The Government Technology Agency (GovTech) is the lead agency driving Singapore’s Smart Nation initiatives and public sector digital transformation. As the Centre of Excellence for Infocomm Technology and Smart Systems (ICT & SS), GovTech develops the Singapore Government’s capabilities in Data Science & Artificial Intelligence, Application Development, Smart City Technology, Digital Infrastructure, and Cybersecurity.
At GovTech, we offer you a purposeful career to make lives better. We empower our people to master their craft through continuous and robust learning and development opportunities all year round. Our GovTechies embody our Agile, Bold and Collaborative values to deliver impactful solutions.
GovTech aims to transform the delivery of Government digital services by taking an "outside-in" view, putting citizens and businesses at the heart of everything we do.
Play a part in Singapore’s vision to build a Smart Nation and embark on your meaningful journey to build tech for public good. Join us to advance our mission and shape your future with us today!
Learn more about GovTech at tech.gov.sg.
About the division:
At Singpass, we aim to provide reliable digital identity for Singapore that streamlines transactions, enables businesses, and protects against fraud. This involves improving the online transaction experience with Singpass and Corppass while keeping it secure. It includes everything from building better frontend applications for residents and keeping an eye on fraudulent transactions to improving internal operations and working with our partners.
What you will be working on:
As an Lead Cybersecurity Engineer , your job will be to:
Determine what assurance gaps exist across our product portfolio and decide what assessment approaches best surface real risk and drive meaningful remediation
Shape the strategic direction of our cybersecurity assurance programme and prioritise activities based on the threat landscape, product criticality, and organisational risk appetite
Work with people from engineering, product, policy, and operations to ensure security assurance is embedded as a rigorous and trusted function across our digital services
Measure and track the effectiveness of our assurance activities, from assessment coverage and finding severity trends to remediation rates and compliance posture
Wear multiple hats to keep our systems honest. You may be leading a penetration test, conducting a secure architecture review, facilitating a threat modelling exercise, or advising on a governance/risk/compliance matter
Build a culture of accountability and continuous improvement with the people you work with
What we are looking for
We are looking for someone who can independently lead a credible and effective assurance function that gives the organisation confidence in the security of its products and practices, and who can operate effectively across a complex, multi-product environment.
In this role, you will:
Own and drive assurance impact across the digital identity space
Take end-to-end ownership of the cybersecurity assurance function across our product portfolio, shaping direction in alignment with Singpass' broader security strategy. Translate risk priorities, regulatory requirements, and product roadmaps into a coherent assurance programme that delivers clear, actionable findings and measurable improvements in security posture.
Lead rigorous security testing across a complex, multi-product environment
Own the end-to-end approach to various security testing engagements across the division. Bring deep hands-on expertise to bear in planning, scoping, executing, and reviewing engagements — ensuring findings are technically sound, well-evidenced, and tied to real-world risk.
Drive secure architecture reviews and threat modelling
Lead structured reviews of system and application architectures to identify security weaknesses before they are built in. Facilitate threat modelling exercises with engineering and product teams, ensuring that security risks are surfaced early and addressed systematically across the product lifecycle.
Make high-quality, risk-informed decisions
Define assurance metrics, evaluate trade-offs, and prioritise activities effectively using vulnerability data, architecture assessments, and strategic context. Focus efforts on the assessments and findings that drive the most meaningful risk reduction across a broad and evolving attack surface.
Bring structure and credibility to cyber GRC
Apply working knowledge of cybersecurity governance, risk, and compliance to ensure our assurance activities align with relevant frameworks, regulations, and internal policies. Help the organisation maintain a well-documented, defensible security posture and support audit and compliance processes with rigour and clarity.
Partner deeply with engineering and product teams
Work closely with software engineers and product managers with sufficient technical depth to communicate findings clearly, influence remediation priorities, and ensure that assurance outcomes translate into tangible security improvements rather than reports that sit on a shelf.
Demonstrate strong ownership and bias for action
Operate with a high degree of autonomy. Identify gaps in assurance coverage, drive improvements proactively, and take initiative on work that goes beyond defined scope.
Influence and align stakeholders effectively
Communicate assurance findings and programme strategy clearly to align cross-functional teams and influence stakeholders, including senior leadership. Translate technical vulnerabilities and risk assessments into business impact and actionable decisions.
Requirements:
10+ years of experience in cybersecurity, with a strong background in VAPT, secure architecture reviews, and threat modelling across software products
Demonstrated experience leading cybersecurity assurance functions or teams and driving assurance programmes end-to-end
Proven hands-on expertise in conducting and overseeing penetration testing and vulnerability assessments across complex, multi-product or multi-service environments
Experience leading secure architecture reviews and threat modelling exercises, with a track record of surfacing meaningful risk early in the product lifecycle
Possess the OSCP certification, or other equivalent or advanced certifications
Working knowledge of cybersecurity GRC, including familiarity with relevant frameworks such as IM8, NIST CSF, or equivalent
Experience working closely with software engineering and product teams to translate assurance findings into remediation outcomes
Strong ability to influence stakeholders and collaborate across engineering, product, and policy teams, including at the senior leadership level
Track record of operating with high autonomy in fast-moving environments, including work that goes beyond defined scope
What we offer you:
GovTech is an equal opportunity employer committed to fostering an inclusive workplace that values diverse voices and perspectives, as we believe that diversity is the foundation to innovation.
Our employee benefits are based on a total rewards approach, offering a holistic and market-competitive suite of perks. These include leave benefits to meet your work-life needs and employee wellness programs.
We champion flexible work arrangements (subject to your job role) and trust that you will manage your own time to deliver your best, wherever you are, and whatever works best for you.
Learn more about life inside GovTech at go.gov.sg/GovTechCareers.
Stay connected with us on social media at go.gov.sg/ConnectWithGovTech