Senior Cybersecurity Operations Specialist (Security Services)

Government Technology Agency

Singapore

On-site

SGD 120,000 - 180,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

GovTech in Singapore is hiring a Security Services Specialist to elevate cyber security across the Ministry Family. The role focuses on security testing governance, secure-by-design, and source code excellence, bridging governance with technical implementation.

You will lead red-teaming, SAST/DAST/SSCA programs, and guide DevSecOps integration, collaborating with CIOs, ACISOs, and project owners to strengthen the government’s security posture.

Qualifications

  • 8–10 years of deep technical experience in cybersecurity with a focus on offensive security and application security.
  • Proven track record in conducting pen-tests for web apps, IT systems (on-prem and cloud), and complex networks.
  • Experience performing manual and automated source code reviews to identify logic flaws, injection vulnerabilities, and cryptographic weaknesses.

Responsibilities

  • Establish ministry-wide security testing standards (VAPT) and SOPs for engaging external vendors.
  • Lead Red Teaming and deep-dive penetration tests on high-impact systems.
  • Oversee secure-by-design practices, including secure coding guidelines based on OWASP/SANS.
  • Drive CI/CD security integration (DevSecOps) and code quality oversight across agencies.
  • Engage CIOs and project owners to promote secure-by-design culture and knowledge sharing.

Skills

SSDLC
Offensive Security
Source code security
Security testing governance

Tools

Checkmarx
Fortify
SonarQube
Snyk
Burp Suite
Jenkins
GitLab CI
GitHub Actions

Job description

GovTech is the lead agency driving Singapore’s Smart Nation initiatives and public sector digital transformation. As the Centre of Excellence forInfocommTechnology and Smart Systems (ICT & SS), GovTech develops the Singapore Government’s capabilities in Data Science & Artificial Intelligence, Application Development, Smart City Technology, Digital Infrastructure, and Cybersecurity.

At GovTech, we offer you a purposeful career to make lives better where we empower our people to master their craft through robust learning and development opportunities all year round.

Play a part in Singapore’s vision to build a Smart Nation and embark on your meaningful journey to build tech for public good. Join us to advance our mission and shape your future with us today!

Learn more about GovTech at tech.gov.sg.

What you will be working on

The Cyber Security Group (CSG) is the cybersecurity arm of GovTech. CSG is committed to create a digital government that is safe and secure. CSG delivers technical and operational capabilities to counteract cyber threats, provides thought leadership on transformative cybersecurity governance and policies and to strengthen the cybersecurity posture of government agencies in a manner that is sustainable, pragmatic, and effective.

To enhance infocommsecurity capabilities in GovTech and the Whole-of-Government (WOG), GovTech appointsChief Information Security Officer (CISO) teams at the various ministries to oversee infocomm security management.

As the Security Services Specialist within the Ministry CISO (MCISO) Office, you will be the domain expert responsible for elevating the security testing and "Secure-by-Design" capabilities across the entire Ministry Family. You will bridge the gap between high-level governance and technical implementation, ensuring that all agencies under the Ministry’s purview adopt consistent, high-quality security practices. Your role is pivotal in shifting the Ministry from a reactive security posture to a proactive, resilient one.

