Jobs › Singapore › Senior Cybersecurity Governance Specialist
Senior Cybersecurity Governance Specialist
GovTech Singapore is hiring for the job of Senior Cybersecurity Governance Specialist, Singapore (On-site). This is a Governance job in the governance, risk, and compliance field. Review the full details below and apply directly with GovTech Singapore.
strong;ObjectId;ClassId;Properties;1;5;1;1;Calibri;Calibri;Calibri;Calibri;1;Calibri;22;gmail-wdcg;2;true;gmail-wdcg;99;true;18441;240;0 Normal the role /:true:true:0:0
GovTech is the lead agency driving Singapore’s Smart Nation initiatives and public sector digital transformation. As the Centre of Excellence for Infocomm;Technology and Smart Systems (ICT SS) GovTech develops the Singapore Government’s capabilities in Data Science Artificial Intelligence Application Development Smart City Technology Digital Infrastructure and Cybersecurity. /:true:true:0:0
At GovTech we offer you a purposeful career to make lives better where we empower our people to master their craft through robust learning and development opportunities all year round. /:true:true:0:0
Play a part in Singapore’s vision to build a Smart Nation and embark on your meaningful journey to build tech for public good. Join us to advance our mission and shape your future with us today! /:true:true:0:0
Learn more about GovTech at tech.gov.sg. /:true:true:0:0
strong you will be working /:true:true:0:0
The Cyber Security Group (CSG) is the cybersecurity arm of GovTech. CSG is committed to create a digital government that is safe and secure. CSG delivers technical and operational capabilities to counteract cyber threats provides thought leadership on transformative cybersecurity governance and policies and to strengthen the cybersecurity posture of government agencies in a manner that is sustainable pragmatic and effective. /:true:true:0
To enhance infocomm;security capabilities in GovTech and the Whole-of-Government (WOG) GovTech appoints Chief Information Security Officer (CISO) teams;at the various ministries to oversee infocomm;security management. /:true:true:0
Reporting to the Ministry CISO (MCISO) you will be the primary architect of the Ministry’s security governance and risk management framework. You will ensure that all agencies within the Ministry Family operate;under a unified effective and modern security standard. Your mission is to transform GRC from a compliance-heavy exercise into a strategic enabler. You will establish;the frameworks that allow the Ministry Family to adopt new technologies;with confidence moving away from a risk-averse posture toward a risk-informed one. You will ensure that risk management is deeply integrated into the lifecycle of every digital system from web applications to critical Operational Technology (OT) environments. /:true:true:0:0
:true:true:0
strong;ObjectId;ClassId;Properties;1;5;1;1;Calibri;Calibri;Calibri;Calibri;1;Calibri;22;gmail-wdcg;2;true;gmail-wdcg;99;true;18441;240;0 Normal Key Responsibilities /:true:true:0:0:0
Enterprise Risk Governance Management /
:1:720:360;Symbol;left;;multilevel Dynamic Risk Registers Establish;and oversee the Ministry-wide security risk register. You will ensure that registers are not static documents but living tools that accurately reflect the current threat landscape and project status across all agencies. /:true:true:0:0:0
:1:720:360;Symbol;left;;multilevel Senior Management Facilitation Lead and facilitate;high-level risk conversations with Senior Management and Agency CIOs. You must be able to translate complex technical risks into clear business impacts to drive informed resource allocation and prioritisation. /:true:true:0:0:0
:1:720:360;Symbol;left;;multilevel Risk Analysis Framework Develop a robust framework to guide agencies in performing consistent high-quality risk analysis. This framework should empower agencies to take calculated risks for innovation rather than defaulting to no due to risk aversion. /:true:true:0:0:0
Threat Risk Assessment (TRA) Standards /
:1:720:360;Symbol;left;;multilevel Unified TRA Framework Establish;and maintain Ministry-wide standards for conducting Threat Risk Assessments across diverse domains including Cloud (GCC) Web Applications and OT/ICS systems. /:true:true:0:0:0
