Step 1 · Compatibility
Senior/ Lead Cybersecurity Engineer, TradeNet
Government Technology Agency · onsite · Singapore
Is this role right for you?
Preview using a demo profile. Build yours
- • Has all 1 required skills
- • 7y experience meets the 4y minimum
- • Open to full-time work
- • Schedule works
You're compatible with this role — here's what it involves. ↓
Step 2 · The role
GovTech is the lead agency driving Singapore’s Smart Nation initiatives and public sector digital transformation. As the Centre of Excellence for Infocomm Technology and Smart Systems (ICT & SS), GovTech develops the Singapore Government’s capabilities in Data Science & Artificial Intelligence, Application Development, Smart City Technology, Digital Infrastructure, and Cybersecurity. At GovTech, we offer you a purposeful career to make lives better where we empower our people to master their craft through robust learning and development opportunities all year round. Play a part in Singapore’s vision to build a Smart Nation and embark on your meaningful journey to build tech for public good. Join us to advance our mission and shape your future with us today! Learn more about GovTech at tech.gov.sg. [What you will be working on] We are seeking a Cybersecurity Engineer to serve as the security SME for a critical national digital platform. This role sits at the intersection of engineering delivery and regulatory compliance. You will translate policy requirements (IM8 Reform, CSA CCOPv2) into implementable technical controls while working shoulder-to-shoulder with product and engineering teams in an agile delivery environment. Cloud & Infrastructure Security • Assess and validate security controls across IaaS/PaaS/SaaS environments, covering identity management, encryption, and network segmentation. • Govern security appliance policy and rule changes (WAF, DAM, Firewalls), including oversight of vendor operations and change management. Application Security • Triage application security findings against OWASP Top 10, reproduce and validate issues, and coordinate retesting with functional leads or delegates. • Ensure adherence to secure SDLC practices across the delivery lifecycle. Regulatory Compliance & Risk • Translate CSA Cybersecurity Act (CII CCOPv2) and WOG IM8 high-risk cloud requirements into actionable technical and process controls. • Log and assess GCSOC/GITSIR/agency advisories, determine impact, follow up with functional leads, and track to closure. • Manage Vulnerability Disclosure Programme findings end-to-end: triage, coordinate with functional leads, track remediation, and close. • Conduct security risk assessments and map technical controls to compliance requirements across relevant frameworks (ISO 27001, NIST, CIS benchmarks). • Support internal and external audits, including evidence gathering and coordination with auditors. Threat Modelling & Offensive/Defensive Operations • Conduct threat modelling with reference to the MITRE ATT&CK framework, scoped to the CII landscape. • Manage or support offensive and defensive operations, including VAPT, incident response, and incident management. • Participate in the design and solutioning of technical setups when new security requirements are introduced, using threat modelling outcomes to prioritize implementation. Stakeholder Engagement & Delivery • Liaise between CSA, Agency CISO stakeholders, and engineering teams — matching regulatory requirements with engineering approaches and design decisions. • Drive remediation through engineering teams, not just identify gaps. • Manage cross-functional security initiatives from requirements through deployment. • Leverage automation for compliance monitoring and evidence collection. • Establish and track KPIs for compliance posture and risk reduction. • Champion agile security practices within the delivery cadence. [What we are looking for] • Minimum 5 years of professional experience in cybersecurity engineering, with hands-on work in security operations, risk assessment, or compliance within cloud environments. • Working knowledge of Singapore-specific regulatory frameworks: WOG IM8 Reform and CSA CCOPv2 for Critical Information Infrastructure. • Hands-on experience with security technologies such as SIEM, CSPM, ASM, WAF, and vulnerability management tools. • Familiarity with cybersecurity frameworks and standards including OWASP, MITRE ATT&CK, ISO 27001, NIST, and CIS benchmarks. • Ability to communicate technical security concepts to policy and compliance stakeholders, and translate compliance requirements into engineering-actionable tasks. • Pragmatic decision-making: able to balance security requirements with delivery timelines and business needs. • Experience supporting audit cycles and producing compliance evidence. • Proficiency in at least one scripting language (e.g., Python, PowerShell, YARA) for automation and tooling. • Relevant certifications such as GCIH, GCFA, OSCP, CISSP, or AWS Security Specialty are advantageous. • Ability to conduct in-house VAPT is a strong plus. • Subject to the nature of your job role that might require you to be onsite during fixed hours. What we offer you: GovTech is an equal opportunity employer committed to fostering an inclusive workplace that values diverse voices and perspectives, as we believe that diversity is the foundation to innovation. Our employee benefits are based on a total rewards approach, offering a holistic and market-competitive suite of perks. These include leave benefits to meet your work-life needs and employee wellness programs. We champion flexible work arrangements (subject to your job role) and trust that you will manage your own time to deliver your best, wherever you are, and whatever works best for you. Learn more about life inside GovTech at go.gov.sg/GovTechCareers. Stay connected with us on social media at go.gov.sg/ConnectWithGovTech
Skills
Similar roles
- Product ManagerGovernment Technology AgencySingapore
- Deputy Director, StrategyGovernment Technology AgencySingapore
- Internship (AI Software Engineer – HR Solutions), Information Technology ClusterPublic Service DivisionSingapore
- Principal AI Engineer - DISMINDEFSingapore
