Agency Chief Information Security Officer

21 hours ago


Singapur, Singapore Government Technology Agency Full time

What the role is

GovTech is the lead agency driving Singapore’s Smart Nation initiatives and public sector digital transformation. As the Centre of Excellence for Infocomm Technology and Smart Systems (ICT & SS), GovTech develops the Singapore Government’s capabilities in Data Science & Artificial Intelligence, Application Development, Smart City Technology, Digital Infrastructure, and Cybersecurity. At GovTech, we offer you a purposeful career to make lives better where we empower our people to master their craft through robust learning and development opportunities all year round. Play a part in Singapore’s vision to build a Smart Nation and embark on your meaningful journey to build tech for public good. Join us to advance our mission and shape your future with us today Learn more about GovTech at tech.gov.sg.

What you will be working on

GovTech supports various Government Agencies in carrying out ICT delivery services and appoints Agency Chief Information Security Officers (ACISO) to oversee information security management within these agencies. The ACISO is a leadership role that requires technical proficiency demonstrated in multiple cybersecurity domains. The role demands knowledge and/or practical experience in most of the domains below:

  • Cybersecurity Governance frameworks
  • Security Operations including incident response
  • Architecture design and threat risk assessment
  • Security Testing

The ACISO must possess technical understanding of both on-premises infrastructure security and cloud security architectures across major platforms (e.g., AWS, Azure, and GCP), including their native security features, identity management systems, and security control implementations.

(What you will be working on)

Emplaced in public agencies and reporting to the agency’s Chief Information Officer (CIO) and Ministry Family CISO, you will collaborate with various stakeholders (GovTech HQ teams, Agency management, Agency project teams, and outsourced vendors) and will be responsible to:

  • Lead the agency-level cybersecurity function in supporting agency digital transformation initiatives whilst ensuring digital resilience of agency systems.
  • Formulate and implement agency cybersecurity strategies, policies and work plans, ensuring continuous alignment with Ministry Family's business strategic goals
  • Review and enhance risk management through threat-based risk assessments, risk mitigations, risk monitoring and reporting.
  • Provide consultation and endorse risk management and mitigation plans from agency’s project teams.
  • Govern and enhance the agency's security posture by maintaining visibility and oversight of ICT assets, security architectures, and cybersecurity operations code of practices.
  • Develop and maintain incident response plan and playbooks. This involves planning, designing and conduct of security incident response workshops and exercises (table-top exercises, simulation and drills) as well as lead the investigation and management of ICT security incidents.
  • Provide advisory and recommendations on appropriate cybersecurity technologies to be deployed that meets agency’s business requirements and aligned with WOG-wide advisories and practices.
  • Ensure secure by design ICT product development, and that security controls implementations comply with the defined security policies, standards and guidelines.
  • Develop and maintain effective cybersecurity awareness and training programmes
What we are looking for
  • Degree in Computer Science, Information Systems, Engineering or related Technology field
  • At least 8-10 years of management experience related to information security and solid grasp of ICT operations, security policies, business processes and the relationship between them.
  • Ability to work with multi-functional, multi-disciplined teams to formulate, institute real time awareness of security posture and baseline among end users.
  • Good interpersonal and partner/executive leadership skills.
  • Demonstrate knowledge and experience in security by design implementations, review of system architecture, devsecops practices, Infrastructure as Code (IaC) tools and securing CI/CD pipelines
  • Demonstrate understanding of cloud service models (IaaS, PaaS, SaaS), coupled with a strong understanding of core cloud services and modern cloud-native architectures (serverless, containers, microservices)
  • Identify on-premises and cloud-specific cybersecurity risks and threats, demonstrating skills to thoroughly assess their impact and likelihood. This assessment encompasses secure configurations, insider threats, vendor risks, data leakage, malwares including ransomware, account hijacking, and compliance risks.
  • Evaluate the effectiveness of existing controls and recommending appropriate mitigation strategies for on-premises and cloud-related cybersecurity and data security issues.
  • Display understanding of emerging threats and technologies, and the ability to translate risk into business impact
  • Strong understanding of compliance requirements and the ability to identify potential violations in on-premises or cloud environments.
  • Able to communicate cyber security topics effectively to senior stakeholders.
  • Minimally possess CISSP certification, preferably with other related certifications, e.g. CISM, CCSP, GCIH that demonstrates continuous learning and knowledge of industry best practices.
  • We believe in being Agile, Bold and Collaborative, and are looking for people who identify with these values.
  • Singaporeans only.

(What we are looking for)

GovTech is an equal opportunity employer committed to fostering an inclusive workplace that values diverse voices and perspectives, as we believe it is key to innovation.

