Cybersecurity Operations Specialist

4 days ago


Singapore Government Technology Agency Full time $120,000 - $200,000 per year

[What the role is]

GovTech is the lead agency driving Singapore's Smart Nation initiatives and public sector digital transformation. As the Centre of Excellence for Infocomm Technology and Smart Systems (ICT & SS), GovTech develops the Singapore Government's capabilities in Data Science & Artificial Intelligence, Application Development, Smart City Technology, Digital Infrastructure, and Cybersecurity.

At GovTech, we offer you a purposeful career to make lives better where we empower our people to master their craft through robust learning and development opportunities all year round.

Play a part in Singapore's vision to build a Smart Nation and embark on your meaningful journey to build tech for public good. Join us to advance our mission and shape your future with us today

Learn more about GovTech at

[What you will be working on]

Do you want to play a critical role in securing our smart nation initiatives by uncovering weaknesses in various domains of cybersecurity programs even before the real threat actors come to play? And are you up to race against the real threat actors before organisations are compromised?

We seek an experienced cybersecurity professional to lead our Crowdsourced Vulnerability Discovery Programme (CVDP) triage team. The role encompasses managing daily operations, leading a team of triage specialists, and ensuring effective handling of vulnerability reports across government systems for the Government Bug Bounty Programme (GBBP), Vulnerability Disclosure Programme (VDP), and Vulnerability Rewards Programme (VRP) for Whole-of-Government (WoG).

Key Responsibilities

Team Leadership & Operations

  • Lead and mentor a team of CVD triage specialists, providing technical guidance and ensuring optimal performance in vulnerability assessment and management
  • Operational planning of day-to-day tasks and development of the team's technical capabilities and soft skills
  • Foster a supportive and collaborative team environment with strong commitment to mentoring team members

Programme Management

  • Lead the conduct of 6 runs of GBBP and Pre-GBBP per year
  • Lead continuous VDP and VRP operations
  • Lead the CVD team in performing technical and impact analysis of reported vulnerabilities for GBBP, VDP and VRP
  • Lead the CVD team in performing in-depth testing on agencies' patches for all CVD programmes

Technical & Strategic Functions

  • Prepare and present materials for bounty approval
  • Develop and deliver presentations on notable vulnerabilities identified through programmes for cross-team sharing, SLM sharing, or forums
  • Conduct technical sharing of vulnerabilities arising from the programmes to internal and external stakeholders
  • Perform analysis on data and payloads of reports to derive insights, statistics, and trends to advise various stakeholders
  • Devise global solutions for recurring vulnerabilities

Process & Documentation

  • Review and maintain standard operating procedures (SOPs) for the vulnerability triage process
  • Continuously improve existing processes and SOPs
  • Develop comprehensive documentation for triage processes
  • Prepare regular vulnerability trends and operational metrics reports

Stakeholder Management

  • Interface with agencies for clarification
  • Manage stakeholder relationships across government agencies, system owners, and security researchers
  • Provide technical support to the Programme Team
  • Oversee integration and maintenance of key platforms

[What we are looking for]

  • Degree in Cybersecurity, Computer Science, Information Systems, Computer Engineering, Information Security, or related technical field
  • OSCP certification (mandatory)
  • Minimum 3-5 years' experience in cybersecurity, penetration testing, or web penetration testing
  • At least 2 years' team leadership or management experience
  • Technical experience in performing web penetration testing or similar skills
  • Understanding of basic cybersecurity principles and concepts
  • Must have legal authorisation to work in Singapore

Advantageous Qualifications

  • Professional certifications ( OSWE, GPEN, CISSP)
  • Experience with bug bounty programmes or vulnerability coordination
  • Previous experience with government systems
  • Background in technical team leadership

Required Skills

  • Comprehensive understanding of web application security and vulnerability assessment
  • Experience with vulnerability management platforms and bug tracking systems
  • Excellent project management and team leadership abilities
  • Strong analytical and problem-solving capabilities
  • Outstanding communication and stakeholder management skills
  • Good command of English (oral and written)
  • Ability to perform under pressure and manage critical incidents
  • Positive attitude and collaborative leadership style
  • Demonstrated ability to foster a supportive and collaborative team environment
  • Strong commitment to mentoring team members and promoting mutual support within the team

GovTech is an equal opportunity employer committed to fostering an inclusive workplace that values diverse voices and perspectives, as we believe that diversity is the foundation to innovation.

