Your career compass awaits
Create a free account to unlock
- ✓ See how you match this role
- ✓ AI resume tailored to this specific job
- ✓ Inside Track Companion — find your insider contact
- ✓ Skills gap analysis and upskill plan
- ✓ Interview prep kit for this role
- ✓ Relocation concierge — salary, tax, cost of living
Free — no credit card required
Senior/ Lead Cybersecurity Engineer, TradeNet
ICT
Company shared salary
NA
Market rate
NA
Based on similar roles (title + domain + location).
Responsibilities
- ● GovTech is the lead agency driving Singapore's Smart Nation initiatives and public sector digital transformation. As the Centre of Excellence for Infocomm Technology and Smart Systems (ICT & SS), GovTech develops the Singapore Government's capabilities in Data Science & Artificial Intelligence, Application Development, Smart City Technology, Digital Infrastructure, and Cybersecurity.
- ● At GovTech, we offer you a purposeful career to make lives better where we empower our people to master their craft through robust learning and development opportunities all year round.
- ● Play a part in Singapore's vision to build a Smart Nation and embark on your meaningful journey to build tech for public good. Join us to advance our mission and shape your future with us today
- ● Learn more about GovTech at tech.gov.sg.
- ● What you will be working on
- ● We are seeking a Cybersecurity Engineer to serve as the security SME for a critical national digital platform. This role sits at the intersection of engineering delivery and regulatory compliance. You will translate policy requirements (IM8 Reform, CSA CCOPv2) into implementable technical controls while working shoulder-to-shoulder with product and engineering teams in an agile delivery environment.
- ● Cloud & Infrastructure Security
- ● Assess and validate security controls across IaaS/PaaS/SaaS environments, covering identity management, encryption, and network segmentation.
- ● Govern security appliance policy and rule changes (WAF, DAM, Firewalls), including oversight of vendor operations and change management.
- ● Application Security
- ● Triage application security findings against OWASP Top 10, reproduce and validate issues, and coordinate retesting with functional leads or delegates.
- ● Ensure adherence to secure SDLC practices across the delivery lifecycle.
- ● Regulatory Compliance & Risk
- ● Translate CSA Cybersecurity Act (CII CCOPv2) and WOG IM8 high-risk cloud requirements into actionable technical and process controls.
- ● Log and assess GCSOC/GITSIR/agency advisories, determine impact, follow up with functional leads, and track to closure.
- ● Manage Vulnerability Disclosure Programme findings end-to-end: triage, coordinate with functional leads, track remediation, and close.
- ● Conduct security risk assessments and map technical controls to compliance requirements across relevant frameworks (ISO 27001, NIST, CIS benchmarks).
- ● Support internal and external audits, including evidence gathering and coordination with auditors.
- ● Threat Modelling & Offensive/Defensive Operations
- ● Conduct threat modelling with reference to the MITRE ATT&CK framework, scoped to the CII landscape.
⚡ Full Resume Sandbox Canvas