DY

Cybersecurity · SecOps · GRC

Darren Yee

CISSP and CEH certified security professional with 10+ years leading security operations, incident response and compliance for critical infrastructure.

Singapore · CISSP (2024) · CEH (2018) · 10+ years in security

01 · About

A decade defending critical systems

I'm a security professional based in Singapore with more than a decade across security operations, governance, risk and compliance, network security, and infrastructure design. Today I'm the Regional CSIRT Lead at Murata Electronics, running security operations and incident response for ASEAN business units.

My career started in Singapore's Digital Intelligence Service, building and defending air-gapped cyber operations infrastructure. Since then I've led VAPT programmes, managed multi-vendor 5G security platforms under IMDA mandates, and automated the tedious parts of security reporting with code.

I like the problems that sit between the technical and the regulatory — where a firewall rule and an audit finding are the same conversation.

02 · Experience

Where I've worked

  1. Senior IT Security Operation Engineer CSIRT Lead

    Mar 2025 – Present

    Murata Electronics Singapore Pte Ltd · Singapore

    • Regional CSIRT Lead for security operations, SOC escalations, and end-to-end incident response across regional IT environments and ASEAN business units.
    • Conduct platform and application vulnerability assessments with CCoE and PSIRT teams, driving Zero Trust remediation plans.
    • Evaluate and lead Proof-of-Concept deployments for emerging security solutions across IT/OT environments.
    • Align regional infrastructure operations with the CIS Critical Security Controls framework to strengthen defense posture.
    • Partner with external vendors and internal departments to operate the information security tooling estate.
    • Report incident metrics, threat vectors and operational risk to Regional IT leadership and the Global Security team, and coordinate cross-border countermeasures with overseas business units.
  2. Security Engineer GRC & Platform Security

    Nov 2023 – Mar 2025

    Antina Pte Ltd · Singapore

    • Promoted to Senior Security Engineer in January 2025, in the final two months of tenure.
    • Managed security operations for the 3.5 GHz C-Band RAN platform, ensuring strict compliance with IMDA 5G security mandates.
    • Oversaw multi-party governance with JV partners (StarHub, M1) and vendors (Nokia, AsiaPac) on threat mitigation and platform upgrades.
    • Led third-party VAPT projects and coordinated regulatory audits (TCS, Mobile TIRA).
    • Administered IAM, SIEM logging (QRadar), EDR, and asset-inventory scanning for the 5G security platform.
    • Authored cross-departmental governance procedures, including a software whitelisting workflow requiring joint operational and security validation.
    • Ran security and workplace-safety awareness workshops for regulatory and WSH compliance.
  3. Digital Intelligence Service

    Jul 2012 – Aug 2023

    Singapore Armed Forces · Singapore

    • Joined in July 2012; progressed from intelligence analyst to leading a 4-person cyber operations team.
    • Architected air-gapped infrastructure with pfSense, Wazuh and Snort; managed on-premise VMware environments.
    • Delivered an Integrated Intelligence System (PHP/MySQL + QGIS/Tableau) that cut report processing time by 90%.
    • Strengthened NIST-aligned compliance through annual and ad-hoc security reviews.

    IT Infrastructure Engineer & Security Lead 2020 – Aug 2023 · concurrent with Cyber Ops Team Lead

    • Led daily IT and security operations for a 4-person team, including server hardening and quarterly vulnerability assessments.
    • Sourced and implemented open-source and free security solutions: pfSense, Snort, Wazuh and a hardware air gap, plus a commercially licensed Nessus for vulnerability scanning.
    • Managed on-premise VMware environments and implemented IBM QRadar with the vendor.

    Cyber Ops Team Lead 2017 – 2023

    • Directed a 4-person team on Cyber Ops Proof-of-Concept initiatives.
    • Worked with DSTA software engineers to build a network-analysis information system from multi-source collected data.

