415,615open jobs
14,704companies
74,833added this week
Browse all
Salary
$88k – $199k per year (Estimated)
Location
In office (Singapore)
Seniority
Senior · 5+ years exp
Employment
Contractor
Overview
Company
Impact
Profile match
Careers@Gov is the official centralized recruitment platform for the Singapore Public Service, serving as a single gateway for job opportunities across government ministries and statutory boards. The portal enables job seekers to explore public sector roles, track applications, and access career development resources powered by digital tools. Headquartered in Singapore, it is managed by the Public Service Division and the Government Technology Agency to streamline public sector talent acquisition.

[What the role is]

As a Governance Risk and Compliance Specialist & Application Security Engineer, this role is crucial in developing and maintaining a robust culture of technology and cybersecurity risk governance across our organization.

[What you will be working on]

Governance, Risk and Compliance (GRC)

  • Develop and promote a culture of technology risk governance and management across the organisation, ensuring proper accountability in managing, tracking, and reporting technology and cyber risks
  • Provide subject matter expertise to internal stakeholders on cybersecurity requirements, including compliance with MAS internal policies and standards, as well as policies from GovTech and Cyber Security Agency of Singapore
  • Review and establish ICT policies and process controls, conducting regular compliance checks to ensure adherence • Track and monitor technology projects and initiatives to meet compliance requirements, including Key Risk Indicators and Control Self-Assessment as part of the technology governance framework
  • Monitor incident reporting processes, reviewing and reporting on corrective measures and improvement areas
  • Participate in consultations and conduct gap analysis against new or revised regulatory requirements • Assess and seek waiver approvals for deviations and develop risk treatment strategies
  • Organise risk forums and monitor action plans, coordinate and facilitate IT and cybersecurity audits
  • Track remediation plans to address audit findings and follow up on remediation actions with stakeholders, project managers, and application managers

Application Security

  • Establish clear guidelines and best practices for secure coding, vulnerability management, and incident response across development teams
  • Serve as Subject Matter Expert in application security for enterprise projects during development phases, providing information security consulting and recommendations
  • Discover security vulnerabilities and devise mitigation strategies, reporting and resolving technical debt effectively • Track and address security issues with timely remediation and patching processes
  • Integrate security tools and processes into DevOps pipelines, automating security scans and tests
  • Collaborate with developers and software teams to ensure security integration at every stage of software development
  • Work with development teams to remediate application security vulnerabilities and prevent future incidents
  • Implement and promote secure coding practices throughout the organisation

Strategic and Operational Excellence

  • Recommend re-engineering and streamlining of processes to enhance control effectiveness
  • Present management reporting to stakeholders with data analysis, trend identification, and strategic recommendations
  • Enhance training materials and documentation in ICT risk management, developing case studies and best practices • Stay updated on latest security threats, trends, and emerging technologies
  • Identify opportunities for incorporating AI assistant tools into development processes and analyse efficacy of potential use cases

This integrated role ensures comprehensive security coverage from governance oversight through to technical implementation, creating a robust security posture across the organisation's technology landscape.

[What we are looking for]

  • At least 5 years relevant experience in ICT cybersecurity, data security, audit management, governance, risk and compliance management, security engineer or security architect role

  • Relevant certifications in IT governance, IT audit, cyber or data security (e.g. CISSP, CISM, CISA, etc.) preferred.

  • Ability to work with cross-functional, multi-disciplined team to operationalise monitor security policies and procedures.

  • Knowledge of Instruction Manual 8 and CSA Cybersecurity Code of Practice preferred.

  • Technical knowledge of security vulnerabilities, validation of remediations and risk assessments.

  • Experience in performing penetration testing, secure code review, static, dynamic and manual source code review.

  • Experience in identifying and remediating common web application vulnerabilities such as OWASP Top 10

  • Hands-on experience with Web Application Scanning Tools

  • Proven experience in secure coding practices, vulnerability assessment, and penetration testing

  • Relevant experience in data visualisation and analytics.

Skillset:

  • Strong analytical, reasoning and problem-solving skills.

  • Meticulous with an eye for detail.

  • Good oral and written communication skills

  • Ability to work independently and assume responsibility for project deliverables.

  • Team player who is proactive and collaborative

  • Experience in reporting and dashboard using JIRA is preferred.

As part of the shortlisting process for this role, you may be required to complete a medical declaration and/or undergo further assessment.

This is a 2-Year Contract. All applicants will be notified on whether they are shortlisted or not within 4 weeks of the closing date of this job posting.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
415,615 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Singapore
$33k per year • Remote • Full-Time • 5+ years exp • Moscow
Cybersecurity
OWASP Top 10
Wazuh
Apply
$20k – $51k per year (Estimated) • In office • Full-Time • 4+ years exp • Bachelor's Degree • Gurgaon
C#
SQL
TypeScript
JavaScript
Frontend
Angular
DevOps
Amazon EventBridge
AWS
Azure
Azure DevOps
CI/CD
Docker
GitHub
GitHub Actions
Kubernetes
Rest API
Cybersecurity
OWASP Top 10
SonarQube
Apply
Remote/Hybrid • Bachelor's Degree
Java
Kotlin
Java
Maven
Databases
Apache Kafka
Kafka
DevOps
Git
Jenkins
Rest API
Cybersecurity
OWASP SAMM
OWASP Top 10
Management
Confluence
Jira
Apply
$100k – $150k per year • Remote • 6+ years exp • Bachelor's Degree
AI/ML
LLM
DevOps
CI/CD
Cybersecurity
OWASP Top 10
Apply
$85k – $105k per year • Remote • 6+ years exp • Bachelor's Degree
AI/ML
LLM
DevOps
CI/CD
Cybersecurity
OWASP Top 10
Apply
$68k – $162k per year (Estimated) • In office • Full-Time • 1+ year exp • Singapore
Apply
In office • Full-Time • Singapore
Apply
$87k – $175k per year (Estimated) • In office • Contractor • 1+ year exp • PhD • Singapore
Python
SQL
Python
pySpark
AI/ML
Spark
DevOps
Azure
Robotics
Digital Twin
Apply
$50k – $110k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • Singapore
Apply
$70k – $174k per year (Estimated) • In office • Contractor • 3+ years exp • Singapore
Apply
$70k – $174k per year (Estimated) • In office • Contractor • 3+ years exp • Singapore
Apply
$51k – $110k per year (Estimated) • In office • Full-Time • 2+ years exp • Singapore
Apply
$85k – $217k per year (Estimated) • Remote/Hybrid • Full-Time • 10+ years exp • Sydney
AI/ML
AI Agents
DevOps
AWS
Azure
GCP
Apply
$97k – $244k per year (Estimated) • In office • Full-Time • 12+ years exp • Singapore
AI/ML
Agentic Workflows
AI Agents
LLM Guardrails
Apply
$22k – $53k per year (Estimated) • In office • Full-Time • 1+ year exp • Bachelor's Degree • Singapore
Marketing
Instagram
LinkedIn
X (Twitter)
Apply
See all jobs
This is one of many
415,615 more open roles from verified company boards, updated every day.