Our employee benefits are based on a total rewards approach, offering a holistic and market-competitive suite of perks. These include leave benefits to meet your work-life needs and employee wellness programmes .

We champion flexible work arrangements (subject to your job role) and trust that you will manage your own time to deliver your best, wherever you are, and whatever works best for you.

Learn more about life inside GovTech at GovTechCareers .

Stay connected with us on social media at ConnectWithGovTech .



  • Singapore Red Alpha Cybersecurity Full time

    Cybersecurity Specialist Join us as a Cybersecurity Specialist through our Alpha Specialist Training Programme (ASTP), a structured and fully sponsored pathway designed to launch your career in cybersecurity. Whether you're a fresh graduate or making a career switch, Red Alpha equips you with practical skills, industry-recognised certifications, and a...


  • Singapore RED ALPHA CYBERSECURITY PTE. LTD. Full time $60,000 - $80,000 per year

    Join us as a Cybersecurity Specialist through our Alpha Specialist Training Programme (ASTP) , a structured and fully sponsored pathway designed to launch your career in cybersecurity. Whether you're a fresh graduate or making a career switch, Red Alpha equips you with practical skills, industry-recognised certifications, and a guaranteed deployment into...


  • Singapore ENSIGN INFOSECURITY (CYBERSECURITY) PTE. LTD. Full time $120,000 - $180,000 per year

    OverviewThe System Manager role ensures unified oversight, accountability, and seamless coordination across security domains, driving operational excellence and aligning cybersecurity operations with organizational strategy. The System Manager will also serve as the point of contact with access to Ensign's expert bench, orchestrating escalations, system...


  • Singapore Centre for Strategic Infocomm Technologies Full time

    CSIT conducts research and development to uncover system vulnerabilities, and defend against advanced cyber threats. Our work covers a wide range of platforms including cloud, enterprise systems, mobile and critical infrastructure. We are looking for innovative individuals who are passionate about cybersecurity and interested to play an important role in...


  • Singapore Changi Airport Group Full time

    Join to apply for the Cybersecurity Specialist role at Changi Airport Group Do you want to help secure the airport systems, applications and infrastructure? Are you keen on cybersecurity technology and learning about new cyber threats? If yes, then you may be a good fit for a job as a Cybersecurity Specialist!About the Role: Finding and reducing...


  • Singapore CADMUS RESOURCES Full time

    About the job Lead Cybersecurity Specialist Our client is a well known retail company within the region and they are currently expanding. They are looking for a Lead Cybersecurity Specialist, where you will be responsible for overseeing and implementing the organization's cybersecurity strategy and ensuring the protection of their IT infrastructure, data,...


  • Singapore Frasers Property Limited Full time

    Description Overview Cybersecurity Operations Specialist, Group Digital & Technology We are seeking a highly skilled and experienced Cybersecurity Operations Specialist to join our Group IT Cybersecurity Incident Detection & Response team. The ideal candidate should possess extensive experience in cybersecurity monitoring, incident response, and system...


  • Singapore Frasers Property Limited Full time

    Overview Cybersecurity Operations Specialist, Group Digital & Technology We are seeking a highly skilled and experienced Cybersecurity Operations Specialist to join our Group IT Cybersecurity Incident Detection & Response team. The ideal candidate should possess extensive experience in cybersecurity monitoring, incident response, and system engineering....


  • Singapore NTUC First Campus Limited Full time $60,000 - $120,000 per year

    Job no: 520823Work type: Full TimeCategories: Corporate PositionsThe IT department in NTUC First Campus manages and maintains the organization's technology applications and infrastructure to ensure operational efficiency and secure organizational resilience.As a Cybersecurity Specialist, you will be responsible for security risk assessments, cybersecurity...


  • Singapore Frasers Property Full time $70,000 - $120,000 per year

    Job Summary We are seeking a highly skilled and experienced Cybersecurity Operations Specialist to join our Group IT Cybersecurity Incident Detection & Response team. The ideal candidate should possess extensive experience in cybersecurity monitoring, incident response, and system engineering. Job DescriptionSecurity Monitoring: Ensure continuous security...