Senior Assistant Director (GCS-Dev/Government/Healthcare), CSPC

Cyber Security Agency of Singapore (CSA)

Singapore

On-site

SGD 180,000 - 260,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

The Cyber Security Agency of Singapore (CSA) is seeking a senior cybersecurity professional to lead a multidisciplinary team across the GCS-Dev, Government and Healthcare pillars. You will conduct risk assessments, review security designs and plan security testing to ensure protective controls meet justifiable risk levels.

You will collaborate with system owners and project teams to develop threat models, recommend mitigations, and drive security architecture improvements while mentoring staff

Qualifications

  • Bachelor degree in ICT-related discipline; information security or cybersecurity preferred.
  • Professional qualifications such as CISSP, CISA, CRISC or equivalent.
  • 15–20 years of relevant experience with 10+ years in leadership roles.
  • Strong interest in cybersecurity and hands-on technical curiosity.
  • Excellent analytical, communication and stakeholder management skills.
  • Able to work independently and lead a team across multiple units.

Responsibilities

  • Perform risk assessments for GCS-Dev/Government/Healthcare and justify risks to System owners.
  • Review security designs of ICT systems and propose mitigations.
  • Review security testing scopes, plans, and results; ensure comprehensive testing.
  • Develop security reference architectures and threat models to guide consultancy.
  • Lead team capability development, training, and knowledge management.
  • Collaborate with stakeholders to ensure secure, compliant systems.

Skills

Leadership
Cybersecurity consulting
Risk assessment
Security design review
Security testing
Team management
Stakeholder management

Education

Bachelor Degree in ICT-related discipline
CISSP/CISA/CRISC or equivalent

Job description

The successful candidate will be assigned to work in one of the various pillars in the division such as "Government Central Systems Development (GCS-Dev)", "Government" and "Healthcare". Lead a team of assistant directors, senior consultants, consultants and system engineers to provide cybersecurity consultancy through evaluating the risk assessment, security design review and plan and review security testing of GCS-Dev / Government/ Healthcare so as to ensure that the Systems are well protected while System owner accepts justifiable risk levels.

Responsibilities
  1. Perform the risk assessment for GCS-Dev/ Government/ Healthcare to ensure it is well protected and justify the risks to the System owner for risk acceptance
    • Collaborate with system owners and project team to understand the business and system requirements so that you can analyse and identify the cyber and physical threats and formulate the relevant project-specific scenarios and potential risks.
    • Propose people, process and technology (PPT) cybersecurity mitigation controls on the completed TRA Template and project-specific scenarios.
    • Justify the residual risks level for acceptance and approval by the designated approving authority.
  2. Review the security design of GCS-Dev/ Government/ Healthcare ICT systems to identify areas of weaknesses and recommend security solution or controls to mitigate against highlighted threats
    • Identify, assess and review cybersecurity solutions to secure ICT networks and systems.
    • Collaborate with system owners and project team to review and provide advice on the final proposed security design and mitigation controls.
    • Collaborate with system owners and project team to identify additional risks due to deviations in the final proposed security design and propose mitigation controls
  3. Review security testing scopes and plans that validate and verify the security design of the GCS (Dev) / Government/ Healthcare ICT Systems
    • Review vendor's system security testing proposals and Penetration Test (PT) plans, and if needed, insert or counter propose test plans and test cases to make sure the security testing is comprehensive.
    • Review and provide advice to system owners and project team on the conduct of system security testing and PT.
    • Serves as controller to verify the execution of the system security testing and PT.
    • Assess and provide advice, identify risks and propose remediation measures on the findings and recommendations from the system security testing and PT reports
  4. Optimise cybersecurity consultancy practices for effectiveness and efficiency of GCS-Dev/ Government/ Healthcare systems
    • Develop security reference architectures and threat reference models to optimise consultancy effectiveness and efficiencies.
    • Work with team members to develop, operate and publish the security reference architectures and threat reference models.
    • Enforce approved security reference architecture and threat reference models during cybersecurity consultancy.
    • Analyse lessons learned from consultancy works and incorporate areas of improvement to enhance Consultancy Models, security reference architecture and threat reference models
  5. Manage Team Capability Development
    • Managed Team esprit de corps, professional and personal developments
    • Develop training plans for the team based on competency framework i.e. RTEC (Raise + Train + Evaluate = Capability) Framework.
    • Identify suitable training programmes/events/seminars for each team role to associate the required capability in dealing with ever-changing cybersecurity threats landscape.
    • Monitor training budget allocated and provide updates to management when required.
    • Establish processes for Knowledge Management for purpose of cybersecurity consultancy knowledge sharing and retention
Qualifications
  • Bachelor Degree in Information Communication Technology-related discipline (Cybersecurity, Information Security, Information Technology, Computer Science, Management Information Systems), Science or Engineering etc.
  • Professional qualifications such as CISSP, SANS, CISA, CRISC or equivalent
  • At least 15 to 20 years relevant working experience and more than 10 years of supervisory experience to manage, work and collaborate with various parties including stakeholders, system owners, teammates and contractors
  • Good understanding and interest in Cybersecurity
  • Technically hands-on and curious about inner workings of technology
  • Strong analytical and conceptualisation skills
  • Good communications and interpersonal relationship skills, stakeholder management
  • Driven and capable to work independently. Resourceful, responsible, motivated and able to work independently as well as in a team.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Assistant Lead Engineer - Security Operations (Cyber Defence & Resilience)
Assistant Lead Engineer - Security Operations (Cyber Defence & Resilience)

Synapxe • Singapore

On-site
SGD 90,000 - 150,000
Specialist (Cybersecurity)
Specialist (Cybersecurity)

NTUC FIRST CAMPUS LIMITED • Singapore

On-site
SGD 70,000 - 120,000
Specialist (Cybersecurity)
Specialist (Cybersecurity)

NTUC First Campus • Singapore

On-site
SGD 90,000 - 130,000
Specialist (Cybersecurity)
Specialist (Cybersecurity)

NTUC First Campus Co-operative Ltd • Singapore

On-site
SGD 90,000 - 150,000
Cybersecurity Consultant
Cybersecurity Consultant

ATET PTE. LTD. • Singapore

On-site
SGD 60,000 - 90,000
Marriage Leave
Childcare Leave
Medical Benefits
Senior Cybersecurity Consultant (Policy & Analytics), CIID
Senior Cybersecurity Consultant (Policy & Analytics), CIID

Cyber Security Agency of Singapore (CSA) • Singapore

On-site
SGD 120,000 - 180,000
Information Technology Security Manager
Information Technology Security Manager

Newtone Consulting • Singapore

On-site
SGD 180,000 - 240,000
Senior Security Analyst (Governance, Risk and Compliance)
Senior Security Analyst (Governance, Risk and Compliance)

energy market company • Singapore

On-site
SGD 120,000 - 180,000
Cybersecurity Strategy (Deputy Director)
Cybersecurity Strategy (Deputy Director)

GovTech Singapore • Singapore

On-site
SGD 100,000 - 130,000
IT Security Manager (Public Sector)
IT Security Manager (Public Sector)

NEWTONE CONSULTING PTE. LTD. • Singapore

On-site
SGD 90,000 - 130,000