A1 - Lead Software Engineer (Cybersecurity)

FPT Asia Pacific

Singapore

On-site

SGD 150,000 - 230,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

FPT Asia Pacific is seeking a senior cybersecurity architect to own and evolve the security architecture for Singapore's TradeNet CII. You will work hands-on with engineering teams to implement controls and improve secure coding practices, while maintaining robust threat models and ensuring high availability and disaster recovery.

The role requires deep experience in regulated, critical platforms, strong scripting abilities (Python/TypeScript), and familiarity with CSA CCoP v2 and WOG IM8

Qualifications

  • 10+ years of cybersecurity experience in software engineering, security engineering, or security architecture.
  • Hands-on designer of secure systems, capable of reviewing/writing code and coaching teams in secure development.
  • Experience designing security architecture for regulated, critical, large-scale platforms.
  • Knowledge of CSA CCoP v2 and WOG IM8 frameworks.

Responsibilities

  • Own and evolve security architecture for the TradeNet Critical Information Infrastructure (CII).
  • Embed secure-by-design controls across architecture and development lifecycles.
  • Collaborate with engineering teams to implement security controls and improve secure coding practices.
  • Maintain threat models using frameworks like MITRE ATT&CK (supply-chain, APTs, nation-state).
  • Design for high availability, disaster recovery, and containment to ensure national trade continuity.

Skills

Cybersecurity architecture
Hands-on security
Threat modelling
MITRE ATT&CK
NIST / ISO / CIS
Scripting (Python)
Scripting (TypeScript)
Kotlin/JVM
DevSecOps / CI-CD security
Security automation

Tools

Python
TypeScript

Job description

Responsibilities
  • Own and evolve the security architecture for the TradeNet Critical Information Infrastructure (CII), covering trust boundaries, identity, segmentation, encryption, key management, Zero Trust principles, and blast-radius containment.
  • Embed secure-by-design and resilient-by-design controls throughout architecture, solution design, development, and implementation.
  • Work hands-on with engineering teams to implement security controls and improve secure coding practices.
  • Maintain threat models using frameworks such as MITRE ATT&CK, covering supply-chain, advanced persistent, and nation-state threats.
  • Design for high availability, recoverability, graceful degradation, disaster recovery, and containment to maintain national trade continuity during cyber incidents.
  • Identify and address dependency, concentration, third-party, and supply-chain risks across the TradeNet ecosystem.
  • Partner with the Singapore Customs ACISO to design the CII security boundary and multi-layered defensive architecture.
  • Translate CSA CCoP v2 and WOG IM8 requirements into practical architecture and engineering controls.
  • Determine which security controls can be inherited from the GovTech security technology stack and which must be built and owned by the TradeNet product team.
  • Maintain clear documentation of security control ownership and the shared-responsibility model.
  • Implement security controls as code, including policy-as-code, CI/CD security guardrails, automated security checks, and continuous control monitoring.
  • Champion Secure SDLC and DevSecOps practices across engineering teams.
  • Evaluate and recommend appropriate cybersecurity tools, technologies, and security architecture patterns.
  • Participate in cybersecurity resilience exercises and incorporate findings into platform architecture and engineering improvements.
  • Provide technical guidance for incident response, vulnerability assessments, and penetration testing where required.
  • Mentor and coach engineers on secure coding, security architecture, threat modelling, and cybersecurity best practices.
Requirements
  • 10+ years of cybersecurity experience, with strong hands-on experience in software engineering, security engineering, or security architecture.
  • Must be technically hands-on and capable of designing secure systems, reviewing or writing code, and coaching engineering teams on secure development.
  • Demonstrated experience designing and implementing security architecture for regulated, critical, large-scale, or enterprise platforms.
  • Working knowledge of Singapore cybersecurity regulatory frameworks, particularly CSA CCoP v2 and WOG IM8
  • Familiarity with security frameworks including MITRE ATT&CK, NIST, ISO 27001, and CIS Benchmarks.
  • Strong understanding of system boundaries, dependencies, failure modes, recoverability, and security risks across complex platforms.
  • Proficiency in at least one scripting or automation language such as Python, TypeScript, Shell/Bash, or equivalent.
  • Preferably proficient in Kotlin/JVM and TypeScript.
  • Experience with government, CII, financial services, national infrastructure, or other mission-critical environments is advantageous.
  • Cybersecurity architecture certifications such as CISSP / CISSP-ISSAP, SABSA, or cloud security certifications are advantageous.
  • Must be eligible for the required personnel security clearance / CII vetting.
  • Onsite presence during fixed hours may be required due to the critical nature of the role.
Strong knowledge of:
  • Cloud security across IaaS, PaaS, and SaaS
  • Identity and access management
  • Encryption and key management
  • Network segmentation and Zero Trust
  • Secure SDLC and DevSecOps
  • Policy-as-code and security automation
  • Resilience, disaster recovery, and business continuity
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

G03 - Lead Software Engineer (Network Security)
G03 - Lead Software Engineer (Network Security)

FPT ASIA PACIFIC PTE. LTD. • Singapore

On-site
SGD 140,000 - 210,000
Information Technology Security Engineer
Information Technology Security Engineer

Ascendion • Singapore

On-site
SGD 70,000 - 110,000
Senior Security Architect - Critical Infra
Senior Security Architect - Critical Infra

FPT Asia Pacific • Singapore

On-site
SGD 150,000 - 230,000
Lead Engineer/Engineer, Security-By-Design, CISO Office, xCyber
Lead Engineer/Engineer, Security-By-Design, CISO Office, xCyber

HTX (Home Team Science & Technology Agency) • Singapore

On-site
SGD 150,000 - 190,000
Senior Manager, Cybersecurity Operations
Senior Manager, Cybersecurity Operations

GOLDTECH RESOURCES PTE LTD • Singapore

On-site
SGD 80,000 - 130,000
Senior/ Lead Cybersecurity Engineer, TradeNet
Senior/ Lead Cybersecurity Engineer, TradeNet

GovTech Singapore • Singapore

On-site
SGD 120,000 - 180,000
IT Security Lead (AMK)
IT Security Lead (AMK)

maestro human resource pte. ltd. • Singapore

On-site
SGD 180,000 - 230,000
5-day work week
On-site in AMK area
IT Security Engineer
IT Security Engineer

COLD STORAGE SINGAPORE (1983) PTE LTD • Singapore

On-site
SGD 90,000 - 130,000
Senior Cybersecurity Governance Specialist
Senior Cybersecurity Governance Specialist

GovTech Singapore • Singapore

On-site
SGD 120,000 - 180,000
Cyber Security Resident Engineer
Cyber Security Resident Engineer

Ensign InfoSecurity • Singapore

On-site
SGD 70,000 - 100,000