Step 1 · Compatibility
Senior Assistant Director (GCS-Dev/Government/Healthcare), CSPC
Cyber Security Agency of Singapore · onsite · closes 9/1/2026
Is this role right for you?
Preview using a demo profile. Build yours
- • No specific skills required
- • 7y of the 15y experience asked for
- • Job is contract, outside your preferences
- • Schedule works
You're compatible with this role — here's what it involves. ↓
Step 2 · The role
The successful candidate will be assigned to work in one of the various pillars in the division such as “Government Central Systems Development (GCS-Dev)”, “Government” and “Healthcare”. Lead a team of assistant directors, senior consultants, consultants and system engineers to provide cybersecurity consultancy through evaluating the risk assessment, security design review and plan and review security testing of GCS-Dev / Government/ Healthcare so as to ensure that the Systems are well protected while System owner accepts justifiable risk levels. Responsibilities Perform the risk assessment for GCS-Dev/ Government/ Healthcare to ensure it is well protected and justify the risks to the System owner for risk acceptance • Collaborate with system owners and project team to understand the business and system requirements so that you can analyse and identify the cyber and physical threats and formulate the relevant project-specific scenarios and potential risks. • Propose people, process and technology (PPT) cybersecurity mitigation controls on the completed TRA Template and project-specific scenarios. • Justify the residual risks level for acceptance and approval by the designated approving authority. Review the security design of GCS-Dev/ Government/ Healthcare ICT systems to identify areas of weaknesses and recommend security solution or controls to mitigate against highlighted threats. • Identify, assess and review cybersecurity solutions to secure ICT networks and systems. • Collaborate with system owners and project team to review and provide advice on the final proposed security design and mitigation controls. • Collaborate with system owners and project team to identify additional risks due to deviations in the final proposed security design and propose mitigation controls Review security testing scopes and plans that validate and verify the security design of the GCS (Dev) / Government/ Healthcare ICT Systems. • Review vendor’s system security testing proposals and Penetration Test (PT) plans, and if needed, insert or counter propose test plans and test cases to make sure the security testing is comprehensive. • Review and provide advice to system owners and project team on the conduct of system security testing and PT. • Serves as controller to verify the execution of the system security testing and PT. • Assess and provide advice, identify risks and propose remediation measures on the findings and recommendations from the system security testing and PT reports Optimise cybersecurity consultancy practices for effectiveness and efficiency of GCS-Dev/ Government/ Healthcare systems • Develop security reference architectures and threat reference models to optimise consultancy effectiveness and efficiencies. • Work with team members to develop, operate and publish the security reference architectures and threat reference models. • Enforce approved security reference architecture and threat reference models during cybersecurity consultancy. • Analyse lessons learned from consultancy works and incorporate areas of improvement to enhance Consultancy Models, security reference architecture and threat reference models Manage Team Capability Development • Managed Team esprit de corps, professional and personal developments • Develop training plans for the team based on competency framework i.e. RTEC (Raise + Train + Evaluate = Capability) Framework. • Identify suitable training programmes/events/seminars for each team role to associate the required capability in dealing with ever-changing cybersecurity threats landscape. • Monitor training budget allocated and provide updates to management when required. • Establish processes for Knowledge Management for purpose of cybersecurity consultancy knowledge sharing and retentions Requirements • Bachelor Degree in Information Communication Technology-related discipline (Cybersecurity, Information Security, Information Technology, Computer Science, Management Information Systems), Science or Engineering etc. • Professional qualifications such as CISSP, SANS, CISA, CRISC or equivalent • At least 15 to 20 years relevant working experience and more than 10 years of supervisory experience to manage, work and collaborate with various parties including stakeholders, system owners, teammates and contractors • Good understanding and interest in Cybersecurity • Technically hands-on and curious about inner workings of technology • Strong analytical and conceptualisation skills • Good communications and interpersonal relationship skills, stakeholder management • Driven and capable to work independently. Resourceful, responsible, motivated and able to work independently as well as in a team. If you share our passion to make a difference in the cyber security landscape, take up the challenge and apply now. All applicants will be notified of whether they are shortlisted or not within four weeks of the closing date of this job posting. For any issues with the application, you may drop your resume with us at [email protected].
Similar roles
- Product ManagerGovernment Technology AgencySingapore
- Deputy Director, StrategyGovernment Technology AgencySingapore
- Internship (AI Software Engineer – HR Solutions), Information Technology ClusterPublic Service DivisionSingapore
- Principal AI Engineer - DISMINDEFSingapore
