Lead Cybersecurity Consultant (Cybersecurity Certification Centre), CSEC

Cyber Security Agency of Singapore

Singapore

On-site

SGD 180,000 - 280,000

Full time

8 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Cyber Security Agency of Singapore is seeking a senior technical leader to drive national cybersecurity certification and labelling schemes, mentor a skilled team, and advance research in penetration testing and security evaluations.

You will guide assessments of emerging technologies and provide technical input for international standards, while building secure testing ecosystems and automation tools for enhanced evaluation capabilities.

Qualifications

  • Bachelor's degree in a technical discipline; engineering, CS, or math.
  • Experience in security evaluation and testing of emerging technologies.
  • Ability to develop and implement security evaluation standards; mentoring and leadership skills.

Responsibilities

  • Provide technical leadership for national cybersecurity certification schemes and labelling.
  • Lead advanced penetration testing and vulnerability assessments for diverse product domains.
  • Drive R&D to identify gaps and translate research into practical schemes and tools.
  • Develop in-house tooling, AI-enabled testing solutions, and automation to improve evaluation efficiency.
  • Collaborate with international standards bodies and academia on scheme development.

Skills

Offensive security research
Penetration testing
Security assessment
Technical leadership
Mentoring
Communication skills
Common Criteria familiarity

Education

Bachelor's degree in Engineering/Computer Science

Tools

Automation frameworks
Common Criteria tooling

Job description

What the role is:

To provide technical leadership and capability development across national cybersecurity certification and labelling schemes (NITES, Common Criteria, Cybersecurity Labelling Scheme), while mentoring the team in advanced penetration testing methodologies, conducting critical technical assessments on emerging technologies, and serving as the Lead Technical Assessor for Enterprise Singapore's ISO/IEC 17025 Accreditation Programme to strengthen Singapore's Testing Inspection and Certification (TIC) Cyber ecosystem and maintain international standards of technical competency across approved testing laboratories.

What you will be working on:
Technical Capability Development
  • Develop and implement technical competency frameworks defining security evaluation standards across diverse product categories including enterprise systems, consumer IoT devices, and medical equipment
  • Provide technical mentorship and build team’s expertise in advanced testing methodologies and security assessment approaches for specialised domains including cryptographic implementations, network security solutions, IoT ecosystems, and medical device cybersecurity
  • Drive research and development initiatives to identify real‑world technical gaps, create innovative attack techniques and methodologies, set research directions, and collaborate with academia to ensure research outcomes are translatable into practical applications
  • Build solutions for in‑house use including tools for processing applications, AI‑enabled testing tools, and automation systems to enhance evaluation efficiency and capabilities
  • Conduct cutting‑edge research into advanced attack vectors and techniques suitable for high‑assurance security evaluations2.
Advanced Security Testing and Evaluation
  • Provide technical leadership for complex evaluation projects across schemes
  • Conduct advanced penetration testing and vulnerability assessments
  • Apply newly developed attack techniques to complex evaluation projects
  • Provide Approved Testing Laboratories with technical guidance on complex evaluations
  • Validate the effectiveness of security controls against state‑of‑the‑art attacks
  • Develop custom testing approaches for novel product categories and emerging technologies, including conducting rapid technical assessments for emerging payment systems, fintech solutions, and digital services (such as Palm Pay and similar technologies)
Emerging Technology Assessment and Scheme Development
  • Conduct technical assessments of emerging technologies for cybersecurity implications
  • Research and analyse security requirements for new product categories/emerging technologies (such as AI/ML, quantum computing, 5G/6G, autonomous systems)
  • Translate technical findings into practical scheme requirements
  • Provide technical input for international standards development and mutual recognition arrangements
  • Lead Singapore's initiative to harmonise cybersecurity requirements for Common Criteria evaluators and certifiers internationally
  • Develop partnerships with academic institutions and industry for cybersecurity research
  • Survey technological landscape and provide recommendations on key opportunities for new schemes
What we are looking for:
  • Minimum 10 – 15 years in the field of cybersecurity with at least 10 years in security evaluation, penetration testing, or product security assessment
  • Bachelor’s degree in Engineering, Computer Science, Information Systems, Mathematics, or relevant technical discipline
  • Strong background in offensive security research, advanced penetration testing techniques, and security assessments of emerging technologies and novel systems
  • Experience in conducting security assessments based on state‑of‑the‑art security attack techniques
  • Deep technical expertise in vulnerability analysis and penetration testing with proven ability to develop custom attack techniques, improvise published attacks, and conduct security assessments based on state‑of‑the‑art security attack techniques
  • Experience in developing custom tools, automation frameworks, or technical solutions for operational use
  • Product security assessment or security evaluation experience (Common Criteria, or similar certification schemes preferred but not required)
  • Good mentoring and knowledge transfer abilities
  • Strong communication skills for technical and non-technical audiences
  • Ability to work under pressure
  • Creative problem-solving and ability to think outside conventional approaches
  • Team player with strong collaborative skills who is also able to work independently and take initiative on complex technical projects
  • Applicant with Certified Ethical Hacker (CEH), Licensed Penetration Tester Master (LPT) Certification, Offensive Security Certified Professional (OSCP), GIAC Penetration Tester (GPEN) Certification, GIAC Exploit Researcher and Advanced Penetration Tester (GXPN) Certification, CompTIA PenTest+ etc would be a plus.
About Cyber Security Agency of Singapore