    Ops Tech Analyst 2016 – 2017

    • Served as intelligence analyst on a Cyber Ops Proof-of-Concept project.
    • Delivered cyber and open-source intelligence training, working daily with OSINT tooling (Shodan, Censys, VirusTotal, ZoomEye, PassiveTotal).

    Junior Ops Tech Analyst 2014 – 2016

    • Recommended and designed infrastructure solutions for Proof-of-Concept projects.
    • Built reporting automation that summarized analyst reports, removing hours of manual tabulation.

    Secondary appointment: UCX Representative (Company Sergeant Major equivalent) — regimental command and control support, workplace and environmental safety reviews, and Joint Intelligence Command safety documentation.

Career & education timeline

ACHIEVEMENTS WORK STUDY CREDENTIALS 2010 2012 2014 2016 2018 2020 2022 2024 2026 today SAF Digital Intelligence Service · Jul 2012 – Aug 2023 — Junior Ops Tech Analyst (2014–2016) → Ops Tech Analyst (2016–2017) → Cyber Ops Team Lead (2017–2023), concurrent with IT Infrastructure Engineer & Security Lead (2020–2023) SAF Digital Intelligence Antina Pte Ltd · Nov 2023 – Mar 2025 — Security Engineer (Nov 2023 – Jan 2025), promoted to Senior Security Engineer (Jan – Mar 2025) Antina Murata Electronics Singapore · Mar 2025 – Present — Senior IT Security Operation Engineer (CSIRT Lead) Murata Junior Analyst Analyst Cyber Ops Lead IT Infra & Security Lead Security Engr ↑ Senior Engr Senior IT Security Operation Engineer Republic Polytechnic · Apr 2009 – May 2012 (approximate) — Diploma in Business Information Systems Republic Polytechnic Murdoch University · Trimester 1 2020 – Trimester 2 2023 — BSc Cyber Security & Forensics Murdoch University Diploma in Business Information Systems — Republic Polytechnic · completed May 2012 Graduated May 2012 BSc Cyber Security & Forensics — Murdoch University · completed Sep 2023 Graduated Sep 2023 CEH — Certified Ethical Hacker (EC-Council), Oct 2018 CEH certified CISSP — Certified Information Systems Security Professional (ISC2), May 2024 CISSP certified Air-gapped cyber ops infra Architected air-gapped cyber ops infrastructure with pfSense, Wazuh, Snort and a hardware air gap (2020–2023) IIS built — 90% faster Integrated Intelligence System — PHP/MySQL + QGIS/Tableau, cut reporting time by 90% (2021) VAPT + regulatory audits Led third-party VAPT and regulatory audits: TCS, Mobile TIRA Zero Trust assessments Platform and application vulnerability assessments with CCoE and PSIRT teams IT/OT PoC evaluations Leads PoC evaluation of emerging security solutions across IT/OT environments

Swipe the chart to see the full timeline →

Work history merged into a single bar; colours distinguish organisations. Dots mark projects and milestones; diamonds mark graduations and rings mark professional certifications. Hover any mark for detail.

Chart legend

  • Work bar — colour identifies the organisation; hover a segment to see the roles held.
  • Role divider — a thin line marks a role change within an organisation.
  • Dots — delivered projects and milestones, positioned by date.
  • Study bars — periods of study.
  • Diamonds — academic graduations.
  • Rings — professional certifications.
  • Dashed line — today.

Hover any mark in the chart for exact dates and details.

