Senior/ Lead Cybersecurity Engineer, TradeNet

GovTech Singapore

Singapore

On-site

SGD 120,000 - 180,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

GovTech Singapore is seeking a Cybersecurity Engineer to act as the security SME for a critical national digital platform. You will translate policy requirements into practical technical controls and work closely with product and engineering teams in an agile delivery setting.

Responsibilities include assessing security controls across IaaS/PaaS/SaaS, managing security appliances, triaging OWASP findings, and ensuring secure SDLC practices while mapping controls to ISO 27001/NIST/CIS benchmarks.

Qualifications

  • Minimum 5 years of professional experience in cybersecurity engineering, with hands-on work in security operations, risk assessment, or compliance within cloud environments.
  • Working knowledge of Singapore-specific regulatory frameworks: WOG IM8 Reform and CSA CCOPv2 for Critical Information Infrastructure.
  • Hands-on experience with security technologies such as SIEM, CSPM, ASM, WAF, and vulnerability management tools.
  • Familiarity with cybersecurity frameworks and standards including OWASP, MITRE ATT&CK, ISO 27001, NIST, and CIS benchmarks.
  • Ability to communicate technical security concepts to policy and compliance stakeholders, and translate compliance requirements into engineering-actionable tasks.
  • Pragmatic decision-making: able to balance security requirements with delivery timelines and business needs.
  • Experience supporting audit cycles and producing compliance evidence.
  • Proficiency in at least one scripting language (e.g., Python, PowerShell, YARA) for automation and tooling.
  • Relevant certifications such as GCIH, GCFA, OSCP, CISSP, or AWS Security Specialty are advantageous.
  • Ability to conduct in-house VAPT is a strong plus.

Responsibilities

  • Translate policy requirements into implementable technical controls for cloud-based platforms.
  • Triage security findings against OWASP Top 10 and coordinate retesting with product and engineering teams.
  • Ensure secure SDLC practices across the delivery lifecycle.
  • Translate CSA Cybersecurity Act and WOG IM8 high-risk cloud requirements into actionable controls.
  • Log and assess advisories, track remediation, and ensure closure.
  • Conduct security risk assessments and map controls to compliance frameworks (ISO 27001, NIST, CIS).
  • Support internal and external audits with evidence gathering and coordination.
  • Perform threat modelling and participate in offensive/defensive security operations as needed.
  • Engage stakeholders to align regulatory requirements with engineering decisions and drive remediation.

Skills

Cybersecurity engineering
Security operations
Risk assessment
Compliance
Cloud security

Tools

SIEM
CSPM
ASM
WAF
Vulnerability management

Job description

GovTech is the lead agency driving Singapore’s Smart Nation initiatives and public sector digital transformation. As the Centre of Excellence for Infocomm Technology and Smart Systems (ICT & SS), GovTech develops the Singapore Government’s capabilities in Data Science & Artificial Intelligence, Application Development, Smart City Technology, Digital Infrastructure, and Cybersecurity.

At GovTech, we offer you a purposeful career to make lives better where we empower our people to master their craft through robust learning and development opportunities all year round.

Play a part in Singapore’s vision to build a Smart Nation and embark on your meaningful journey to build tech for public good. Join us to advance our mission and shape your future with us today!

Learn more about GovTech at tech.gov.sg.

[What you will be working on]

We are seeking a Cybersecurity Engineer to serve as the security SME for a critical national digital platform. This role sits at the intersection of engineering delivery and regulatory compliance. You will translate policy requirements (IM8 Reform, CSA CCOPv2) into implementable technical controls while working shoulder-to-shoulder with product and engineering teams in an agile delivery environment.

