Senior / IT Security Consultant (Cybersecurity Governance & Assurance)

Central Provident Fund Board

Singapore

Hybrid

SGD 120,000 - 180,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Hybrid work model
Annual leave
Pro-family leave
Medical and dental benefits

Job summary

Central Provident Fund Board in Singapore is seeking a Security Consultant in our Cybersecurity Governance & Assurance team to safeguard CPF systems used by millions.

You will conduct risk assessments, advise stakeholders, assess AI-related risks, and coordinate penetration testing, vulnerability management, and regulatory reviews in a hybrid work setup.

Qualifications

  • Experience in cybersecurity risk assessments and assurance activities.
  • Familiarity with standards such as NIST, ISO 27001 and regulatory requirements.
  • Ability to translate findings into practical risk recommendations.

Responsibilities

  • Conduct cybersecurity risk assessments and security testing across systems and cloud environments.
  • Provide risk and assurance advice to stakeholders and implement controls.
  • Plan and coordinate penetration testing and remediation activities.
  • Collaborate on audits, regulatory assessments and policy development.

Skills

Cybersecurity
Risk assessment
Security governance
Penetration testing
Python scripting

Education

Bachelor's degree in a relevant field

Tools

Burp Suite
Nmap
OWASP

Job description

What the role is:

At #TeamCPF, you’re not just joining a team; you are embracing a culture of excellence, collaboration, and meaningful impact. You will play a pivotal role in empowering over 4 million members to secure their retirement, healthcare, housing needs and better navigate life’s uncertainties.We thrive on sharp minds and insightful decisions. Your ability to analyse and think critically isn't just valued; it's essential. Every choice you make contributes to our collective success.Collaboration is our way of life. We believe in the power of effective partnerships and seamless communications across teams. Together, we amplify each other’s strengths and achieve remarkable results.Our learning never stops. We encourage your inquisitiveness and courage to embrace new challenges head-on. Your agility, readiness to challenge conventions, embrace of data-driven strategies, dedication to learning and applying new skills fuels our innovation and progress.At the core of everything we do lies a genuine desire to make a difference. We serve our community and support each other with compassion, empathy, and unwavering dedications. Every action we take is guided by a deep sense of purpose and a commitment to those we serve.Join us at #TeamCPF! Together, let's redefine possibilities and leave a legacy that echoes for generations.

What you will be working on:

As a Security Consultant in our Cybersecurity Governance & Assurance team, you will play an important role in safeguarding the systems and information that millions of CPF members rely on for their retirement, healthcare and housing needs.You will contribute to strengthening CPF Board’s cybersecurity governance, risk management and assurance capabilities, helping to ensure that cybersecurity risks are effectively identified, assessed and managed. Working with stakeholders across the organisation, you will provide cybersecurity advice, conduct security assessments and assurance activities, and support the continuous improvement of the Board’s cybersecurity posture and resilience.

In this role, you will:

  • Conduct cybersecurity risk assessments and security assurance activities across systems, applications, infrastructure, cloud environments and technology initiatives to identify security risks, vulnerabilities and control gaps, assess the adequacy and effectiveness of cybersecurity controls and recommend appropriate risk treatment and remediation measures.
  • Provide cybersecurity risk and assurance advice to system owners, project teams and other stakeholders, translating findings into practical recommendations and supporting the implementation of appropriate security controls and mitigation measures.
  • Assess cybersecurity risks arising from new and emerging technologies, including Artificial Intelligence (AI) and Generative AI (GenAI), as well as new solutions and changes to existing systems across application, infrastructure, network, cloud and security architecture, and contribute to the development of appropriate security, risk management and assurance measures to strengthen resilience and support secure adoption.
  • Plan, coordinate and conduct penetration testing and security testing of applications, infrastructure, networks, cloud environments and other technology solutions, working with relevant stakeholders and external security testing providers, where appropriate, to address relevant cybersecurity risks and attack scenarios, identify vulnerabilities and validate the effectiveness of security controls.
  • Analyse and validate penetration testing findings, assess their exploitability and cybersecurity risk, perform or coordinate retesting and validation to ensure identified security vulnerabilities are adequately addressed.
  • Leverage penetration testing results together with vulnerability assessments, threat intelligence, External Attack Surface Management (EASM), Adversarial Exposure Validation (AEV) and other technical security assessments to identify systemic security weaknesses and strengthen cybersecurity assurance.
  • Explore the use of scripting, automation and data analytics, including Python where appropriate, to improve the efficiency and effectiveness of cybersecurity risk assessment, assurance, monitoring and reporting activities.
  • Support and participate in internal and external cybersecurity audits, reviews and regulatory assessments, including the coordination, assessment and remediation of findings.
  • Assess compliance with applicable cybersecurity policies, standards, regulatory requirements and industry frameworks, and recommend improvements where necessary.
  • Develop, review and enhance cybersecurity policies, standards, procedures and governance frameworks to address evolving cybersecurity risks, regulatory requirements, emerging technologies and organisational needs.
  • Contribute to the continuous improvement of cybersecurity governance, risk and assurance methodologies, processes, tools and capabilities, including the adoption of threat-informed and risk-based approaches.
What we are looking for:

We value the diverse talents and experiences that each individual brings to the table. While mastery of every requirement may not be necessary, familiarity and expertise in some of the following areas will position you for success within this team.

Cybersecurity Governance & Assurance
  • Relevant experience in cybersecurity, information security, technology risk, security assurance, cybersecurity governance or related areas.
  • Experience in conducting cybersecurity risk assessments, security reviews, control assessments and/or other security assurance activities, and recommending appropriate risk treatment and remediation measures.
  • Good understanding of cybersecurity risks, threats, vulnerabilities and security controls, with the ability to assess how these may affect systems, applications, infrastructure, network, security architecture and technology environments.
  • Ability to assess cybersecurity issues and translate technical findings, vulnerabilities and control weaknesses into clear risk implications and practical recommendations.
  • Familiarity with relevant cybersecurity standards, frameworks and regulatory requirements, such as the NIST Cybersecurity Framework, ISO/IEC 27001, CIS Controls, Singapore Government Instruction Manuals, and applicable cybersecurity legislation, Codes of Practice and regulatory requirements.
  • Good analytical, problem-solving and stakeholder management skills, with the ability to evaluate cybersecurity risks and controls in the context of business, technology and operational requirements, and communicate cybersecurity risks and recommendations effectively to both technical and non-technical stakeholders.
  • Adaptable, inquisitive and keen to broaden cybersecurity expertise through exposure to different areas of cybersecurity risk, assurance, governance and emerging technologies.
  • Awareness of emerging cybersecurity threats and technologies, including developments relating to Artificial Intelligence (AI) and Generative AI (GenAI), and an interest in understanding their cybersecurity risks and implications.
Penetration Testing & Security Assessment
  • Experience or knowledge in penetration testing, vulnerability assessment or security testing, including the identification, validation and assessment of security vulnerabilities.
  • Good understanding of common application, infrastructure, network and cloud security vulnerabilities, attack techniques and security controls, including familiarity with frameworks and references such as the OWASP Top 10, OWASP Web Security Testing Guide (WSTG), MITRE ATT&CK and CVSS.
  • Familiarity with penetration testing methodologies and commonly used security testing tools, such as Burp Suite, Nmap, vulnerability scanners and other relevant security assessment tools.
  • Ability to analyse penetration testing and vulnerability assessment findings, assess their exploitability, potential impact and cybersecurity risk, and translate technical findings into practical remediation recommendations.
  • Ability to document and communicate security testing findings clearly to both technical and non-technical stakeholders and work with system owners and technical teams to address identified vulnerabilities.
Experience or knowledge in one or more of the following areas would be an advantage:
  • Hands-on experience conducting web application, API, mobile application, infrastructure, network, Active Directory or cloud penetration testing.
  • Experience in Red Teaming, Purple Teaming, adversarial security testing or threat-informed security assessments, including the use of realistic attack scenarios to evaluate security controls.
  • Experience with External Attack Surface Management (EASM), Adversarial Exposure Validation (AEV), breach and attack simulation or continuous security validation approaches.
  • Experience analysing and validating complex vulnerabilities, attack paths and chained security weaknesses beyond automated vulnerability scanning.
  • Knowledge of scripting or programming languages such as Python, PowerShell or other relevant languages for security testing, data analysis or automation.
  • Relevant offensive security or penetration-testing certifications, such as OSCP, OSWA, OSWE, CREST certifications, GPEN, or equivalent professional certifications.
  • Relevant cybersecurity such as CISSP, CCSP, CISM, CRISC, CISA, ISO/IEC 27001, or equivalent certifications, would be advantageous.

The seniority of appointment and actual corporate job title will commensurate with individual work experiences.

Position is on a 2-year full-time contract directly under the payroll of CPF Board with potential for emplacement into a permanent position.