03 · Skills

Skills & knowledge

Skills

SecOps & IR CSIRT lead · 10+ yrs security ops VAPT Leads VAPT programmes System Arch Air-gap design Network Firewalls · SIEM · endpoint Cloud VMware · Entra ID Automation In-house tooling Leadership Teams of 4 · governance 1 2 3 4 5 Security Operations & Incident Response: 5 of 5 Vulnerability Management & Pen Testing: 4 of 5 System Architecture: 4 of 5 Network & Platform Security: 4 of 5 Cloud & Virtualization: 3 of 5 Automation & Tooling: 4 of 5 Leadership & Stakeholder Management: 4 of 5
  • 5

    Security Operations & Incident Response

  • 4

    Vulnerability Management & Pen Testing

  • 4

    System Architecture

  • 4

    Network & Platform Security

  • 3

    Cloud & Virtualization

  • 4

    Automation & Tooling

  • 4

    Leadership & Stakeholder Management

Knowledge

Security Arch Defence-in-depth · CISSP GRC NIST · CIS CSC · IMDA Threat Threat hunting IR & Forensics BSc Forensics · CSIRT Cloud Entra ID Data Python · Tableau Networking Protocols · platforms 1 2 3 4 5 Security Architecture: 4 of 5 Governance, Risk & Compliance: 4 of 5 Threat Landscape & Attack Techniques: 4 of 5 Incident Response & Digital Forensics: 4 of 5 Cloud & Identity: 3 of 5 Data, Development & Analytics: 3 of 5 Networking & Systems: 4 of 5
  • 4

    Security Architecture

  • 4

    Governance, Risk & Compliance

  • 4

    Threat Landscape & Attack Techniques

  • 4

    Incident Response & Digital Forensics

  • 3

    Cloud & Identity

  • 3

    Data, Development & Analytics

  • 4

    Networking & Systems

Self-rated 0–5, anchored to ownership: 3 = independent delivery · 4 = lead/own · 5 = architect-level depth. Grounded in the roles and outcomes above.

Technical toolkit

Cloud & Virtualization

Entra ID · VMware ESXi/vCenter/vSAN · Windows Server

Development & Analytics

Java · JavaScript · MySQL · PHP · Python · QGIS · Tableau

Frameworks & Compliance

CIS CSC · GRC Policy Writing · IMDA 5G Security · NIST · Threat Modeling

Security & Network Infrastructure

Check Point · Cisco Switching · F5 · Fortinet · Palo Alto Panorama · pfSense · Snort · Wazuh

Security Operations & Incident Response

Air-Gapped Operations · CSIRT Leadership · Incident Response · SOC Management · Threat Hunting

SIEM, IAM & Endpoint

IBM QRadar · McAfee ePO · Nokia IAM/SOAR · RSA · Splunk · Trend Micro · YubiKey

Vulnerability & Pen Testing

Metasploit · Nessus · Nmap · Static & Dynamic Scanning · Wireshark

04 · Projects

Selected projects

A few things I've built and run — most of it in environments where uptime and compliance both mattered.

Software Development with AI

Developing software with AI-assisted workflows. Mar 2025 – Present

Integrated Intelligence System

A PHP/MySQL system that automated raw-data intake, cleaning and analysis for intelligence reporting; QGIS and Tableau turned the output into decision metrics. Cut manual report-processing time by 90%. 2021 · PHP · MySQL · QGIS · Tableau

Air-Gapped Cyber Ops Infrastructure

Designed and operated an air-gapped environment with pfSense, Wazuh, Snort and a hardware air gap to defend the cyber operations estate. 2020 – 2023 · pfSense · Wazuh · Snort · Air gap

Homelab

Hands-on practice lab: pfSense and Fortinet firewalls, Cisco switching, an ESXi cluster, and a Plex stack. Until 2024 · ESXi · Cisco · Fortinet · Plex

05 · Credentials

Certifications & education

Professional certifications

CISSP

Certified Information Systems Security Professional · ISC2 · 2024

CEH

Certified Ethical Hacker · EC-Council · 2018

Tertiary education

Bachelor of Science Cyber Security and Forensics

Murdoch University · 2023

Diploma, Business Information Systems

Republic Polytechnic · 2012

06 · Contact

Let's talk

I'm open to conversations about security operations, incident response and GRC — or to exchange notes on building software with AI. The fastest way to reach me is email.

wandererdarren@gmail.com
↑