Joshua A.

CEO

Singapore, Singapore, Singapore6 yrs experience
Most Likely To SwitchHighly Stable

Key Highlights

  • Over 6 years of cybersecurity experience.
  • Expert in threat detection and incident response.
  • Proven leadership in managing SOC operations.
Stackforce AI infers this person is a Cybersecurity professional with expertise in Security Operations and Incident Management.

Contact

Skills

Core Skills

Threat Detection & AnalysisSecurity Operations CenterInformation SecurityCybersecurityService DeskIt Support

Other Skills

Intrusion DetectionServiceNowWebOrionCloud SecurityCarbon BlackGoogle SecOpsTeam Leadership / MentoringCrowdstrike FalconIBM QRadarCyberarkAWS CloudAnomaliOffice 365VeracodeZscaler Cloud Security

About

I’m a cybersecurity professional with over 6 years of experience (since 2019), currently serving as a Team Lead – Security Operations Center (SOC) at NCS Pte. Ltd., a leading IT and communications engineering provider in the Asia-Pacific region. My role focuses on safeguarding clients’ digital environments through real-time threat detection, incident response, and proactive defense. I lead and mentor a team of SOC analysts, oversee daily operations, manage escalations, and ensure effective coordination across the Cyber Defense Team to maintain operational excellence. On the technical side, I stay fully hands-on with tools like Google SecOps, CrowdStrike Falcon, IBM QRadar, VMware Carbon Black, Cloud Security solutions, and AWS Cloud, while using ServiceNow as the core ITSM platform. Beyond daily monitoring, I focus on improving workflows, refining playbooks, and strengthening the SOC’s detection and response maturity. I hold multiple industry certifications, including: • ITIL® 4 Foundation Certificate in IT Service Management • (ISC)² Certified in Cybersecurity (CC) • Microsoft Certified: Security Operations Analyst Associate (SC-200) • Certified Network Defender (CND) • AWS Certified Cloud Practitioner I’m passionate about building capable teams, continuously learning, and contributing to a safer digital ecosystem; one alert, one incident, and one improvement at a time.

Experience

6 yrs
Total Experience
1 yr 6 mos
Average Tenure
3 yrs 9 mos
Current Experience

Ncs group

2 roles

SOC Team Lead

Promoted

May 2025Present · 1 yr 1 mo · Singapore · On-site

  • Promoted to lead and oversee the daily operations of the Security Operations Center (SOC), ensuring smooth coordination across the team and effective incident management.
  • Mentor and guide junior analysts, conduct knowledge-transfer sessions, review cases, and support continuous skill development to improve detection and response quality.
  • Assist the SOC Manager with operational planning, prioritization, and execution of daily tasks to maintain operational excellence.
  • Manage day-to-day SOC activities including shift handovers, ticket escalations, workload distribution, and communications with internal stakeholders.
  • Lead investigations for complex or high-severity incidents, performing advanced technical monitoring, intrusion detection, event correlation, and threat containment.
  • Conduct initial triage and in-depth analysis of alerts, eliminate false positives, validate true positives, and determine incident severity and business impact.
  • Perform event correlation and historical log searches to identify root cause, attack patterns, scope of compromise, and potential lateral movement.
  • Oversee case management activities, ensuring proper documentation, report generation, and timely closure of all incidents.
  • Monitor and triage web defacement alerts, collaborating with the Incident Response team to ensure swift remediation and accurate reporting.
Threat Detection & AnalysisIntrusion DetectionServiceNowWebOrionCloud SecurityCarbon Black+7

SOC Analyst

Sep 2022May 2025 · 2 yrs 8 mos · Singapore · On-site

  • Conducted continuous SIEM monitoring, correlated security events, and identified potential threat patterns.
  • Performed initial triage of alerts, validated true positives, eliminated false positives, and escalated actionable incidents.
  • Investigated security events through event correlation and historical log analysis to determine root cause, scope, and compromise impact.
  • Correlated activities across multiple institutions to identify attack patterns, related incidents, and signs of lateral movement.
  • Managed incident cases via the ticketing system, documented findings, generated reports, and ensured timely closure of all investigations.
  • Monitored web defacement alerts, performed incident triage, and produced detailed reports while coordinating closely with the incident response team for swift remediation.
  • Maintained 24x7 SOC coverage through rigorous shift rotations, ensuring uninterrupted monitoring and delivering rapid incident response to effectively minimize security risks.
Threat Detection & AnalysisIntrusion DetectionServiceNowWebOrionCarbon BlackSecurity Operations Center+4

