SOC Lead
Aspire is the leading all-in-one finance operating system for growing businesses in APAC. We are on a mission to reinvent business finance for a new generation of entrepreneurs and business owners, empowering startups and MSME to realise their full potential.
Founded in 2018, Aspire has raised over USD 300M+ across equity and debt from world-class investors. In 2023, we successfully closed an oversubscribed USD 100 million Series C equity round led by Sequoia Capital and Lightspeed Ventures with participation of Tencent, Paypal Ventures, LGT Capital Partners, Picus Capital and MassMutual Ventures. To power our solutions, we have partnered with some of the best companies in the world such as Visa and Wise and helped more than 50,000 businesses using our suite of products.
For 2 consecutive years in 2022 & 2023, Aspire has been awarded Best Employer of the Year and Startup of the year by Asia FinTech Awards, and also LinkedIn’s Top Startup in Singapore. In 2023, we also made it to CB Insights’ Top 100 Global Fintech List.
You will be amazed by the energy and experience of our team! Aspire serves as an environment for you to innovate and drive change with our team of ex-entrepreneurs, ex-founders, and high-achievers with international and diverse backgrounds.
Are you a top talent who is passionate about entrepreneurship? Join our rapidly growing team to make an impact in the fintech space!
About the team:
At Aspire, we recognize that data and infrastructure security are paramount to the success and trust of our customers. Our Security Team is at the forefront of protecting and securing our systems, ensuring compliance with industry best practices, and continuously learning and evolving to stay ahead of emerging threats. Our emphasis extends to data privacy, seamlessly integrating it into our security initiatives.
About the role:
As the SOC Lead, you will be responsible for overseeing and advancing the company’s SIEM/SOAR, Incident Response, Threat Hunting and continuing strengthening of Aspire's real-time detection mechanisms. You will manage a diverse technology stack, with an emphasis on Azure Sentinel, Data Dog, AWS, Azure AD, Intune, Microsoft Defender for Endpoint, and Unifi network solutions. Your role will also encompass ensuring compliance with at least PCI DSS, ISO 27001, and SOC2 standards, contributing to a secure and reliable IT environment.
Minimum qualifications:
- Bachelor’s degree in Computer Science, Information Security, Cybersecurity, or a related field.
- Experience:
- At least 8 years of experience in cybersecurity roles, with a minimum of 4 years in a leadership position within a SOC environment.
- Threat hunting capability with up-to-date threat landscape and common attack TTPs.
- Incident handling and forensics skills including knowledge of common probing and attack methods, network/service discovery, system assessment, malware.
- Deep knowledge in cloud security
- Proven track record of building and improving security detection capabilities over a vast area of applications and infrastructure.
- Ability to prepare reports of analysis and results to provide briefings to management
- Technical Skills:
- EDR (Crowdstrike/MS Defender)
- Proficiency in managing and configuring Security Information and Event Management (SIEM) tools especially Azure Sentinel and Data Dog.
- Experience in building Security Orchestration Automation Response (SOAR)
- Experience in incident response and threat analysis.
- Proficiency in scripting languages (e.g., Python, PowerShell) for automation of security tasks.
- Experience in building AWS infrastructure to support SOC engineering processes
- Strategic skills:
- Building and leading a SOC team which is responsible for engineering, forensic, threat hunting and incident response.
- Architecting and monitoring systems to be state-of-the-art and cost efficient.
- Mentoring a team to reach new levels of expertise in both technical and non-technical skills.
Preferred qualifications:
- Experience:
- Proven and deep experience with linux based systems to monitor, engineer security monitoring solutions and understand how to detect security weaknesses.
- Familiarity with GCloud, ELK, Prometheus - Monitoring and Azure Logic Apps
- Open-source tools for SOC and their successful implementation.
- Certifications: Advanced certifications such as CISS, CEH, CompTIA Security+ or GSOC.
- Proven experience to serve as the point of contact for regulatory requirements and incident response protocols to align international and local regulations and standards, including data protection laws (e.g., GDPR, CCPA, PDPA) and financial compliance requirements (e.g., MAS TRM, PCI-DSS).
- Demonstrated expertise in managing SOC activities within regulated environments, with a proven track record of compliance with relevant standards and frameworks (e.g., ISO 27001, SOC 2, ACSC Essential Eight).
What we offer
- Uncapped flexible annual leave.
- Hybrid work arrangement.
- Training subsidy for your professional growth.
- Wellness benefit.
- Team bonding budget to foster collaboration and sense of belonging.
- Flexibility to work from anywhere (for up to 90 days per annum).
- Culture is Key: We always strive to cultivate a special culture that brings special talents together - You can learn more about our culture on our careers site and LinkedIn Life page.
Equal Opportunity Statement
Aspire is an equal opportunity employer and is committed to providing equal employment opportunities to all qualified individuals without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, or any other protected characteristic as outlined by applicable laws.
Please note: by submitting your application, you acknowledge that you have read and understood Aspire’s Data Protection Policy for Employees, Freelancers, Contractors and Job Applicants (the “Policy”), and consent to the collection, use and disclosure of your personal data by Aspire for the purposes set out in the Policy. You may withdraw consent for such collection, use and disclosure, and make an access or correction request in respect of your personal data, in accordance with the Policy by emailing people@aspireapp.com.
Apply for this job
*
indicates a required field