
Overview
The Cyber Fusion Centre is Enovise's operational hub for integrating threat intelligence, detection, and response into a unified, high-tempo capability. As Cyber Fusion Centre Lead for the APAC region, you will build, run, and continuously improve a fusion centre operation that serves government and enterprise clients with some of the most demanding security requirements in the region. You will lead a multidisciplinary team of analysts, engineers, and intelligence professionals, setting standards for detection quality, response velocity, and intelligence integration. This role requires a rare combination of technical depth, operational leadership, and the ability to communicate with clarity across all levels of a client organisation.
Responsibilities
- Lead day-to-day operations of the Enovise Cyber Fusion Centre for APAC-region clients, including triage, escalation, and incident coordination.
- Integrate threat intelligence feeds into detection workflows and ensure analytics reflect current adversary behaviour.
- Develop and maintain detection logic, correlation rules, and response playbooks across SIEM and SOAR platforms.
- Drive continuous improvement in detection coverage, mean time to detect, and mean time to respond metrics.
- Manage and mentor a team of fusion centre analysts across shift operations, coaching for both technical and analytical skill.
- Serve as the senior point of contact for clients during significant incidents and provide clear, timely situational awareness.
- Liaise with Enovise red team and DFIR practices to ensure findings feed back into detection and response capability.
Requirements
- 7+ years of experience in SOC, fusion centre, or security operations leadership roles.
- Deep knowledge of SIEM platforms (Splunk, Microsoft Sentinel, or equivalent) and SOAR workflow design.
- Strong understanding of threat intelligence integration, detection engineering, and adversary TTP mapping.
- Experience leading analyst teams in a high-pressure, 24x7 or follow-the-sun operational model.
- Proven ability to communicate complex security situations to executive stakeholders and government clients.
- Familiarity with the APAC regional threat landscape, including nation-state actors and critical infrastructure risks.
- GCDA, GSOM, or equivalent SOC leadership certification.
Nice to Have
- Prior experience building or standing up a fusion centre capability from inception.
- Familiarity with the Cyber Kill Chain, MITRE D3FEND, and detection-as-code practices.
- Experience working with government or defence clients in the APAC region.
- Understanding of OT/ICS environments and cross-domain detection challenges.