GovTech is the lead agency driving Singapore’s Smart Nation initiatives and public sector digital transformation. As the Centre of Excellence for Infocomm Technology and Smart Systems (ICT & SS), GovTech develops the Singapore Government’s capabilities in Data Science & Artificial Intelligence, Application Development, Smart City Technology, Digital Infrastructure, and Cybersecurity.
At GovTech, we offer you a purposeful career to make lives better where we empower our people to master their craft through robust learning and development opportunities all year round.
Play a part in Singapore’s vision to build a Smart Nation and embark on your meaningful journey to build tech for public good. Join us to advance our mission and shape your future with us today!
Learn more about GovTech at tech.gov.sg.
Government Commercial Cloud (GCC) is a key platform within Singapore Government Technology Stacks that enables government agencies to build and operate digital services on commercial cloud. The GCC Engineering team develops platform automations, landing zones, and security tooling across AWS, Azure, and GCP — serving thousands of government systems and thousands of public officers.
Security at GCC is not a side function — it's core to the platform's value proposition. Government agencies trust GCC to be secure by default.
You are the single named owner of security outcomes across all engineering teams in GCC. You define how security works — the standards, processes, escalation paths, and technical approaches — and drive adoption through influence, not authority. You operate through a Security Champions network: persistent, named engineers in each product team who own security judgment locally, coordinated by you. Your accountability is whether GCC is actually secure — measured through process health, incident response quality, and security posture metrics you define.
This role is part of the organisation's domain leadership structure — you join alongside Engineering Managers as a peer, not as a report to any EM. The Security domain is being stood up fresh. The previous model (centralised security team gatekeeping all decisions) has been retired. You inherit a Champions network in early stages, documented runbooks, and interim coverage from a senior security advisor. Your job is to take it from "interim bridge" to "sustainable, scalable security function."
The domain scope will evolve. Today it centres on the areas listed above — but we expect the role to grow into adjacent areas (AI security, detection engineering) as the organisation's needs develop. Adaptability and willingness to define your own frontier matters more than deep expertise in every area on day one.
[What you will be working on]
Security Architecture & Posture
Own the organisation's security posture across all product teams and cloud environments
Architect security frameworks that integrate into engineering workflows without creating bottlenecks
Design and evolve threat modelling methodologies adapted to the organisation's multi-cloud, multi-tenant context
Define escalation paths, severity frameworks, and incident response playbooks
Own the relationship with GCSOC, shaping how external security signals translate into internal action
Drive security tooling strategy — selecting, configuring, and setting alert thresholds that distinguish signal from noise
Standards & Process Design
Define security standards, runbooks, and compliance approaches that teams can self-serve against
Design the Security Champions model: training curriculum, forum cadence, escalation criteria, and what "good" looks like for a champion
Replace gatekeeping with enablement — move from "security reviews everything" to "teams self-certify against clear criteria, you spot-check and consult"
Own security decision records: all posture choices documented, auditable, and transferable
Reform compliance processes (e.g. IMR8) to reduce ceremony while maintaining assurance
Cross-Org Influence
Drive security adoption across 5-6 engineering teams through the Champions network
Run a regular cross-org security forum: shared learning, emerging threats, pattern reviews
Consult on high-risk designs and architectural trade-offs when teams escalate
Handle genuine security incidents personally, with Champions as informed participants
Build security judgment across the engineering organisation — not by centralising decisions, but by raising the floor
Serve as the organisation's authoritative security voice on technical matters — advising on vendor evaluations, platform-level policy design, and cross-programme security decisions that require deep domain expertise beyond any single team's scope
Technical Depth
Maintain hands-on capability in at least two of: cloud security architecture, application security, supply chain security, detection engineering
Evaluate and prototype security tooling; make build-vs-buy recommendations grounded in the org's actual threat model
Contribute to or lead security incident post-mortems with root cause analysis that drives systemic improvement
Stay current on emerging threats and translate external signals into organisational action
[What we are looking for]
Must-Have
Deep security engineering expertise (architecture, not just operations) — you've designed security frameworks, not just followed them
Demonstrated ability to influence without authority across multiple engineering teams
Experience designing security processes that scale through enablement rather than gatekeeping
Strong enough as an engineer to review designs, read code, and earn credibility with senior SWEs
Clear, structured communication — you'll write strategies, runbooks, and decision records that outlive you
Comfort operating with ambiguity: this role is being stood up for the first time, and you'll shape what it becomes
Proficiency in scripting (Python, Bash) and working with APIs — you'll build and review automation, not just specify it
Solid understanding of identity, networking, logging, monitoring, and data security in cloud environments
Strong Signals
Experience with cloud security across multiple CSPs — ideally hands-on with native security services, not just console-level familiarity
Background in both offensive (threat modelling, VAPT, red team) and defensive (SIEM, detection engineering, incident response) security
Track record of building security champion or embedded security programs
Experience with CNAPP/CSPM platforms and vulnerability management tooling
Experience integrating security controls into CI/CD pipelines and DevSecOps workflows
Familiarity with compliance and threat frameworks and the judgment to know when compliance ≠ security
Experience working in government or highly regulated environments
Awareness of AI security risks and emerging governance frameworks
Technology Landscape
You'll encounter the following in this role. We don't expect mastery of all of these on day one — what matters is the ability to learn quickly and form sound judgment across unfamiliar tools.
| Area | Technologies |
|------|-------------|
| Cloud providers | AWS, Azure, GCP (multi-account/subscription/project at scale) |
| Security posture | Wiz, AWS Security Hub, Azure Defender, GCP Security Command Center |
| Vulnerability management | Nessus, Trivy, AWS Inspector, container scanning |
| SIEM & detection | Elastic SIEM, GuardDuty, Sentinel, CloudTrail/Activity Log |
| Identity & access | IAM (all CSPs), Entra ID, workload identity, RBAC/ABAC patterns |
| IaC & pipelines | Terraform, GitLab CI/CD, policy-as-code (OPA, Sentinel) |
| Secrets & supply chain | Vault, AWS Secrets Manager, SBOM tooling, dependency scanning |
| Compliance frameworks | IMR8, CIS Benchmarks, NIST CSF, ISO 27001, MITRE ATT&CK |
| Scripting & automation | Python, Bash, REST APIs |
| Emerging | AI/LLM security (OWASP LLM Top 10, NIST AI RMF), detection-as-code |
Preferred Certifications
Not required, but signal depth in relevant areas:
Cloud security: AWS Security Specialty, Azure Security Engineer Associate, GCP Professional Cloud Security Engineer
Security generalist: CISSP, CCSP, or relevant GIAC certifications
Offensive: OSCP, GPEN, or equivalent hands-on security testing credentials
Dealbreakers
Pure compliance/audit background with no engineering depth — this role requires technical credibility with senior engineers
Preference for centralised control ("everything goes through security") — the operating model is distributed enablement
Inability to document and codify decisions — if you leave, someone else must be able to pick up without an information gap
What we offer you:
GovTech is an equal opportunity employer committed to fostering an inclusive workplace that values diverse voices and perspectives, as we believe that diversity is the foundation to innovation.
Our employee benefits are based on a total rewards approach, offering a holistic and market-competitive suite of perks. These include leave benefits to meet your work-life needs and employee wellness programs.
We champion flexible work arrangements (subject to your job role) and trust that you will manage your own time to deliver your best, wherever you are, and whatever works best for you.
Learn more about life inside GovTech at go.gov.sg/GovTechCareers.
Stay connected with us on social media at go.gov.sg/ConnectWithGovTech