Our employee benefits are based on a total rewards approach, offering a holistic and market-competitive suite of perks.

We champion flexible work arrangements (subject to your job role) and trust you to manage your time to deliver your best.

Learn more about life inside GovTech at go.gov.sg/GovTechCareers.

About GovTech

The Government Technology Agency (GovTech) is the lead agency driving Singapore’s Smart Nation initiatives and public sector digital transformation. As the Centre of Excellence for Infocomm Technology and Smart Systems (ICT & SS), GovTech develops the Singapore Government’s capabilities in Data Science & Artificial Intelligence, Application Development, Smart City Technology, Digital Infrastructure, and Cybersecurity. GovTech aims to transform the delivery of Government digital services by taking an "outside-in" view, putting citizens and businesses at the heart of everything we do. GovTechies embody our Agile, Bold and Collaborative values to deliver impactful solutions. Learn more about GovTech at tech.gov.sg.

#J-18808-Ljbffr

  • Singapur, Singapore JOHN ETHANS INTERNATIONAL PTE. LTD. Full time

    Our client is a government agency which supports ICT delivery services. This is a leadership role that requires technical proficiency demonstrated in multiple cybersecurity domains. Responsibilities: Lead the agency-level cybersecurity function in supporting agency digital transformation initiatives whilst ensuring digital resilience of agency systems....


  • Singapur, Singapore HyreWise Full time

    Chief Financial Officer (CFO) - Securization & DCM transactions We are working on behalf of a confidential client to identify an exceptional finance leader with proven expertise in securitization and debt capital markets (DCM) transactions to join their senior management team as Chief Financial Officer . This role can be based in either Singapore or...

  • Head of Security

    3 days ago


    Singapur, Singapore Coins.ph Full time

    Overview Join the Pioneer Crypto Brand in the Philippines! Coins is the most established crypto brand in The Philippines and has gained the trust of more than 18 million users. Through the easy-to-use mobile app, users can buy and sell a variety of different cryptocurrencies and access a wide range of financial services. Coins is fully regulated by the...

  • Senior Manager

    3 days ago


    Singapur, Singapore Cyber Security Agency of Singapore Full time

    What the role is You will join a dynamic team at the forefront of advancing Singapore’s cybersecurity R&D capabilities. Within the CSA, the Capability Masterplanning Office (CMO) leads the National Cybersecurity R&D Programme (NCRP), where you will play a crucial role in strategising and driving national cybersecurity initiatives. Your work will directly...

  • Chief Information

    3 days ago


    Singapur, Singapore RevUp Consulting Full time

    Overview The Chief Information & Digital Officer is responsible for shaping and leading the organisation’s technology vision and digital strategy. This role drives innovation and business growth by harnessing emerging technologies such as Artificial Intelligence (AI) & Quantum Computing, while ensuring robust ICT operations that align with organisational...

  • Chief Information

    3 days ago


    Singapur, Singapore RevUp Consulting Full time

    Overview The Chief Information & Digital Officer is responsible for shaping and leading the organisation’s technology vision and digital strategy. This role drives innovation and business growth by harnessing emerging technologies such as Artificial Intelligence (AI) & Quantum Computing, while ensuring robust ICT operations that align with organisational...


  • Singapur, Singapore Home Team Science and Technology Agency (HTX) Full time

    What the role is The Home Team Science and Technology Agency (HTX) is a statutory board under the Ministry of Home Affairs (MHA) which aims to pioneer innovation solutions and develop world class science and technology capabilities to transform and empower the Home Team in delivering safety and security for Singapore. The jobholder will provide operational...


  • Singapur, Singapore RevUp Consulting Full time

    Key Responsibilities Develop and lead the organization’s overall cybersecurity strategy and roadmap Manage enterprise risk and compliance with standards such as ISO 27001, GDPR, and relevant regulatory requirements Oversee Security Operations including threat detection, incident response, and vulnerability management Promote a security-first culture...

  • Temp HR Executive

    3 days ago


    Singapur, Singapore Cyber Security Agency of Singapore Full time

    What the role is What the role is: About CSAEstablished on 1 April 2015, the Cyber Security Agency of Singapore (CSA) provides dedicated and centralised oversight of Singapore's national cyber security functions. It is the national body overseeing cyber security strategy, operation, education and outreach and ecosystem development. It is part of the Prime...


  • Singapur, Singapore Cyber Security Agency of Singapore Full time

    What the role is As a member of the Communications and Engagement team, you will play an instrumental role in communicating CSA's policies and programmes to the public. In partnership with stakeholders from the public and private sectors such as businesses, media outlets and other government agencies, the officer will specialise in managing media relations...