint detection backlog, and vendor performance reporting with supporting evidence.

Provide full operational and technical support to the Incident Response Manager across the incident response lifecycle, including severity assessment, playbook maintenance, investigation, evidence collection, containment execution, and recovery activities.

Support the Incident Response Manager during major incidents by directing technical investigation workstreams when delegated, executing containment actions, and coordinating operational inputs from the managed SOC and IT Infrastructure.

Provide the Incident Response Manager, Compliance, and the Head of Cybersecurity with accurate technical facts, timelines, impact assessments, and supporting evidence for crisis communications and regulatory, investor, and counterparty notification workflows.

Support the Incident Response Manager in delivering the annual tabletop exercise program and scenario-based response simulations, and implement agreed lessons learned through playbook, detection, and control improvements.

Set detection strategy and coverage direction, including MITRE ATT&CK mapping, detection engineering priorities, and threat intelligence operationalization.

Own vulnerability and patch service level governance across the estate, escalating breaches to infrastructure owners and to management with evidence.

Manage and develop the Security Operations Analyst, own the on-call Rota, and remain hands-on in the tooling as a working lead in a small team.

Own security operations metrics and reporting to the COO and executive committee, maintain audit-ready evidence aligned to MAS Technology Risk Management guidelines, MAS Notice 658, and NIST CSF 2.0, and validate disaster recovery and backup recovery testing with IT Infrastructure.

Job Requirements

Bachelor’s degree in Computer Science, Information Security, Engineering, or a related discipline (or equivalent practical experience) preferred.

8+ years in security operations, including at least 2 years leading a function or team in a regulated environment, with experience managing or mentoring security analysts; substantial experience supporting major incident response. Financial services, hedge fund, or asset management experience are advantageous.

Demonstrable experience providing technical and operational support during material security incidents — from detection and investigation through containment, recovery, and post-incident review — under an Incident Response Manager.

Experience owning an outsourced SOC or managed detection and response provider, including holding the service to its contractual commitments.

Microsoft Sentinel and Defender XDR at operational depth, including KQL, detection rule strategy, and advanced hunting.

Detection strategy and coverage management using MITRE ATT&CK, with the ability to set direction for detection engineering and threat intelligence.

Vulnerability management governance, including service level enforcement and driving remediation across infrastructure teams that do not report to you.

Experience preparing technical evidence and impact assessments to support regulatory incident notification under MAS Technology Risk Management guidelines and MAS Notice 658, or an equivalent regime.

Cloud and identity security operations, including Azure logging, Defender for Cloud, Entra ID, conditional access, and privileged access.

Able to brief the Incident Response Manager and senior stakeholders clearly during and after an incident, remain calm and structured under pressure, and participate in an on-call Rota; hands-on technical currency required as a working lead.

Preferred certifications: SC-200 Microsoft Security Operations Analyst. GCIH, GCIA, GCFA, or GCTI are advantageous, as are CISSP or CISM.