Description
[What the role is]
GovTech is the lead agency driving Singapore’s Smart Nation initiatives and public sector digital transformation. As the Centre of Excellence for Infocomm Technology and Smart Systems (ICT & SS), GovTech develops the Singapore Government’s capabilities in Data Science & Artificial Intelligence, Application Development, Smart City Technology, Digital Infrastructure, and Cybersecurity.
At GovTech, we offer you a purposeful career to make lives better where we empower our people to master their craft through robust learning and development opportunities all year round.
Play a part in Singapore’s vision to build a Smart Nation and embark on your meaningful journey to build tech for public good. Join us to advance our mission and shape your future with us today!
Learn more about GovTech at tech.gov.sg.
[What you will be working on]
The Cyber Security Group (CSG) is the cybersecurity arm of GovTech. CSG is committed to create a digital government that is safe and secure. CSG delivers technical and operational capabilities to counteract cyber threats, provides thought leadership on transformative cybersecurity governance and policies and to strengthen the cybersecurity posture of government agencies in a manner that is sustainable, pragmatic, and effective.
To enhance infocomm security capabilities in GovTech and the Whole-of-Government (WOG), GovTech appoints Chief Information Security Officer (CISO) teams at the various ministries to oversee infocomm security management.
Reporting to the Ministry CISO (MCISO), you will be the primary architect of the Ministry’s security governance and risk management framework. You will ensure that all agencies within the Ministry Family operate under a unified, effective, and modern security standard. Your mission is to transform GRC from a compliance-heavy exercise into a strategic enabler. You will establish the frameworks that allow the Ministry Family to adopt new technologies with confidence, moving away from a "risk-averse" posture toward a "risk-informed" one. You will ensure that risk management is deeply integrated into the lifecycle of every digital system, from web applications to critical Operational Technology (OT) environments.
Key Responsibilities
- Enterprise Risk Governance & Management
- Dynamic Risk Registers: Establish and oversee the Ministry-wide security risk register. You will ensure that registers are not static documents but "living" tools that accurately reflect the current threat landscape and project status across all agencies.
- Senior Management Facilitation: Lead and facilitate high-level risk conversations with Senior Management and Agency CIOs. You must be able to translate complex technical risks into clear business impacts to drive informed resource allocation and prioritisation.
- Risk Analysis Framework: Develop a robust framework to guide agencies in performing consistent, high-quality risk analysis. This framework should empower agencies to take calculated risks for innovation rather than defaulting to "no" due to risk aversion.
- Threat Risk Assessment (TRA) & Standards
- Unified TRA Framework: Establish and maintain Ministry-wide standards for conducting Threat Risk Assessments across diverse domains, including Cloud (GCC), Web Applications, and OT/ICS systems.
- Crown Jewel Identification: Develop SOPs to guide agency project teams in identifying "Crown Jewels" (Critical Information Assets) and mapping comprehensive threat vectors.
- Standardisation of Controls: Define common security configuration standards and ensure that controls are technically effective in mitigating identified risks, rather than just meeting baseline requirements.
- Zero Trust & Architecture Governance
- Zero Trust Roadmap: Lead the establishment of a Ministry-wide Zero Trust Framework, setting the standards for identity-based security, micro-segmentation, and "never trust, always verify" architectures.
- Architectural Advisory: Provide expert GRC input during the design phase of high-impact systems to ensure security-by-design and alignment with Ministry standards.
- Technology Application: Evaluate and recommend security technologies that effectively mitigate specific risks, ensuring that defensive layers remain relevant against modern threats.
- Supply Chain & Ecosystem Risk Management
- Third-Party Risk Strategy: Establish the framework for managing risks across the software supply chain and IT vendors.
- Dependency & Vendor Risk: Develop standards for assessing the cyber-resilience of third-party partners and managing risks associated with software dependencies (e.g., Open Source libraries).
- Audit Excellence & Systemic Improvement
- Proactive Readiness: Shift agencies from "reactive" audit preparation to a state of continuous compliance and readiness.
- Root Cause Rectification: Oversee the closure of audit findings, ensuring agencies implement substantive, effective technical fixes rather than surface-level measures.
