Agency Chief Information Security Officer

GovTech Singapore

Singapore

On-site

SGD 180,000 - 320,000

Full time

37 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

GovTech Singapore invites a seasoned ACISO to lead the agency's information security program, overseeing security across on‑premises and cloud platforms. The role requires strategic oversight and hands‑on expertise in governance, incident response, and secure architecture.

You will collaborate with CIOs, project teams, and vendors to define security strategies, manage risk, and drive security by design across digital transformation initiatives within public agencies.

Qualifications

  • Solid grasp of ICT operations, security policies and business processes.
  • Strong leadership and ability to work with multi-functional teams.
  • Knowledge of security by design, secure architecture reviews, DevSecOps.
  • Understanding of cloud service models (IaaS, PaaS, SaaS) and cloud-native architectures.
  • Ability to assess on-premises and cloud cybersecurity risks.
  • Experience communicating cyber security topics to senior stakeholders.
  • CISSP certification or equivalent preferred.

Responsibilities

  • Lead the agency-level cybersecurity function in supporting agency digital transformation initiatives while ensuring digital resilience.
  • Formulate and implement agency cybersecurity strategies, policies and work plans, aligning with business goals.
  • Review and enhance risk management through threat-based assessments, mitigations, monitoring and reporting.
  • Provide consultation and endorse risk management plans from project teams.
  • Govern and enhance security posture by maintaining visibility of ICT assets, architectures and operations.
  • Develop and maintain incident response plans and playbooks, conduct workshops and drills, lead investigations.
  • Advise on cybersecurity technologies that meet business requirements and align with advisories.
  • Ensure secure by design ICT product development and compliance with policies and guidelines.
  • Develop and maintain cybersecurity awareness and training programs.

Skills

Cybersecurity governance
Security operations
Architecture design
Threat risk assessment
Security testing
Cloud security
DevSecOps
IaC
CI/CD security
Security by design
Stakeholder communication
Leadership

Education

Degree in Computer Science, Information Systems, Engineering or related Technology field

Tools

IaC tools

Job description

Role

GovTech supports various Government Agencies in carrying out ICT delivery services and appoints Agency Chief Information Security Officers (ACISO) to oversee information security management within these agencies. The ACISO is a leadership role that requires technical proficiency demonstrated in multiple cybersecurity domains. The role demands knowledge and/or practical experience in most of the domains below:

  • Cybersecurity Governance frameworks,
  • Security Operations including incident response,
  • Architecture design and threat risk assessment,
  • Security Testing.

The ACISO must possess technical understanding of both on-premises infrastructure security and cloud security architectures across major platforms (e.g., AWS, Azure, and GCP), including their native security features, identity management systems, and security control implementations.

[What you will be working on]
Responsibilities

Emplaced in public agencies and reporting to the agency's Chief Information Officer (CIO) and Ministry Family CISO, you will collaborate with various stakeholders (GovTech HQ teams, Agency management, Agency project teams, and outsourced vendors) and will be responsible to:

  • Lead the agency-level cybersecurity function in supporting agency digital transformation initiatives whilst ensuring digital resilience of agency systems.
  • Formulate and implement agency cybersecurity strategies, policies and work plans, ensuring continuous alignment with Ministry Family's business strategic goals
  • Review and enhance risk management through threat-based risk assessments, risk mitigations, risk monitoring and reporting.
  • Provide consultation and endorse risk management and mitigation plans from agency's project teams.
  • Govern and enhance the agency's security posture by maintaining visibility and oversight of ICT assets, security architectures, and cybersecurity operations code of practices.
  • Develop and maintain incident response plan and playbooks. This involves planning, designing and conduct of security incident response workshops and exercises (table-top exercises, simulation and drills) as well as lead the investigation and management of ICT security incidents.
  • Provide advisory and recommendations on appropriate cybersecurity technologies to be deployed that meets agency's business requirements and aligned with WOG-wide advisories and practices.
  • Ensure secure by design ICT product development, and that security controls implementations comply with the defined security policies, standards and guidelines.
  • Develop and maintain effective cybersecurity awareness and training programmes
[What we are looking for]
  • Degree in Computer Science, Information Systems, Engineering or related Technology field
  • At least 8-10 years of management experience related to information security and solid grasp of ICT operations, security policies, business processes and the relationship between them.
  • Ability to work with multi-functional, multi-disciplined teams to formulate, institute real time awareness of security posture and baseline among end users.
  • Good interpersonal and partner/executive leadership skills.
  • Demonstrate knowledge and experience in security by design implementations, review of system architecture, devsecops practices, Infrastructure as Code (IaC) tools and securing CI/CD pipelines
  • Demonstrate understanding of cloud service models (IaaS, PaaS, SaaS), coupled with a strong understanding of core cloud services and modern cloud-native architectures (serverless, containers, microservices)
  • Identify on-premises and cloud-specific cybersecurity risks and threats, demonstrating skills to thoroughly assess their impact and likelihood. This assessment encompasses, but is not limited to, secure configurations, insider threats, vendor risks, data leakage, malwares including ransomware, account hijacking, and compliance risks.
  • Evaluate the effectiveness of existing controls and recommending appropriate mitigation strategies for on-premises and cloud-related cybersecurity and data security issues.
  • Display understanding of emerging threats and technologies, and the ability to translate risk into business impact
  • Strong understanding of compliance requirements and the ability to identify potential violations in on-premises or cloud environments.
  • Able to communicate cyber security topics effectively to senior stakeholders.
  • Minimally possess CISSP certification, preferably with other related certifications, e.g. CISM, CCSP, GCIH that demonstrates continuous learning and knowledge of industry best practices.
  • We believe in being Agile, Bold and Collaborative, and are looking for people who identify with these values.
  • Singaporeans only.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Public Sector CISO & Cybersecurity Strategy Leader
Public Sector CISO & Cybersecurity Strategy Leader

GovTech Singapore • Singapore

On-site
SGD 180,000 - 320,000
Senior Cybersecurity Governance Specialist
Senior Cybersecurity Governance Specialist

GovTech Singapore • Singapore

On-site
SGD 120,000 - 180,000
Senior Cybersecurity Operations Specialist
Senior Cybersecurity Operations Specialist

GovTech Singapore • Singapore

On-site
SGD 180,000 - 240,000
Agency Chief Information Security Officer
Agency Chief Information Security Officer

JJ CONSULTING SERVICES • Singapore

On-site
SGD 120,000 - 180,000
Senior Cybersecurity GRC Leader: Zero Trust Risk Strategy
Senior Cybersecurity GRC Leader: Zero Trust Risk Strategy

GovTech Singapore • Singapore

On-site
Cybersecurity Strategy (Deputy Director)
Cybersecurity Strategy (Deputy Director)

GovTech Singapore • Singapore

On-site
SGD 100,000 - 130,000
Ministry Chief Information Security Officer
Ministry Chief Information Security Officer

GovTech Singapore • Singapore

On-site
SGD 300,000 - 500,000
IT Security Manager (Public Sector)
IT Security Manager (Public Sector)

NEWTONE CONSULTING PTE. LTD. • Singapore

On-site
SGD 90,000 - 130,000
IT Security Officer - JN
IT Security Officer - JN

DCI CONSULTANTS PRIVATE LIMITED • Singapore

On-site
SGD 120,000 - 170,000
Senior/ Lead Cybersecurity Engineer, TradeNet
Senior/ Lead Cybersecurity Engineer, TradeNet

GovTech Singapore • Singapore

On-site
SGD 120,000 - 180,000