S&p global

Information Security Associate

Mar 2022Aug 2022 · 5 mos · Georgetown, Penang, Malaysia

  • 📑 IHS Markit is now part of S&P Global 🤝
  • » Triage and investigate cybersecurity alerts.
  • » Monitor and respond to alerts generated by our enterprise security tools.
  • » Triage issues escalated by the Cyber Defense team ensuring quick and appropriate follow-up actions are taken.
  • » Recommend alert tuning as required and participate in the tuning process.
  • » Improve our detection capabilities by building and enhancing alert rules and actively hunting for evidence of malicious activity.
  • » Operate and maintain security tooling and platforms.
  • » Follow and enhance security playbooks for the Security Operations Team.
  • » Work closely with the Incident Response Team to ensure time-sensitive actions are performed quickly and diligently.
  • » Work on various internal projects/initiatives such as UAT and POC of new SOC tools, working cross-functionally with other teams/departments as a stakeholder.
  • » Participate in firm-sponsored training, red/blue team events.
  • » Perform whitelisting/filtering of false-positive signals.
  • » Block malicious network traffic and isolate infected hosts on internal networks.
  • » Participate in working with the Security automation team in developing cutting edge security enhancements.
Threat Detection & AnalysisIntrusion DetectionOffice 365VeracodeCloud SecurityInformation Security+9

Ihs markit

2 roles

Information Security Associate I

Feb 2021Mar 2022 · 1 yr 1 mo · Penang, Malaysia

  • 📑 IHS Markit is now part of S&P Global 🤝
  • » Coordinate response to security incidents and request.
  • Incident & Request ticket queue management for Information Security related incidents and tasks.
  • Works initially for all tickets assigned to Information Security queue. Escalates more complex issues to Tier 2 SOC.
  • » Apply security policies and procedures.
  • » Basic analysis of IDS, Syslog and SIEM alerts.
  • » Create incidents based on suspicious alerts and proceed according to incident response guidelines.
  • » Use advance analytic tools to determine emerging threat patterns and vulnerabilities.
  • » Monitor network availability for any potential security incidents and investigate security events when applicable.
  • » Identify security breaches and take action to stop and prevent them in the future.
  • » Monitor identity and access management, including monitoring for abuse of permissions by authorized system users.
  • » Work closely with all operational teams to assign ownership of events.
  • » Support maintenance and operation of monitoring tools.
  • » Provide support for multiple back-office information security products.
  • » Configuration and administration of internal security team specific solutions.
  • » Supporting 24x7 SOC support coverage.
Threat Detection & AnalysisIntrusion DetectionOffice 365VeracodeCloud SecurityInformation Security+9

Information Security Associate

Mar 2020Feb 2021 · 11 mos · Penang, Malaysia

Threat Detection & AnalysisIntrusion DetectionOffice 365VeracodeCloud SecurityInformation Security+9

Dnex technology sdn bhd

Security Analyst

Sep 2019Feb 2020 · 5 mos · Bangsar South, Kuala Lumpur

  • Internship at Security Operations Centre (SOC) for 6 months
  • Technical Task:
  • Respond to security alerts.
  • Investigate and gather evidences of incidents for Incident Reporting from SIEM console.
  • Acknowledge each security alert triggered on SIEM console.
  • Monitor Website Uptime and Integrity.
  • Monitor client's Domain Name System (DNS) behavior, including its security extensions (DNSSEC) via DNSViz.
  • Monitor on the critical alert triggered from the services on servers, switches, applications and service via Nagios and report it to the Security Analyst (SA).
  • Create query and develop content (on Dashboard) for monitoring purposes in SIEM console.
  • Administrative Task:
  • Daily Health Check on every clients device for detecting logs availability.
  • Notify Senior Security Analyst (SSA) or Team Leader in the event of serious security threats.
  • Create an open ticket for Incident Reporting.
  • Assist on client's Security Monthly Report.
  • Log daily activities to be reviewed by SSA for internship reporting purposes.
Threat Detection & AnalysisIntrusion DetectionSecurity Operations CenterMicrosoft 365CybersecurityNagios

Intel electronics (malaysia) sdn bhd

Global IT Support

Nov 2015Aug 2016 · 9 mos · Penang, Malaysia

  • Global IT Support (L1 Support)
  • Intel escalation process (depends on the sensitivity of the issues)
  • Troubleshoot Windows issues on Windows Roaming & Local Profile, Temporary Admin Right and etc.
  • Troubleshooting Office products’ issues on Lync, Outlook (.PST file, .OST file and Mail Cloud) and etc.
  • Troubleshooting Intel products’ issues on Let’s Meet (LM), Wellnomics, Citrix, Intel Software Market (ISM), Mokafive, Syncplicity
  • Knowledge in Office 365, Intel enforcement process & the Enforcement Management Portal (EMP)
Intrusion DetectionComputer Hardware TroubleshootingMicrosoft 365Service DeskIT Support

M-tech it solutions

IT Technician

Jun 2013Oct 2014 · 1 yr 4 mos · Penang, Malaysia

  • IT Technician (as Intern)
  • Provide on-site technical support
  • Installing and configuring computer hardware, operating systems and applications
  • Monitor networking equipment and servers
  • Installing and configuring CCTV and alarm system
  • Involved in PC Refresh of Laptops/Desktops for Alliance Bank Malaysia with the support from Hewlett-Packard (HP) Malaysia
  • Involved in setting up Centralized Customer Queue Management System for Bank Rakyat Malaysia throughout Northern region
Computer Hardware Troubleshooting

Education

Universiti Teknikal Malaysia Melaka

Bachelor of Computer Science (Computer Security) — Information Technology

Jan 2016Jan 2020

Stackforce found 100+ more professionals with Threat Detection & Analysis & Security Operations Center

Explore similar profiles based on matching skills and experience