Similar jobs
GovTech is the lead agency driving Singapore’s Smart Nation initiatives and public sector digital transformation. As the Centre of Excellence for Infocomm Technology and Smart Systems (ICT & SS), GovTech develops the…
GovTech is the lead agency driving Singapore’s Smart Nation initiatives and public sector digital transformation. As the Centre of Excellence for Infocomm Technology and Smart Systems (ICT & SS), GovTech develops the…
Est. 124,000 USD
Step into a career with ASM, where cutting edge technology meets collaborative culture. For over 55 years ASM has been ahead of what’s next, at the forefront of innovation and what’s technologically possible. With more…
About Nebius: Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from data and model training through to…
Sr. Security Engineer - IAM Truveta provides unprecedented real-world data and real-time intelligence, powered by a dataset built with and owned by US health systems united in a mission of Saving Lives with Data. Togethe…
Est. 120,000 USD
At NiCE, we don’t limit our challenges. We challenge our limits. Always. We’re ambitious. We’re game changers. And we play to win. We set the highest standards and execute beyond them. And if you’re like us, we can offer…
Role Purpose The Deputy Director (DD), Government Incident Reporting Ops, leads a high-performing operational team responsible for centralizing, assessing, and managing the full spectrum of Whole-of-Government (WOG) inci…
Why Choose Bottomline? Are you ready to transform the way businesses pay and get paid? Bottomline is a global leader in business payments and cash management, with over 35 years of experience and moving more than $16 tri…
Truveta provides unprecedented real-world data and real-time intelligence, powered by a dataset built with and owned by US health systems united in a mission of Saving Lives with Data. Together, we power breakthrough med…
GovTech supports various Government Agencies in carrying out ICT delivery services and appoints Agency Chief Information Security Officers (ACISO) to oversee information security management within these agencies. The ACI…
GovTech is the lead agency driving Singapore’s Smart Nation initiatives and public sector digital transformation. As the Centre of Excellence for Infocomm Technology and Smart Systems (ICT & SS), GovTech develops the…
Truveta provides unprecedented real-world data and real-time intelligence, powered by a dataset built with and owned by US health systems united in a mission of Saving Lives with Data. Together, we power breakthrough med…
Est. 124,000 USD
About Lucid At Lucid, we are creating exceptional mobility experiences through innovation to drive the world forward. Built on Lucid’s proprietary technology and software-defined vehicle architecture, our award-winning v…
Est. 115,000 USD
Cordance is dedicated to accelerating the growth of vertically focused business-to-business (B2B) software-as-a-service (SaaS) companies through acquisition and long-term tactical and financial guidance. We’re experience…
Est. 80,000 GBP
About Baringa Baringa is a global consulting firm that partners with leaders to drive change and create value. With deep industry expertise, and enabled by advanced technology, the firm helps clients to deliver with grea…
Est. 115,000 USD
About Nebius: Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from data and model training through to…
To enhance infocomm security capabilities in GovTech and the whole-of-government, GovTech will be appointing Chief Security Information Officers (CISO) at the various ministries to oversee infocomm security management. T…
Est. 85,000 EUR
About Nebius: Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from data and model training through to…
Est. 90,000 GBP
dunnhumby is the global leader in Customer Data Science, partnering with the world’s most ambitious retailers and brands to put the customer at the heart of every decision. We combine deep insight, advanced technology, a…
Est. 80,000 USD
ESSENTIAL JOB RESPONSIBILITIES include but are not limited to: Supports and demonstrates IMA’s core values Values and understands the importance of diversity, equity, and inclusion among all IMA associates
About Nebius: Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from data and model training through to…
Overview: We are looking for a Senior Technical Product Manager (TPM) to support delivery across Guidepoint's AI Platform and Data Products initiatives. This role will partner closely with Product, Engineering, Operation…
Truveta provides unprecedented real-world data and real-time intelligence, powered by a dataset built with and owned by US health systems united in a mission of Saving Lives with Data. Together, we power breakthrough med…
The Government Technology Agency (GovTech) is the lead agency driving Singapore’s Smart Nation initiatives and public sector digital transformation. As the Centre of Excellence for Infocomm Technology and Smart Systems (…
Est. 250,000 USD
We’re looking for a Principal Architect to lead the design and delivery of complex, multi-domain systems spanning cloud, data, and AI. This role is ideal for a deeply experienced engineer who owns the hardest architectur…
Est. 140,000 USD
Black Duck Software, Inc. helps organizations build secure, high-quality software, minimizing risks while maximizing speed and productivity. Black Duck, a recognized pioneer in application security, provides SAST, SCA, a…
Black Duck Software, Inc. helps organizations build secure, high-quality software, minimizing risks while maximizing speed and productivity. Black Duck, a recognized pioneer in application security, provides SAST, SCA, a…
Est. 115,000 USD
About Lucid At Lucid, we are creating exceptional mobility experiences through innovation to drive the world forward. Built on Lucid’s proprietary technology and software-defined vehicle architecture, our award-winning v…
Est. 250,000 USD
About the Role: PubMatic is seeking a Director of Information Security to lead and evolve our global security program across enterprise infrastructure, cloud platforms, products, corporate systems, and emerging AI techno…
Est. 120,000 GBP
About Baringa Baringa is a global consulting firm that partners with leaders to drive change and create value. With deep industry expertise, and enabled by advanced technology, the firm helps clients to deliver with grea…