Stand out for this role — generate a tailored resume and cover letter in about a minute.
GovTech Singapore is driving Singapore’s Smart Nation initiatives and the public sector’s digital transformation. We build capabilities in Data Science, AI, application development, smart city tech, digital infrastructure, and cybersecurity to improve public services.
Join GovTech to contribute to governance, risk, and assurance in a modern, impact‑driven environment that designs, builds, tests, and learns with real-world systems for government scale.
GovTech is the lead agency driving Singapore’s Smart Nation initiatives and public sector digital transformation. As the Centre of Excellence for Infocomm Technology and Smart Systems (ICT & SS), GovTech develops the Singapore Government’s capabilities in Data Science & Artificial Intelligence, Application Development, Smart City Technology, Digital Infrastructure, and Cybersecurity.
At GovTech, we offer you a purposeful career to make lives better where we empower our people to master their craft through robust learning and development opportunities all year round.
Play a part in Singapore’s vision to build a Smart Nation and embark on your meaningful journey to build tech for public good. Join us to advance our mission and shape your future with us today!
Learn more about GovTech at tech.gov.sg.
Some problems are easy to walk past. Others keep nagging at you.
Why are we still doing this manually?
Why does sensible policy become painful when it meets the real world?
Why do we discover risks after the fact when the signals were already there?
How should government govern AI systems that increasingly make decisions and take actions for themselves? And why, when technology can change in minutes, does governance sometimes still move in months?
If questions like these bother you enough that you want to get underneath them, experiment with better answers and solve the real-world problem, we should talk.
We are rethinking what modern governance, risk and assurance could look like across GovTech and, ultimately, the wider Singapore Government.
GovTech is where we can design, build, test and learn. The ambition is bigger.
We are modernising Governance, Risk, and Compliance (GRC) so government can use technology and AI with greater confidence, improve services faster, and keep the essential systems people rely on dependable and resilient.
Ultimately, the test is bigger than GRC: Can government use technology better, serve citizens better, and retain their trust when things go wrong?
That is the problem behind this role. And we do not expect to solve it by designing the perfect framework in a room.
We expect to work on real systems, with real users and real constraints. To experiment. Test assumptions. Prototype, understand behavior and incentives. Learn from what does not work.
And turn what does into something that can work at government scale. One role. Multiple archetypes. This is one modern GRC role, not six separate jobs or six career tracks.
The six archetypes below describe different capabilities a Modern GRC Practitioner can develop and create a problem.
You might begin with strength in one. Over time, you can acquire additional archetypes without giving up the ones you already have. An engineer might combine GRC Platform Engineering with Policy Engineering and AI Governance. An assurance practitioner might bring together Threat-Informed Risk Intelligence, Enterprise Risk Management and Systems Architecture. A policy practitioner might combine Policy Engineering with behavioral insights, systems thinking and platform capability.
Which archetypes you draw on depends on the problem. Some practitioners will build deep expertise in one or two. Others will develop a broader combination across several. Neither is a prescribed progression. The archetypes are not boxes to move between. They are capabilities you can accumulate, combine and apply. The ambition is to build practitioners with an increasingly powerful repertoire for understanding and solving difficult problems. Six capabilities you could build and combine.
How do we design policy that survives contact with engineers, users and actual organisational behavior?
Bring together domain expertise, behavioral insights, human-centered design and technology to create controls that people can understand, systems can implement and organisations can actually operate.
A technically correct policy that everyone works around is not a successful policy.
How do we help leaders decide which risks matter, what needs intervention and what we can deliberately live with? Connect signals across the organisation, expose dependencies and concentration risks, translate risk appetite into practical choices and bring better analysis to difficult decisions.
The output is not another register. It is a better decision.
How do we make governance and assurance part of the delivery environment rather than another checkpoint around it? Build Policy-as-Code, automated evidence, continuous control verification and other infrastructure that makes safer behavior easier and assurance more timely.
Sometimes the answer is automation. Sometimes the smarter answer is removing the process first.
What can an AI agent decide? Where must humans intervene? How should decision boundaries, accountability and assurance work when autonomous systems act at scale?
How do we govern model drift, changing behavior and GRC's own use of AI? Some answers exist. Many do not. You could help develop them.
How do we understand what is changing now rather than explain months later what went wrong? Connect cyber, data, resilience, platform, supply‑chain and operational signals to identify patterns and emerging risks earlier.
Less: “Did the control pass?” More: “Is it working now, what changed, and what does that tell us?”
How do policy, risk, controls, evidence, engineering and assurance fit together?
Design the taxonomies, information flows, feedback loops and operating models that allow them to work as one system. Ask some people about one control and they will explain the other three things it affects.
We like those people.
Sometimes the answer is better policy. Sometimes automation. Sometimes a different operating model. Occasionally, the right answer is to stop doing something altogether.
The expectation is not to challenge everything. It is to know what deserves to be challenged, why, and what should replace it.
That is part of the work.
Investigate before recommending. Prototype before standardising. Sit with engineers and users before writing policy. Use evidence before forming conclusions. Connect signals that others have not put together. And be willing to change your mind when your first hypothesis is wrong. We consider that progress.
Success is not the number of policies, findings, reports or dashboards produced. We are making progress when:
And ultimately: Government uses technology better, essential services remain dependable, and citizens experience better public services without sacrificing trust. That is the measure that matters.
There is no single background we are looking for.
You may come from engineering, cybersecurity, risk, assurance, resilience, AI, architecture, digital policy, product delivery, behavioural science, service design, design research, or somewhere less obvious.
Depth matters. But so does what happens when you reach the edge of what you know.
For some of the problems we are tackling, the answer does not exist yet. That is precisely what makes them worth working on.
If you are looking for a mature playbook, tightly defined boundaries and a portfolio that mainly needs maintaining, there are probably better roles. This work involves ambiguity, experimentation, difficult trade-offs and the occasional failed idea. But if a stubborn problem bothers you enough that you want to understand it, challenge assumptions and build something better, we should probably have a conversation.
GovTech is in an unusual position. We help shape government technology policy. We build and operate major digital platforms. We can engineer governance and assurance into real delivery environments. We can test ideas against real-world problems and see whether they actually work. And what works here can become capability that benefits the wider Singapore Government.
So, this is not simply a chance to practice GRC differently. It is a chance to help discover what modern governance, risk and assurance needs to become.
GovTech is an equal opportunity employer committed to fostering an inclusive workplace that values diverse voices and perspectives, as we believe that diversity is the foundation to innovation.
Our employee benefits are based on a total rewards approach, offering a holistic and market-competitive suite of perks. These include leave benefits to meet your work-life needs and employee wellness programs.
We champion flexible work arrangements (subject to your job role) and trust that you will manage your own time to deliver your best, wherever you are, and whatever works best for you.
Learn more about life inside GovTech at go.gov.sg/GovTechCareers.
Stay connected with us on social media at go.gov.sg/ConnectWithGovTech