:1:720:360;Symbol;left;;multilevel Crown Jewel Identification Develop SOPs to guide agency project teams in identifying Crown Jewels (Critical Information Assets) and mapping comprehensive threat vectors. /:true:true:0:0:0
:1:720:360;Symbol;left;;multilevel Standardisation of Controls Define common security configuration standards and ensure that controls are technically effective in mitigating identified;risks rather than just meeting baseline requirements. /:true:true:0:0:0
Zero Trust Architecture Governance /
:1:720:360;Symbol;left;;multilevel Zero Trust Roadmap Lead the establishment of a Ministry-wide Zero Trust Framework setting the standards for identity-based security micro-segmentation and never trust always verify architectures. /:true:true:0:0:0
:1:720:360;Symbol;left;;multilevel Architectural Advisory Provide expert GRC input during the design phase of high-impact systems to ensure security-by-design and alignment with Ministry standards. /:true:true:0:0:0
:1:720:360;Symbol;left;;multilevel Technology Application Evaluate and recommend security technologies that effectively mitigate specific risks ensuring that defensive layers remain;relevant against modern threats. /:true:true:0:0:0
Supply Chain Ecosystem Risk Management /
:1:720:360;Symbol;left;;multilevel Third-Party Risk Strategy Establish;the framework for managing risks across the software supply chain and IT vendors. /:true:true:0:0:0
:1:720:360;Symbol;left;;multilevel Dependency Vendor Risk Develop standards for assessing the cyber-resilience of third-party partners and managing risks associated with software dependencies (e.g. Open Source;libraries). /:true:true:0:0:0
Audit Excellence Systemic Improvement /
:1:720:360;Symbol;left;;multilevel Proactive Readiness Shift agencies from reactive audit preparation to a state of continuous compliance and readiness.
:1:720:360;Symbol;left;;multilevel Root Cause Rectification Oversee the closure of audit findings ensuring agencies implement substantive effective technical fixes rather than surface-level measures. /:true:true:0:0:0
:1:720:360;Symbol;left;;multilevel Systemic Weakness Identification Analyse audit trends across the Ministry Family to identify;and address systemic weaknesses before they can be exploited. /:true:true:0:0:0
Stakeholder Management Threat Intelligence /
:1:720:360;Symbol;left;;multilevel Education Advocacy Partner with Agency CIOs CISOs and Project Owners to inculcate a proactive risk management mindset. /:true:true:0:0:0
:1:720:360;Symbol;left;;multilevel Threat Tech Foresight Keep abreast of evolving Actor TTPs (Tactics Techniques and Procedures) and technology changes. Periodically review the relevancy of existing Ministry-wide defences against the latest threat s. /:true:true:0:0:0
:true:true:0
Qualifications Requirements /:true:true:0:0:0
Experience /:true:true:0:0:0
:1:720:360;Symbol;left;;multilevel Years of Experience / 10;to 12;years in Cybersecurity GRC Information Security Risk Management or Security Architecture. /:true:true:0:0:0
:1:720:360;Symbol;left;;multilevel Domain Breadth / Proven experience in managing risks across IT and Cloud environments exposure to OT (Operational Technology) systems is a significant advantage. /:true:true:0:0:0
:1:720:360;Symbol;left;;multilevel Regulatory Knowledge / Deep familiarity with Singapore Government security policies (e.g. Instruction Manual on IT Management) and international standards (e.g. NIST ISO 27001). /:true:true:0:0:0
Technical Skills /:true:true:0:0:0
:1:720:360;Symbol;left;;multilevel Risk Methodologies / Mastery of risk assessment methodologies (e.g. TVRA) and the ability to translate technical vulnerabilities into business risk. /:true:true:0:0:0
:1:720:360;Symbol;left;;multilevel Security Technologies / Strong technical understanding of various Zero Trust Architecture (ZTA) components;and cloud security technologies. Such as Firewalls EDR IAM SIEM CSPM CWPP CASB;and secrets management etc. /:true:true:0:0:0
:1:720:360;Symbol;left;;multilevel Threat Awareness / Ability to map technical controls to the MITRE ATT;CK framework to ensure defensive coverage. /:true:true:0:0:0
:1:720:360;Symbol;left;;multilevel Offensive Security;Proficiency;in manual and automated testing tools deep understanding of the MITRE ATT;CK framework and common TTPs.
