Cybersecurity Engineer (Security Operations)

GovTech Singapore

Singapore

On-site

SGD 80,000 - 120,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

GovTech Singapore is seeking a Cybersecurity Specialist to lead initiatives in incident management and response for public sector safety. This role empowers you to establish incident response protocols, oversee critical incidents, and coordinate agency cybersecurity efforts effectively.

Ideal candidates will bring 8-10 years of experience in cybersecurity operations and possess strong technical skills in SIEM and digital forensics. Join GovTech in shaping Singapore’s digital future.

Qualifications

  • 8 to 10 years of experience in Cybersecurity Operations, SOC Management, or Incident Response.
  • Proven track record of leading security incidents with technical oversight.
  • Experience managing security operations in hybrid environments.

Responsibilities

  • Establish incident response playbooks for diverse threats.
  • Provide oversight during high severity incidents.
  • Design and oversee Tabletop Exercises for agencies.

Skills

Incident Management & Response
Cybersecurity Operations
Digital Forensics
Malware Analysis
Threat Landscape Understanding
Monitoring Strategies

Education

Professional certifications such as GCIH, GCFA, CHFI, or CISSP

Tools

SIEM technologies
SOAR technologies
XDR technologies
EDR technologies

Job description

What the role is

GovTech is the lead agency driving Singapore’s Smart Nation initiatives and public sector digital transformation. As the Centre of Excellence for Infocomm Technology and Smart Systems (ICT & SS), GovTech develops the Singapore Government’s capabilities in Data Science & Artificial Intelligence, Application Development, Smart City Technology, Digital Infrastructure, and Cybersecurity.

At GovTech, we offer you a purposeful career to make lives better where we empower our people to master their craft through robust learning and development opportunities all year round.

Play a part in Singapore’s vision to build a Smart Nation and embark on your meaningful journey to build tech for public good. Join us to advance our mission and shape your future with us today!

Learn more about GovTech at tech.gov.sg.

What you will be working on
Key Responsibilities
  • Incident Management & Response Standardisation
  • Establish and maintain Ministry-wide Incident Response (IR) playbooks for diverse threat scenarios (e.g. ransomware, data exfiltration, cloud breaches)
  • Provide direct technical oversight and guidance during High and Critical severity incidents, ensuring timely containment and reporting
  • Work with Agency CIOs and CISOs to establish clear command structures and governance frameworks that empower leaders to make high-stakes decisions during a crisis
  • Operational Readiness & Resiliency Testing
  • Design and oversee high-quality Tabletop Exercises (TTX) for stakeholders including system owners, SIROs, CISOs, and CIOs; evaluate external vendors to ensure exercises are realistic and rigorous
  • Drive adoption of chaos testing across agencies to validate resiliency plans and surface hidden failure points in critical systems
  • Continuously assess the Ministry Family's incident management capabilities and lead initiatives to bridge identified gaps
  • Continuous Monitoring & Asset Governance
  • Ensure all Ministry systems are effectively onboarded to central monitoring services, working with system owners to resolve onboarding challenges
  • Partner with Agency CIOs to maintain a robust and current IT asset inventory
  • Provide expert guidance for agencies with specialised environments (e.g. OT/ICS) to build bespoke detection capabilities outside standard monitoring coverage
  • Vulnerability & Attack Surface Management
  • Establish SOPs for vulnerability management across on-premises, cloud (GCC), and OT environments, including procedures for managing unpatched vulnerabilities
  • Oversee deployment of internal and external attack surface scanning tools
  • Manage finding prioritisation workflows and validate that patches are applied effectively
  • Advocacy & Education
  • Educate agency stakeholders on the importance of Response and Business Continuity Planning (BCP)
  • Foster an "assumed breach" mindset among project owners and agency leaders, ensuring they understand their roles in threat monitoring and incident management
Qualifications & Requirements
Experience
  • 8 to 10 years of experience in Cybersecurity Operations, SOC Management, or Incident Response
  • Proven track record of leading or providing technical oversight during high-pressure, high-severity security incidents
  • Experience managing security operations across complex hybrid environments (on-premises, cloud, and OT)
Technical Skills
  • Mastery of IR methodologies with strong grounding in digital forensics and malware analysis
  • Deep knowledge of the threat landscape and ability to map monitoring use cases to the MITRE ATT&CK framework
  • Strong understanding of the CVE system and CVSS scoring, including how vulnerabilities are weaponised and how to assess exploitability within a specific environment
  • Proficiency in SIEM, SOAR, XDR, and EDR technologies
  • Familiarity with monitoring and incident response in Government Commercial Cloud (GCC) and native cloud environments
  • Professional certifications such as GCIH, GCFA, CHFI, or CISSP are highly desirable
Soft Skills
  • Calm and authoritative under pressure, with the ability to lead during high-stakes security crises
  • Skilled at translating operational needs into strategic priorities when engaging senior stakeholders
  • Strong strategic foresight to proactively adapt monitoring strategies against emerging threats and evolving actor TTPs
Why Join Us

Be part of a lean, high-impact team at the heart of Agencies cybersecurity function. You will have broad exposure across the full security spectrum — from hands-on technical work to senior stakeholder engagement — and the opportunity to shape how a critical government ministry prepares for and responds to cyber threats.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cybersecurity Operations Specialist
Senior Cybersecurity Operations Specialist

GovTech Singapore • Singapore

On-site
SGD 180,000 - 240,000
Lead Cybersecurity Incident Response Specialist
Lead Cybersecurity Incident Response Specialist

GovTech Singapore • Singapore

On-site
SGD 60,000 - 80,000
Employee wellness programmes
Leave benefits
Flexible work arrangements
Senior Cybersecurity Engineer
Senior Cybersecurity Engineer

GovTech Singapore • Singapore

On-site
SGD 80,000 - 120,000
Flexible work arrangements
Employee wellness programs
Senior Cybersecurity Operation Specialist
Senior Cybersecurity Operation Specialist

Sciente Consulting • Singapore

On-site
SGD 180,000 - 300,000
Senior/ Lead Cybersecurity Engineer, TradeNet
Senior/ Lead Cybersecurity Engineer, TradeNet

GovTech Singapore • Singapore

On-site
SGD 120,000 - 180,000
Senior Cybersecurity Incident & Resilience Lead
Senior Cybersecurity Incident & Resilience Lead

GovTech Singapore • Singapore

On-site
SGD 80,000 - 120,000
Cybersecurity Engineer
Cybersecurity Engineer

GovTech Singapore • Singapore

On-site
SGD 90,000 - 130,000
Leave benefits
Wellness programs
Flexible work arrangements
Lead Cybersecurity Specialist (Security Operations)
Lead Cybersecurity Specialist (Security Operations)

JJ Consulting Services • Singapore

On-site
SGD 80,000 - 120,000
Lead Cybersecurity Specialist (Cyber Defence)
Lead Cybersecurity Specialist (Cyber Defence)

JJ CONSULTING SERVICES • Singapore

On-site
SGD 100,000 - 150,000
Lead Cybersecurity Engineer
Lead Cybersecurity Engineer

GovTech Singapore • Singapore

On-site
SGD 180,000 - 260,000