GovTech is the lead agency driving Singapore’s Smart Nation initiatives and public sector digital transformation. As the Centre of Excellence for Infocomm Technology and Smart Systems (ICT & SS), GovTech develops the Singapore Government’s capabilities in Data Science & Artificial Intelligence, Application Development, Smart City Technology, Digital Infrastructure, and Cybersecurity.
AtGovTech, we offer you a purposeful career to make lives better where we empower our people to master their craft through robust learning and development opportunities all year round.
Play a part in Singapore’s vision to build a Smart Nation and embark on your meaningful journey to build tech for public good. Join us to advance our mission and shape your future with us today!
Learn more aboutGovTechat tech.gov.sg.
What you will be working on
About TradeNet
TradeNet is Singapore’s National Single Window for trade permit processing. It processes over 9 million permit applications annually across import, export and transshipment. As one of Singapore’s key trade systems, TradeNet is being brought in-house to strengthen technology ownership and long-term sustainability.
How we build
Designated as critical IT infrastructure, we favor simple, durable technology choices over the latest trends. We prioritize systems that are easy to reason about, operate, and maintain for the long term.
We operate with high autonomy. Engineers are expected to think deeply, exercise sound judgement, and take ownership of technical decisions. You own the code from technical design through to production. We practice and value honest feedback, practical decision-making and real impact.
We are seeking a Lead Cybersecurity Engineer to oversee technical design and execution for the TradeNet CII modernization—driving architectural security, secure coding, DevSecOps practices, and platform reliability.
In this role, you will write code, implement CI/CD security controls, embed protectivemechanisms into system blueprints, delineate core infrastructure requirements, and partner withthe Customs ACISO to meet CSA CII obligations
Success in this role means deploying a platform that is defensible and reliable by design, ratherthan relying on reactive fixes.
Secure and resilient architecture (core mandate)
- Own the reference security architecture for the TradeNet CII: trust boundaries, identity architecture, segmentation and trust-zone strategy, east-west controls, encryption and key management, and blast-radius containment for the CII boundary.
- Embed secure-by-design controls by working inside product and engineering teams through the delivery lifecycle — at design, solutioning and implementation time, not as post-build validation.
- Maintain a living threat model per system and trust boundary, referenced to MITRE ATT&CK and to relevant adversary classes (including supply-chain and nation-state), and use it to drive architecture and segmentation decisions — not merely to prioritise remediation.
Resilience and national trade continuity
- Engineer the platform's recoverability and graceful degradation: degraded-mode operation, recovery objectives appropriate to a national single-window, and containment design that preserves trade continuity under attack.
- Map and treat dependency and concentration risk across the TradeNet ecosystem (traders, brokers, ports, and partner agencies), including third-party and supply-chain integration risk.
- Design for, and participate in, CSA-mandated cyber resilience exercising for the CII, feeding findings back into the architecture.
Defensive terrain (with the Customs ACISO)
- Partner the Customs ACISO as the technical design authority enabling the agency to discharge CII accountability to CSA: design the Customs digital terrain and CII boundary with multi-layered defence, and translate regulatory obligation into architecture rather than into compliance tasks.
- Co-develop the defensible architecture and resilience narrative the ACISO relies on for CSA engagement, audits, and CII regulatory submissions.
Platform leverage and control inheritance
- Determine and document what the CII inherits from the GovTech security tech stack (e.g. GCC, central SOC/monitoring, ShipHats pipeline guardrails, IM8 baseline controls) versus what the TradeNet product team must build and own.
- Maintain the shared-responsibility delineation as an architectural artefact that also scopes CII audit boundaries, so inherited controls are not re-attested.
Continuous assurance and secure delivery
- Express security control intent as code: pipeline guardrails, policy-as-code, and continuous control monitoring designed into the platform so conformance is observable continuously rather than reconstructed for audits.
- Champion secure SDLC and agile security practice within the delivery cadence, embedded in engineering teams rather than gating them.
Transitional / Day-2 scope (explicitly secondary)
The following areas are transitional and secondary to the core role. Operational validation sits with an independent assurance line to preserve control independence; the Lead Cybersecurity Engineer provides engineering guidance rather than self-validation:
- Advisory and incident-response engineering support in coordination with SIRO, ACISO, and GCSOC.
- Scoping and engineering guidance for external VAPT and vulnerability assessment, with closure validation performed independently.
What we are looking for
- A minimum of 10 years of engineering experience in software security, distinct from purely advisory, compliance, or incident response capacities.
- A practitioner who builds and writes code directly, implements DevSecOps automation and pipeline security, mentors developers on secure coding and defensive programming, and evaluates technical tooling—rather than purely advisory, policy, or compliance roles.
- Proven track record in building defensive controls into critical or government-scale platforms, beyond standard auditing or penetration testing.
- Deep familiarity with national security governance structures, specifically CSA CCoP v2 and WOG IM8, turning mandates into functional designs and delineating inherited boundaries.
- Strong architectural judgment to evaluate system failure modes, trade continuity, and supply-chain risks.
- Extensive experience across cloud environments, zero-trust patterns, cryptosystems, network isolation, and automated policy guardrails.
- Experience using threat models (including MITRE ATT&CK, ISO 27001, and CIS standards) to guide defensive design.
- Ability to serve as technical design lead with the ACISO to establish defensible security specifications.
- Hands‑on DevSecOps and automation skill set, integrating policy enforcement and security tooling into CI/CD pipelines using languages such as Python, TypeScript, or Shell.
- Hands‑on development experience in Kotlin/JVM.
- Hands‑on development experience in Node.js environments.
- Hands‑on experience with penetration testing, vulnerability assessments, and security tooling, applying offensive and defensive hacking methodologies to identify and mitigate security risks.
Good to have
- Relevant certifications in enterprise security architecture (e.g. CISSP-ISSAP or SABSA) are preferred over strictly offensive certifications.
- Must successfully satisfy national security vetting credentials required for Critical Information Infrastructure access.
- Depending on operational requirements, working from designated premises during core operating hours may apply.
What we offer you:
GovTechis an equal opportunity employer committed to fostering an inclusive workplace that values diverse voices and perspectives, as we believe that diversity is the foundation to innovation.
Our employee benefits are based on a total rewards approach, offering a holistic and market-competitive suite ofperks. These include leave benefits to meet your work-life needs and employee wellness programs.
We champion flexible work arrangements (subject to your job role) and trust that you will manage your own time to deliver your best, wherever you are, and whatever works best for you.
Learn more about life insideGovTechat go.gov.sg/GovTechCareers.
Stay connected with us on social media at go.gov.sg/ConnectWithGovTech