:1:720:360;Symbol;left;;multilevel Certifications / Professional certifications such as / CISM (Certified Information Security Manager) CRISC (Certified in Risk and Information Systems Control) CISSP OSCP;or OSWE (Offensive Security Web Expert) / are highly preferred. /:true:false:0:0:0
Soft Skills /:true:true:0:0:0
:1:720:360;Symbol;left;;multilevel Strategic Influence / Ability to educate and persuade senior stakeholders (CIOs/Project Owners) on the importance of rigorous risk governance. /:true:true:0:0:0
:1:720:360;Symbol;left;;multilevel Critical Thinking / Ability to look past surface-level audit compliance to find and fix underlying systemic issues. /:true:true:0:0:0
:1:720:360;Symbol;left;;multilevel Lifelong Learner / A genuine passion for staying updated on the latest security technologies and evolving cyber threat landscapes. /:true:true:0:0:0
:1:720:360;Symbol;left;;multilevel Risk Articulation /;Exceptional ability to translate deep technical issues (e.g. zero-day vulnerabilities configuration drifts) into business risk for non-technical senior executives. /:false:false:0:0:0
:false:false:0:0:0
:false:false:0:0:0
Certifications this role asks for
Studying for one of these? Try the free CISM practice questions in our academy. No signup, no cost.
Location and market context
This job is based in Singapore on-site. Local candidates benefit from being close to GovTech Singapore's teams and regional hiring market. Confirm the exact in-office expectation and any relocation support with the employer.
About governance jobs
Governance jobs design the structures, policies, and oversight that keep complex programs accountable, coordinating across legal, risk, compliance, and technology. Jobs like this one are typically evaluated against frameworks such as governance frameworks, policy standards, and oversight and reporting practices.
How to position yourself for this governance job
Strong candidates emphasize policy and standard-setting, committee and stakeholder coordination, oversight reporting, and translating strategy into durable operating structures. In your resume and outreach, tie your experience to how GovTech Singapore would apply governance frameworks, policy standards, and oversight and reporting practices, and lead with concrete outcomes rather than duties.
Similar GRC jobs
- Senior Manager - Digital Governance Specialist · GovTech Singapore · Singapore
- Fraud Operations Manager (Mandarin-speaking) · Stripe · Singapore
- AML Strategy and Governance Senior Manager · FanDuel · Toronto, Ontario, Canada
- DORA Governance & TPRM Specialist · Capco · Italy - Milan
- Staff Identity Governance and Access Engineer · Okta · Bellevue, Washington
- Vendor Operations & Governance Specialist · Twilio · Remote
- Security Operations Governance & Modernization, AVP · Deutsche Bank · 2 Locations
- Senior Manager, Loan Salability & First-Line Model Governance · Upstart · Remote
More jobs at GovTech Singapore
- Lead / Senior Product Manager, AI Safety & Governance, PlatformAI · GovTech Singapore · Singapore
- Senior Manager/Assistant Director, Responsible AI & Governance AI Strategy Office (AISO) · GovTech Singapore · Singapore
- Assistant Director, ICT & SS Auditor (MOE) · GovTech Singapore · Singapore
- Deputy Director, ICT & SS Risk Specialist · GovTech Singapore · Singapore
- Head of Governance and Risk, Singpass · GovTech Singapore · Singapore
- Senior Manager, ICT & SS Auditor (MOE) · GovTech Singapore · Singapore
More GRC jobs in Singapore
- Senior Risk Analyst · AlphaSense · India · Remote
- Senior Compliance Specialist · Singlestore · India
- Governance, Risk, and Compliance Expert, GTM, Pre-Sales · Vanta · . · Remote
- Senior Risk & Governance Engineer · AlphaSense · India
- Compliance Engineering Lead · Socket · United States
- Third-Party Risk Management Analyst · Samsara · Remote
Hiring for Governance?
Reach candidates who are already searching for this role, not a general audience. Your posting appears on this page, in the job alerts, and across the GRC Careers network.
Post a job Pricing from $99 · About GRC Careers · Hiring toolkit
Want to be next in a job like this?
Jobs like Senior Cybersecurity Governance Specialist in Singapore open regularly. Be first to know, privately. No current employer ever sees you looking.
Employer, or see something wrong with this posting? Report this posting and we will review it promptly.