What you can expect
  • Opportunities to engage in a mix of formal and informal training, keeping your skills sharp in our ever-evolving technological landscape.
  • Promotion opportunities based on your capability and on-the-job performance.
  • A vibrant community of like-minded and friendly colleagues, where collaboration and creativity thrive.
  • A hybrid work model that offers flexibility for remote work, subject to exigencies of service.
  • Flexible dress code that empowers you to choose your appropriate outfit for the day.
  • A comprehensive rewards package that includes annual leave, pro-family leave, medical and dental benefits, and access to recreational activities.
About Central Provident Fund Board

Central Provident Fund (CPF) Board is the cornerstone of Singapore's social security system, committed to serving and empowering over 4 million members in securing their retirement, healthcare, and housing needs. As an employer, we believe in developing our people to do their life’s best work through the 3Ps: Purposeful Work, Professional Growth, People & Culture.Purposeful Work – Beyond being a pension fund, we are unique in being a national social security organisation, and we serve CPF members knowing that our work we make a difference.Professional Growth – At CPF Board, you will have the opportunity to learn on the job, acquire new skills, and broaden your knowledge. Although you are joining one organisation, you will have access to many career paths in the years ahead.People and Culture – When you join CPF Board, you become part of a mission-oriented organisation with a strong culture of teamwork, collaboration, and innovation. Our people are our greatest asset, and we champion a culture of respect, diversity, and inclusivity, where every voice is heard and contributions are recognised and celebrated.We are a recipient of the Enabling Mark (Platinum) by SG Enable, we welcome candidates with disabilities and are committed to providing an inclusive and supportive work environment.Come and be a part of #TeamCPF today, to make a difference in the lives of others and in the future of Singapore. To learn more about CPF Board, visit our website at www.cpf.gov.sg.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Business Auditor
Senior Business Auditor

Central Provident Fund Board • Singapore

Hybrid
SGD 80,000 - 140,000
Hybrid work
Annual leave
Medical benefits
+3
Senior/Lead Consultant (Quality Engineering)
Senior/Lead Consultant (Quality Engineering)

Central Provident Fund Board • Singapore

Hybrid
SGD 120,000 - 180,000
Hybrid work model
Medical and dental benefits
Annual leave
Graduate Technology Consultant (NextGen Programme)
Graduate Technology Consultant (NextGen Programme)

Central Provident Fund Board • Singapore

Hybrid
SGD 42,000 - 56,000
Hybrid work model
Medical and dental benefits
Annual leave & pro-family leave
[2027 H1 Term-time Internship] Cloud Infra Engineer Intern
[2027 H1 Term-time Internship] Cloud Infra Engineer Intern

Central Provident Fund Board • Singapore

Hybrid
SGD 13,000 - 27,000
Hybrid work model
Annual leave
Medical benefits
+3
[2027 H1 Term-time Internship] Application Developer Intern (CDS)
[2027 H1 Term-time Internship] Application Developer Intern (CDS)

Central Provident Fund Board • Singapore

Hybrid
SGD 18,000 - 24,000
Hybrid work model
Annual leave
Medical and dental benefits
[2027 H1 Term-time Internship] Strategy & International Engagement Intern
[2027 H1 Term-time Internship] Strategy & International Engagement Intern

Central Provident Fund Board • Singapore

Hybrid
SGD 10,000 - 17,000
Formal and informal training
Promotion opportunities
Hybrid work model
+4
[2027 H1 Term-time Internship] Leadership Development Intern
[2027 H1 Term-time Internship] Leadership Development Intern

Central Provident Fund Board • Singapore

Hybrid
SGD 20,000 - 26,000
Annual leave
Pro-family leave
Medical and dental benefits
+1
[2027 H1 Term-time Internship] Data Analytics Intern
[2027 H1 Term-time Internship] Data Analytics Intern

Central Provident Fund Board • Singapore

Hybrid
SGD 20,000 - 27,000
Hybrid work model
Formal and informal training
Annual leave
+1
Policy Administration Executive (Home Protection Scheme)
Policy Administration Executive (Home Protection Scheme)

Central Provident Fund Board • Singapore

Hybrid
SGD 40,000 - 60,000
Hybrid work model
Training opportunities
Promotion opportunities
+1
[2027 H1 Term-time Internship] GenAI Engineering Intern
[2027 H1 Term-time Internship] GenAI Engineering Intern

Central Provident Fund Board • Singapore

Hybrid
SGD 12,000 - 19,000
Annual leave
Pro-family leave
Medical benefits
+3