IT Security Lead (AMK)

maestro human resource pte. ltd.

Singapore

On-site

SGD 180,000 - 230,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

5-day work week
On-site in AMK area

Job summary

maestro human resource pte. ltd. seeks an IT Security Lead to manage end-to-end governance, compliance, and operations for mission-critical systems. You'll collaborate with cross-functional teams and external auditors to ensure adherence to government security policies.

Responsibilities cover secure design, threat modeling, risk assessment, and securing CI/CD pipelines with DevSecOps practices, incident response, and audits. Strong Singapore govt security experience is required.

Qualifications

  • Minimum 8–12 years IT experience withat least 5 years as Security Lead or Architect.
  • Proven experience in Singapore Government IT projects and IM8/government security compliance.
  • Hands-on experience with Kubernetes/Docker security, API security, IAM, and security tools (SAST/DAST/SIEM) integrated with CI/CD.

Responsibilities

  • Day 1 – Define and implement system security architecture aligned with Singapore Government policies.
  • Review designs for security compliance across application, middleware, infrastructure and platform.
  • Conduct threat modeling and risk assessments with mitigating controls.
  • Translate policy requirements into actionable technical controls across tech stacks.
  • Ensure compliance with IM8, Whole-of-Government security requirements, and PDPA where applicable.
  • Establish and oversee cybersecurity governance across infrastructure, applications and projects.
  • Prepare and maintain Security Risk Assessments, Vulnerability Assessments, Penetration Testing reports and baselines.
  • Partner with software teams to enforce secure coding standards and DevSecOps practices.
  • Integrate and govern SAST/DAST, SCA scanning, and container image scanning in CI/CD pipelines.
  • Review and triage security findings; drive remediation and risk acceptance decisions.
  • Provide guidance on API security, token/secret management, and secure service-to-service communication.
  • Plan, coordinate, and manage vulnerability and penetration testing engagements and vendors.
  • Track remediation progress to closure and document residual risks and risk acceptance.
  • Support security clearances and go-live certifications.
  • Review and approve OS, middleware, database, Kubernetes/container security, API gateway, WAF, rate-limiting and authentication configurations.

Skills

Kubernetes security
Docker security
API security
IAM
CI/CD security
Security governance

Education

CS/InfoSec degree

Tools

SAST/DAST tools
CI/CD security tooling

Job description

Job Summary

The IT Security Lead manages end-to-end security governance, compliance, and operations for mission-critical systems, collaborating with cross-functional teams and external auditors to ensure adherence to government security policies.

Responsibilities

Day 1 – Project / Implementation Security

  • Define and implement system security architecture aligned with Singapore Government policies
  • Review application, middleware, infrastructure, and platform designs for security compliance
  • Conduct threat modeling and risk assessments, mapping risks to mitigating controls
  • Translate policy requirements into actionable technical controls across technology stacks
  • Ensure compliance with IM8, Whole-of-Government security requirements, and PDPA where applicable
  • Establish and oversee cybersecurity governance across infrastructure, application, and project teams
  • Prepare and maintain documentation including Security Risk Assessments, Vulnerability Assessments, Penetration Testing reports, and security hardening baselines
  • Partner with software teams to enforce secure coding standards and DevSecOps practices
  • Integrate and govern SAST/DAST, dependency/SCA scanning, and container image scanning within CI/CD pipelines
  • Review and triage security tool findings, driving remediation and risk acceptance decisions
  • Provide guidance on API security, token/secret management, and secure service-to-service communication
  • Plan, coordinate, and manage vulnerability and penetration testing engagements and vendors
  • Track remediation progress to closure and document residual risks and risk acceptance
  • Support security clearances and go-live certifications
  • Review and approve OS, middleware, database, Kubernetes/container security, API gateway, WAF, rate-limiting, and authentication configurations

Day 2 – Operations / Production Security

  • Lead security incident investigations, containment, and recovery efforts
  • Perform root cause analysis and define corrective and preventive actions
  • Coordinate with Government SOC and stakeholders; contribute to and refine incident response playbooks
  • Communicate security incidents clearly to technical and non-technical audiences
  • Oversee continuous vulnerability monitoring and posture management
  • Track patch and configuration compliance across infrastructure, middleware, applications, and containers
  • Provide risk assessments and compensating controls for deferred patches
  • Review and tune alerts, detections, and dashboards in SIEM and related tools
  • Ensure monitoring coverage for critical systems and high-value assets
  • Support internal and external audits, evidence collection, and closure of audit findings
  • Prepare and present security posture, metrics, and trend reports to management
  • Maintain risk registers and mitigation plans with up-to-date security documentation
  • Communicate security assessments and findings effectively to varied stakeholders
  • Oversee and periodically review RBAC, MFA, Privileged Access Management, and joiner/mover/leaver processes
  • Ensure least privilege access, segregation of duties, and periodic access recertifications
  • Support incident response handling, log analysis, and activity reviews
  • Drive continuous improvement across identify, protect, detect, respond, and recover functions
Required competencies and certifications
  • Degree in Computer Science, Cybersecurity, Information Security, or equivalent
  • 8–12 years of IT experience including at least 5 years as a Security Lead or Security Architect
  • Proven experience in Singapore Government IT projects and IM8/government security compliance
  • Hands-on experience with Kubernetes/Docker security, API security, Identity & Access Management (IAM), and security tools (SAST/DAST/SIEM) integrated with CI/CD
Preferred competencies and qualifications
  • Certifications such as CISSP, CISM, CISA, CEH, GIAC (e.g., GSEC, GCIA, GCIH, GCSA)
  • AWS or Azure Security certifications

5 day week @ AMK area

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Security Engineer
IT Security Engineer

MINDTECK SINGAPORE PTE LTD • Singapore

On-site
SGD 60,000 - 120,000
IT Security Engineer
IT Security Engineer

ASCENDION ENGINEERING SOLUTIONS SINGAPORE PTE. LTD. • Singapore

On-site
SGD 90,000 - 120,000
Information Technology Security Engineer
Information Technology Security Engineer

Ascendion • Singapore

On-site
SGD 70,000 - 110,000
IT Security Engineer
IT Security Engineer

NEWTONE SERVICES PTE. LTD. • Singapore

On-site
SGD 80,000 - 120,000
IT Security Manager (Public Sector)
IT Security Manager (Public Sector)

NEWTONE CONSULTING PTE. LTD. • Singapore

On-site
SGD 120,000 - 180,000
IT Security manager
IT Security manager

NEWTONE CONSULTING PTE. LTD. • Singapore

On-site
SGD 120,000 - 160,000
Information Technology Security Engineer
Information Technology Security Engineer

Newtone consulting • Singapore

On-site
SGD 60,000 - 110,000
Security Manager | Singaporean Only !
Security Manager | Singaporean Only !

TG Singapore • Singapore

On-site
SGD 120,000 - 180,000
Security Operations Engineer
Security Operations Engineer

DADACONSULTANTS PTE. LTD. • Singapore

On-site
SGD 90,000 - 150,000
IT Security Lead: Government-Grade Security & Compliance
IT Security Lead: Government-Grade Security & Compliance

maestro human resource pte. ltd. • Singapore

On-site
SGD 180,000 - 230,000
5-day work week
On-site in AMK area