About the Cyber Security Agency of SingaporeEstablished in 2015, the Cyber Security Agency of Singapore (CSA) seeks to keep Singapore’s cyberspace safe and secure to underpin our Nation Security, power a Digital Economy and protect our Digital Way of Life. It maintains an oversight of national cybersecurity functions and works with sector leads to protect Singapore’s Critical Information Infrastructure. CSA also engages with various stakeholders to heighten cyber security awareness, build a vibrant cybersecurity ecosystem supported by a robust workforce, pursue international partnerships and drive regional cybersecurity capacity building programmes. CSA is part of the Prime Minister’s Office and is managed by the Ministry of Digital Development and Information. For more news and information, please visit www.csa.gov.sg

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Cybersecurity Consultant (Cybersecurity Certification Centre), CSEC
Lead Cybersecurity Consultant (Cybersecurity Certification Centre), CSEC

Cyber Security Agency of Singapore (CSA) • Singapore

On-site
SGD 180,000 - 280,000
Senior Cybersecurity Consultant (ASG), Cybersecurity Engineering Centre
Senior Cybersecurity Consultant (ASG), Cybersecurity Engineering Centre

Cyber Security Agency of Singapore • Singapore

On-site
SGD 120,000 - 170,000
Senior Assistant Director (GCS-Dev/Government/Healthcare), CSPC
Senior Assistant Director (GCS-Dev/Government/Healthcare), CSPC

Cyber Security Agency of Singapore • Singapore

On-site
SGD 180,000 - 260,000
Lead Cybersecurity Consultant & Technical Evaluation Expert
Lead Cybersecurity Consultant & Technical Evaluation Expert

Cyber Security Agency of Singapore (CSA) • Singapore

On-site
SGD 180,000 - 280,000
Senior Cybersecurity Consultant (Policy & Analytics), CII
Senior Cybersecurity Consultant (Policy & Analytics), CII

Cyber Security Agency of Singapore • Singapore

On-site
SGD 100,000 - 150,000
Deputy Director/Senior Assistant Director, SingCERT, NCIRC, CSA
Deputy Director/Senior Assistant Director, SingCERT, NCIRC, CSA

Cyber Security Agency of Singapore • Singapore

On-site
SGD 180,000 - 300,000
Manager, Cybersecurity Governance and Risk Assessment, Safer Cyberspace Division
Manager, Cybersecurity Governance and Risk Assessment, Safer Cyberspace Division

Cyber Security Agency of Singapore • Singapore

On-site
SGD 90,000 - 150,000
Lead Cybersecurity Consultant: Advanced Testing
Lead Cybersecurity Consultant: Advanced Testing

Cyber Security Agency of Singapore • Singapore

On-site
SGD 180,000 - 280,000
Senior Cybersecurity Consultant (ASG), Cybersecurity Engineering Centre
Senior Cybersecurity Consultant (ASG), Cybersecurity Engineering Centre

Cyber Security Agency of Singapore (CSA) • Singapore

On-site
SGD 120,000 - 180,000
Lead Consultant / Senior Consultant, Technical Architecture Office
Lead Consultant / Senior Consultant, Technical Architecture Office

Cyber Security Agency of Singapore • Singapore

On-site
SGD 180,000 - 260,000