Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.
Government Technology Agency is seeking a senior security leader to own GCC security posture across multiple product teams and cloud environments. You will design and evolve threat modelling, escalation frameworks, and incident playbooks while driving tooling strategy and a Champions network.
You will influence without authority across engineering teams and shape platform security for Singapore's public sector cloud.
GovTechis the lead agency driving Singapore’s Smart Nation initiatives and public sector digital transformation. As the Centre of Excellence forInfocommTechnology and Smart Systems (ICT & SS),GovTechdevelops the Singapore Government’s capabilities in Data Science & Artificial Intelligence, Application Development, Smart City Technology, Digital Infrastructure, and Cybersecurity.
AtGovTech, we offer you a purposeful career to make lives better where we empower our people to master their craft through robust learning and development opportunities all year round.
Play a part in Singapore’s vision to build a Smart Nation and embark on your meaningful journey to build tech for public good. Join us to advance our mission and shape your future with us today!
Learn more aboutGovTechat tech.gov.sg.
Government Commercial Cloud (GCC) is a key platform within Singapore Government Technology Stacks that enables government agencies to build and operate digital services on commercial cloud. The GCC Engineering team develops platform automations, landing zones, and security tooling across AWS, Azure, and GCP — serving thousands of government systems and thousands of public officers.
Security at GCC is not a side function — it's core to the platform's value proposition. Government agencies trust GCC to be secure by default.
You are the single named owner of security outcomes across all engineering teams in GCC. You define how security works — the standards, processes, escalation paths, and technical approaches — and drive adoption through influence, not authority. You operate through a Security Champions network: persistent, named engineers in each product team who own security judgment locally, coordinated by you. Your accountability is whether GCC is actually secure — measured through process health, incident response quality, and security posture metrics you define.
This role is part of the organisation's domain leadership structure — you join alongside Engineering Managers as a peer, not as a report to any EM. The Security domain is being stood up fresh. The previous model (centralised security team gatekeeping all decisions) has been retired. You inherit a Champions network in early stages, documented runbooks, and interim coverage from a senior security advisor. Your job is to take it from "interim bridge" to "sustainable, scalable security function."
The domain scope will evolve. Today it centres on the areas listed above — but we expect the role to grow into adjacent areas (AI security, detection engineering) as the organisation's needs develop. Adaptability and willingness to define your own frontier matters more than deep expertise in every area on day one.
You'll encounter the following in this role. We don't expect mastery of all of these on day one — what matters is the ability to learn quickly and form sound judgment across unfamiliar tools.
| Area | Technologies |
|------|-------------|
| Cloud providers | AWS, Azure, GCP (multi-account/subscription/project at scale) |
| Security posture | Wiz, AWS Security Hub, Azure Defender, GCP Security Command Center |
| Vulnerability management | Nessus, Trivy, AWS Inspector, container scanning |
| SIEM & detection | Elastic SIEM, GuardDuty, Sentinel, CloudTrail/Activity Log |
| Identity & access | IAM (all CSPs), Entra ID, workload identity, RBAC/ABAC patterns |
| IaC & pipelines | Terraform, GitLab CI/CD, policy-as-code (OPA, Sentinel) |
| Secrets & supply chain | Vault, AWS Secrets Manager, SBOM tooling, dependency scanning |
| Compliance frameworks | IMR8, CIS Benchmarks, NIST CSF, ISO 27001, MITRE ATT&CK |
| Scripting & automation| Python, Bash, REST APIs |
| Emerging | AI/LLM security (OWASP LLM Top 10, NIST AI RMF), detection-as-code |
Not required, but signal depth in relevant areas:
GovTechis an equal opportunity employer committed to fostering an inclusive workplace that values diverse voices and perspectives, as we believe that diversity is the foundation to innovation.
Our employee benefits are based on a total rewards approach, offering a holistic and market-competitive suite of perks. These include leave benefits to meet your work-life needs and employee wellness programs.
We champion flexible work arrangements (subject to your job role) and trust that you will manage your own time to deliver your best, wherever you are, and whatever works best for you.
Learn more about life insideGovTechat go.gov.sg/GovTechCareers.
Stay connected with us on social media at go.gov.sg/ConnectWithGovTech