Key Responsibilities
  1. Security Testing Governance & Standardisation
  • Establish Standards: Define and maintain the Ministry-wide framework for security testing (Vulnerability Assessment and Penetration Testing - VAPT).
  • SOP Development: Create and roll out Standard Operating Procedures (SOPs) to guide Agency project teams on engaging external security vendors and managing internal testing cycles.
  • Quality Assurance: Develop "Quality Rubrics" to help agencies evaluate the performance of pen-testers. You will conduct periodic sampling of testing reports and project involvements to ensure quality and rigour across the Ministry Family.
  1. Advanced Technical Operations
  • Red Teaming & Critical Testing: Lead and execute complex Red Teaming exercises and deep-dive penetration tests on the Ministry’s high-impact systems.
  • Adversary Simulation: Utilise knowledge of the latest Adversary Tactics, Techniques, and Procedures (TTPs) to simulate real-world attacks, helping agencies identify blind spots in their prevention, detection and response capabilities.
  • Environmental Scanning: Proactivelymonitorthe global threat landscape toidentifyemerging threats and evolving actor TTPs. Assess how these changesimpactthe Ministry's current security posture and update testing standards accordingly.
  1. Secure-by-Design & Source Code Excellence
  • Secure Coding Standards: Establish Ministry-wide secure coding guidelines (e.g., based on OWASP, SANS) to ensure developers build security into the application layer from day one.
  • Source Code Analysis: Lead the strategy for Static Application Security Testing (SAST) and Software Composition Analysis (SCA). You will evaluate tools that automate the detection of vulnerabilities in source code and third-party libraries.
  • CI/CD Integration: Evaluate, recommend, and provide guidance on integrating security tools into the agencies' DevOps pipelines (DevSecOps).
  • Code Quality Oversight: Review and recommend systems that help to boost code quality, ensuring that security is treated as a core component of "clean code."
  • Technology Foresight: Stay abreast of technology changes (e.g., Cloud-native security, AI-driven development) and recommend systems/technologies that enhance code quality and resilience.
  1. Stakeholder Engagement & Advocacy
  • Consultative Leadership: Act as a trusted advisor to Agency CIOs, ACISOs, and Project Owners to educate them and inculcate a culture of secure-by-design.
  • Community of Practice: Establish a platform for knowledge sharing among security practitioners within the Ministry Family to harmonise security testing efforts.
Qualifications & Requirements
Experience
  • Years of Experience: 8 to 10 years of deep technical experience in Cybersecurity, with a strong focus on offensive security and application security.
  • Domain Expertise: Proventrack record in conducting penetration tests for Web Applications, IT Systems (on-premises and cloudenvironments), and complex Network architectures.
  • Code Review Mastery: Experience in performing manual and automated source code reviews toidentifylogic flaws, injection vulnerabilities, and cryptographic weaknesses.
Technical Skills
  • Secure Development: Deep understanding of secure software development lifecycles (SSDLC) and the ability to read/analyze common programming languages (e.g., Java, Python, .NET, JavaScript).
  • Source Code Analysis Tools: Proficiency with enterprise-grade SAST, DAST, SCAand VAPT tools (e.g., Checkmarx, Fortify, SonarQube, Snyk, Burp Suite).
  • Offensive Security: Proficiency in manual and automated testing tools; deep understanding of the MITRE ATT&CK framework and common TTPs.
  • Cloud & DevOps: Experience with Government Commercial Cloud (GCC) environments and practical knowledge of Jenkins, GitLab CI, or GitHub Actions.
  • Certifications: Professional certifications such as OSCP, OSWE (Offensive Security Web Expert), CASE (Certified Application Security Engineer), or GWEB are highly desirable.
Soft Skills
  • Influence & Diplomacy: Ability to communicate complex technical risks to non-technical stakeholders (CIOs/Project Owners) and influence change without direct reporting lines.
  • Analytical Mindset: Ability to spot patterns in "bad" testing jobs or recurring code vulnerabilities and provide constructive feedback to improve agency-level performance.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Cybersecurity Operations Specialist
Senior Cybersecurity Operations Specialist

Government Technology Agency • Singapore

On-site
SGD 150,000 - 190,000
Senior Cybersecurity Operations Specialist
Senior Cybersecurity Operations Specialist

GovTech Singapore • Singapore

On-site
SGD 180,000 - 240,000
Senior Cybersecurity Governance Specialist
Senior Cybersecurity Governance Specialist

Government Technology Agency • Singapore

On-site
SGD 180,000 - 260,000
Senior Cybersecurity Governance Specialist
Senior Cybersecurity Governance Specialist

GovTech Singapore • Singapore

On-site
SGD 120,000 - 180,000
Senior Cybersecurity GRC Leader: Zero Trust Risk Strategy
Senior Cybersecurity GRC Leader: Zero Trust Risk Strategy

GovTech Singapore • Singapore

On-site
Confidential
Cybersecurity Engineer, BCA
Cybersecurity Engineer, BCA

Government Technology Agency • Singapore

Hybrid
SGD 90,000 - 120,000
Flexible work arrangements
Wellness programs
Total rewards approach
Senior/ Lead Cybersecurity Engineer, TradeNet
Senior/ Lead Cybersecurity Engineer, TradeNet

GovTech Singapore • Singapore

On-site
SGD 120,000 - 180,000
Lead Cybersecurity Engineer
Lead Cybersecurity Engineer

GovTech Singapore • Singapore

On-site
SGD 180,000 - 260,000
Lead Cybersecurity Engineer
Lead Cybersecurity Engineer

Government Technology Agency • Singapore

On-site
SGD 180,000 - 260,000
Flexible work arrangements
Total rewards and wellbeing programs
Cybersecurity Engineer, BCA
Cybersecurity Engineer, BCA

GovTech Singapore • Singapore

On-site
SGD 60,000 - 100,000