Cloud & Infrastructure Security
  • Assess and validate security controls across IaaS/PaaS/SaaS environments, covering identity management, encryption, and network segmentation.
  • Govern security appliance policy and rule changes (WAF, DAM, Firewalls), including oversight of vendor operations and change management.
Application Security
  • Triage application security findings against OWASP Top 10, reproduce and validate issues, and coordinate retesting with functional leads or delegates.
  • Ensure adherence to secure SDLC practices across the delivery lifecycle.
Regulatory Compliance & Risk
  • Translate CSA Cybersecurity Act (CII CCOPv2) and WOG IM8 high-risk cloud requirements into actionable technical and process controls.
  • Log and assess GCSOC/GITSIR/agency advisories, determine impact, follow up with functional leads, and track to closure.
  • Manage Vulnerability Disclosure Programme findings end-to-end: triage, coordinate with functional leads, track remediation, and close.
  • Conduct security risk assessments and map technical controls to compliance requirements across relevant frameworks (ISO 27001, NIST, CIS benchmarks).
  • Support internal and external audits, including evidence gathering and coordination with auditors.
Threat Modelling & Offensive/Defensive Operations
  • Conduct threat modelling with reference to the MITRE ATT&CK framework, scoped to the CII landscape.
  • Manage or support offensive and defensive operations, including VAPT, incident response, and incident management.
  • Participate in the design and solutioning of technical setups when new security requirements are introduced, using threat modelling outcomes to prioritize implementation.
Stakeholder Engagement & Delivery
  • Liaise between CSA, Agency CISO stakeholders, and engineering teams — matching regulatory requirements with engineering approaches and design decisions.
  • Drive remediation through engineering teams, not just identify gaps.
  • Manage cross-functional security initiatives from requirements through deployment.
  • Leverage automation for compliance monitoring and evidence collection.
  • Establish and track KPIs for compliance posture and risk reduction.
  • Champion agile security practices within the delivery cadence.
[What we are looking for]
  • Minimum 5 years of professional experience in cybersecurity engineering, with hands-on work in security operations, risk assessment, or compliance within cloud environments.
  • Working knowledge of Singapore-specific regulatory frameworks: WOG IM8 Reform and CSA CCOPv2 for Critical Information Infrastructure.
  • Hands-on experience with security technologies such as SIEM, CSPM, ASM, WAF, and vulnerability management tools.
  • Familiarity with cybersecurity frameworks and standards including OWASP, MITRE ATT&CK, ISO 27001, NIST, and CIS benchmarks.
  • Ability to communicate technical security concepts to policy and compliance stakeholders, and translate compliance requirements into engineering-actionable tasks.
  • Pragmatic decision-making: able to balance security requirements with delivery timelines and business needs.
  • Experience supporting audit cycles and producing compliance evidence.
  • Proficiency in at least one scripting language (e.g., Python, PowerShell, YARA) for automation and tooling.
  • Relevant certifications such as GCIH, GCFA, OSCP, CISSP, or AWS Security Specialty are advantageous.
  • Ability to conduct in-house VAPT is a strong plus.
  • Subject to the nature of your job role that might require you to be onsite during fixed hours.
What we offer you:

GovTech is an equal opportunity employer committed to fostering an inclusive workplace that values diverse voices and perspectives, as we believe that diversity is the foundation to innovation.

Our employee benefits are based on a total rewards approach, offering a holistic and market-competitive suite of perks. These include leave benefits to meet your work-life needs and employee wellness programs.

We champion flexible work arrangements (subject to your job role) and trust that you will manage your own time to deliver your best, wherever you are, and whatever works best for you.

Learn more about life inside GovTech at go.gov.sg/GovTechCareers.

Stay connected with us on social media at go.gov.sg/ConnectWithGovTech

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Engineer, BCA
Cybersecurity Engineer, BCA

GovTech Singapore • Singapore

On-site
SGD 60,000 - 100,000
Cybersecurity Engineer, BCA
Cybersecurity Engineer, BCA

GovTech • Singapore

Hybrid
SGD 90,000 - 130,000
Total rewards approach
Flexible work arrangements
Lead Cybersecurity Engineer
Lead Cybersecurity Engineer

GovTech Singapore • Singapore

On-site
SGD 180,000 - 260,000
Senior DevOps Engineer: Cloud Infra & CI/CD
Senior DevOps Engineer: Cloud Infra & CI/CD

GovTech Singapore • Singapore

On-site
SGD 80,000 - 120,000
Flexible work arrangements
Employee wellness programs
Comprehensive leave benefits
Software Engineer (DevOps), TIC
Software Engineer (DevOps), TIC

GovTech Singapore • Singapore

On-site
SGD 80,000 - 120,000
Flexible work arrangements
Employee wellness programs
Comprehensive leave benefits
Lead Cybersecurity Incident Response Specialist
Lead Cybersecurity Incident Response Specialist

GovTech Singapore • Singapore

On-site
SGD 120,000 - 180,000
Software Engineer, Core Engineering Products
Software Engineer, Core Engineering Products

GovTech Singapore • Singapore

On-site
SGD 90,000 - 150,000
Senior Engineering Manager (TechOps), TradeNet
Senior Engineering Manager (TechOps), TradeNet

GovTech Singapore • Singapore

Hybrid
SGD 180,000 - 260,000
Flexible work arrangements
Total rewards package
Leave benefits
Systems Engineer, Smart City Technology Division
Systems Engineer, Smart City Technology Division

GovTech Singapore • Singapore

On-site
SGD 140,000 - 210,000
Leave benefits
Employee wellness programs
Flexible work arrangements
Lead, Cybersecurity Engineer, Singpass
Lead, Cybersecurity Engineer, Singpass

GovTech Singapore • Singapore

On-site
SGD 180,000 - 240,000
Flexible work arrangements
Total rewards approach
Leave benefits and wellness programs