Cybersecurity · SecOps · GRC
Darren Yee
CISSP and CEH certified security professional with 10+ years leading security operations, incident response and compliance for critical infrastructure.
Singapore · CISSP (2024) · CEH (2018) · 10+ years in security
01 · About
A decade defending critical systems
I'm a security professional based in Singapore with more than a decade across security operations, governance, risk and compliance, network security, and infrastructure design. Today I'm the Regional CSIRT Lead at Murata Electronics, running security operations and incident response for ASEAN business units.
My career started in Singapore's Digital Intelligence Service, building and defending air-gapped cyber operations infrastructure. Since then I've led VAPT programmes, managed multi-vendor 5G security platforms under IMDA mandates, and automated the tedious parts of security reporting with code.
I like the problems that sit between the technical and the regulatory — where a firewall rule and an audit finding are the same conversation.
02 · Experience
Where I've worked
-
Senior IT Security Operation Engineer CSIRT Lead
Mar 2025 – Present
- Regional CSIRT Lead for security operations, SOC escalations, and end-to-end incident response across regional IT environments and ASEAN business units.
- Conduct platform and application vulnerability assessments with CCoE and PSIRT teams, driving Zero Trust remediation plans.
- Evaluate and lead Proof-of-Concept deployments for emerging security solutions across IT/OT environments.
- Align regional infrastructure operations with the CIS Critical Security Controls framework to strengthen defense posture.
- Partner with external vendors and internal departments to operate the information security tooling estate.
- Report incident metrics, threat vectors and operational risk to Regional IT leadership and the Global Security team, and coordinate cross-border countermeasures with overseas business units.
-
Security Engineer GRC & Platform Security
Nov 2023 – Mar 2025
- Promoted to Senior Security Engineer in January 2025, in the final two months of tenure.
- Managed security operations for the 3.5 GHz C-Band RAN platform, ensuring strict compliance with IMDA 5G security mandates.
- Oversaw multi-party governance with JV partners (StarHub, M1) and vendors (Nokia, AsiaPac) on threat mitigation and platform upgrades.
- Led third-party VAPT projects and coordinated regulatory audits (TCS, Mobile TIRA).
- Administered IAM, SIEM logging (QRadar), EDR, and asset-inventory scanning for the 5G security platform.
- Authored cross-departmental governance procedures, including a software whitelisting workflow requiring joint operational and security validation.
- Ran security and workplace-safety awareness workshops for regulatory and WSH compliance.
-
Digital Intelligence Service
Jul 2012 – Aug 2023
- Joined in July 2012; progressed from intelligence analyst to leading a 4-person cyber operations team.
- Architected air-gapped infrastructure with pfSense, Wazuh and Snort; managed on-premise VMware environments.
- Delivered an Integrated Intelligence System (PHP/MySQL + QGIS/Tableau) that cut report processing time by 90%.
- Strengthened NIST-aligned compliance through annual and ad-hoc security reviews.
IT Infrastructure Engineer & Security Lead 2020 – Aug 2023 · concurrent with Cyber Ops Team Lead
- Led daily IT and security operations for a 4-person team, including server hardening and quarterly vulnerability assessments.
- Sourced and implemented open-source and free security solutions: pfSense, Snort, Wazuh and a hardware air gap, plus a commercially licensed Nessus for vulnerability scanning.
- Managed on-premise VMware environments and implemented IBM QRadar with the vendor.
Cyber Ops Team Lead 2017 – 2023
- Directed a 4-person team on Cyber Ops Proof-of-Concept initiatives.
- Worked with DSTA software engineers to build a network-analysis information system from multi-source collected data.
Ops Tech Analyst 2016 – 2017
- Served as intelligence analyst on a Cyber Ops Proof-of-Concept project.
- Delivered cyber and open-source intelligence training, working daily with OSINT tooling (Shodan, Censys, VirusTotal, ZoomEye, PassiveTotal).
Junior Ops Tech Analyst 2014 – 2016
- Recommended and designed infrastructure solutions for Proof-of-Concept projects.
- Built reporting automation that summarized analyst reports, removing hours of manual tabulation.
Secondary appointment: UCX Representative (Company Sergeant Major equivalent) — regimental command and control support, workplace and environmental safety reviews, and Joint Intelligence Command safety documentation.
Career & education timeline
Swipe the chart to see the full timeline →
Work history merged into a single bar; colours distinguish organisations. Dots mark projects and milestones; diamonds mark graduations and rings mark professional certifications. Hover any mark for detail.
03 · Skills
Skills & knowledge
Skills
- 5
Security Operations & Incident Response
- 4
Vulnerability Management & Pen Testing
- 4
System Architecture
- 4
Network & Platform Security
- 3
Cloud & Virtualization
- 4
Automation & Tooling
- 4
Leadership & Stakeholder Management
Knowledge
- 4
Security Architecture
- 4
Governance, Risk & Compliance
- 4
Threat Landscape & Attack Techniques
- 4
Incident Response & Digital Forensics
- 3
Cloud & Identity
- 3
Data, Development & Analytics
- 4
Networking & Systems
Self-rated 0–5, anchored to ownership: 3 = independent delivery · 4 = lead/own · 5 = architect-level depth. Grounded in the roles and outcomes above.
Technical toolkit
Cloud & Virtualization
Entra ID · VMware ESXi/vCenter/vSAN · Windows Server
Development & Analytics
Java · JavaScript · MySQL · PHP · Python · QGIS · Tableau
Frameworks & Compliance
CIS CSC · GRC Policy Writing · IMDA 5G Security · NIST · Threat Modeling
Security & Network Infrastructure
Check Point · Cisco Switching · F5 · Fortinet · Palo Alto Panorama · pfSense · Snort · Wazuh
Security Operations & Incident Response
Air-Gapped Operations · CSIRT Leadership · Incident Response · SOC Management · Threat Hunting
SIEM, IAM & Endpoint
IBM QRadar · McAfee ePO · Nokia IAM/SOAR · RSA · Splunk · Trend Micro · YubiKey
Vulnerability & Pen Testing
Metasploit · Nessus · Nmap · Static & Dynamic Scanning · Wireshark
04 · Projects
Selected projects
A few things I've built and run — most of it in environments where uptime and compliance both mattered.
Software Development with AI
Developing software with AI-assisted workflows.
Integrated Intelligence System
A PHP/MySQL system that automated raw-data intake, cleaning and analysis for intelligence reporting; QGIS and Tableau turned the output into decision metrics. Cut manual report-processing time by 90%.
Air-Gapped Cyber Ops Infrastructure
Designed and operated an air-gapped environment with pfSense, Wazuh, Snort and a hardware air gap to defend the cyber operations estate.
Homelab
Hands-on practice lab: pfSense and Fortinet firewalls, Cisco switching, an ESXi cluster, and a Plex stack.
05 · Credentials
Certifications & education
Professional certifications
CISSP
Certified Information Systems Security Professional · ISC2 · 2024
CEH
Certified Ethical Hacker · EC-Council · 2018
Tertiary education
Bachelor of Science Cyber Security and Forensics
Murdoch University · 2023
Diploma, Business Information Systems
Republic Polytechnic · 2012
06 · Contact
Let's talk
I'm open to conversations about security operations, incident response and GRC — or to exchange notes on building software with AI. The fastest way to reach me is email.
wandererdarren@gmail.com