Search by job, company or skills

Senior IT Security Officer for MOE (2 years contract)

7-9 Years
SGD 1.02 - 1.2 LPA
  • Posted 7 hours ago
  • Be among the first 10 applicants

Job Description

[2 years contract]

1. Role Purpose

The Senior IT Security Officer is responsible for providingcybersecurity governance, risk management, security assurance and securityadvisory across ICT systems, digital services, cloud platforms andinfrastructure supporting a Singapore Public Sector organisation.

The role works closely with system owners, application teams,infrastructure and cloud teams, cybersecurity operations, enterprisearchitects, project managers, vendors and management to ensure that securityrisks are identified early, controls are proportionate and effective, andsystems are operated in accordance with applicable Government ICT&SSpolicies and standards, organisational requirements, contractual obligationsand recognised cybersecurity good practices.

2. Key Responsibilities

2.1 Cybersecurity Governance and Risk Management

. Provide independentcybersecurity governance and advisory across the project and system lifecycle.

. Lead or review cybersecurityrisk assessments, including threat identification, vulnerability analysis,attack-path considerations, inherent risk, residual risk, compensating controlsand risk treatment plans.

. Ensure material security risks,deviations and exceptions are properly documented, justified, tracked,escalated and formally accepted by the appropriate risk owner when required.

. Monitor recurring control gaps,overdue remediation and systemic risks, and recommend programme-levelcorrective actions.

. Maintain clear securitydecision records, evidence and audit trails for governance and managementassurance.

2.2 Security Architecture and Security-by-Design

. Review application, cloud,infrastructure, network, identity and integration architectures for securityrisks and control gaps.

. Assess trust boundaries, dataflows, privileged access paths, external exposure, administrative interfaces,API integrations and dependency risks.

. Challenge security assumptionsand ensure proportionate preventive, detective and recovery controls areincluded before production implementation.

. Advise teams on secure designpatterns for authentication, authorisation, encryption, secrets, logging,segmentation, resilience and least privilege.

. Participate in architecturereview boards, design reviews, go-live readiness reviews and securityacceptance decisions.

2.3 Cloud, Identity and Platform Security

. Assess cloud security designsand configurations across AWS, Microsoft Azure and/or Google Cloud, includingIAM, network controls, workload protection, encryption, key management, loggingand monitoring.

. Review identity and accessmanagement controls including MFA, privileged access, RBAC, service accounts,workload identities, conditional access and access lifecycle management.

. Assess Zero Trust, ZTNA, remoteaccess, endpoint security and security service integrations where applicable.

. Evaluate security implicationsof SaaS, managed services, containers, Kubernetes and other modern platformtechnologies.

2.4 Vulnerability Management, VA/PT and Security Testing

. Review vulnerability findingsand determine practical risk, remediation priority and required treatment basedon business context and exploitability.

. Track remediation againstapplicable service levels and escalate overdue or repeated high-risk findings.

. Define or review securitytesting requirements, including vulnerability assessment, penetration testing,application security testing, configuration review and other assuranceactivities.

. Review test reports, validateremediation evidence and challenge inappropriate risk acceptance or weakcompensating controls.

. Support secure developmentpractices by reviewing relevant SAST, DAST, SCA, API security and CI/CDsecurity evidence where applicable.

2.5 Security Operations and Incident Response

. Work with SOC and securityoperations teams to ensure appropriate logging, telemetry, alerting, detectionuse cases and escalation paths exist for critical systems.

. Participate in or coordinatecybersecurity incident response, investigation, containment, eradication,recovery and lessons-learned activities as required.

. Translate incident findings andadversary techniques into preventive improvements, detection requirements andremediation actions.

. Assess emergingvulnerabilities, CVEs and threat intelligence to determine applicability andpriority for systems within the assigned portfolio.

. Support cyber exercises,tabletop exercises and operational readiness testing.

2.6 Cyber Resilience and Recovery

. Review cybersecurity aspects ofbusiness continuity, disaster recovery, backup, restoration and ransomwareresilience arrangements.

. Assess recovery dependencies,privileged recovery paths, backup protection, immutability and recovery testevidence.

. Participate in disasterrecovery and cyber resilience exercises and ensure security lessons are trackedto closure.

2.7 Stakeholder Management, Reporting and Leadership

. Act as a trusted cybersecurityadvisor to project teams, system owners, business stakeholders and seniormanagement.

. Explain complex cybersecurityrisks in clear business language and recommend practical options fordecision-making.

. Prepare concise managementreports covering key risks, vulnerabilities, incidents, audit findings,remediation progress and security posture.

. Mentor junior ITSOs andcontribute to consistent security assessment methods, templates, playbooks andstandards across the organisation.

. Escalate material risksobjectively and maintain independence when reviewing solutions or riskacceptance requests.

3. Minimum Requirements

. Minimum 7 years of relevant ITor cybersecurity experience, with substantial experience in cybersecuritygovernance, risk management, security assurance, architecture, operations,cloud security, audit or security consulting.

. At least 3 years of experienceindependently reviewing or governing enterprise-scale systems, major ICTprojects or government/public-sector environments.

. Demonstrated ability to conductor critically review cybersecurity risk assessments and recommend proportionatetechnical and governance controls.

. Strong understanding ofenterprise security architecture across applications, infrastructure, networks,cloud, identity and security operations.

. Experience working withtechnical teams, project management, auditors, vendors and senior stakeholders.

. Strong written and verbalcommunication skills, including the ability to produce clear risk statements,security recommendations, management papers and audit responses.

. Ability to work independently,exercise professional judgement and escalate material risk where necessary.

. Relevant degree inCybersecurity, Information Systems, Computer Science, Engineering or a relateddiscipline equivalent professional experience may be considered.

4. Professional Certifications

The candidate should possess at least one current recognisedprofessional cybersecurity certification. Suitable certifications include:

.CISSP - Certified InformationSystems Security Professional

.CISM - Certified InformationSecurity Manager

.CRISC - Certified in Risk andInformation Systems Control

.CISA - Certified InformationSystems Auditor

.CCSP - Certified Cloud SecurityProfessional

.CGEIT - Certified in theGovernance of Enterprise IT

.Relevant GIAC certifications orequivalent professional cybersecurity certifications

5. Framework and Standards Knowledge

The Senior ITSO should have practical working knowledge of relevantframeworks and be able to apply them proportionately rather than as achecklist. Useful knowledge includes:

.Applicable Singapore GovernmentICT&SS cybersecurity policies, standards, control requirements andagency-specific security directives.

. ISO/IEC 27001 and ISO/IEC27002.

.NIST Cybersecurity Frameworkand relevant NIST SP 800-series guidance.

. CIS Controls and CISBenchmarks.

.MITRE ATT&CK forunderstanding adversary tactics and techniques.

.OWASP guidance for webapplication and API security.

.Cloud security good practicesand shared-responsibility principles.

.Applicable legal, regulatoryand data-protection requirements, including PDPA and sector-specificobligations where relevant.

More Info

Job Type:
Industry:
Function:
Employment Type:

About Company

Job ID: 153612103

Beware of Scammers

We don’t charge money for job offers