368,657open jobs
9,442companies
50,883added this week
Browse all
Salary
$95k – $215k per year (Estimated)
Location
In office (Singapore)
Seniority
Senior · 5+ years exp
Employment
Contractor
Overview
Company
Impact
Profile match
GovTech Singapore (Government Technology Agency) is the statutory board under the Smart Nation and Digital Government Group (SNDGG) responsible for driving Singapore's digital government transformation. The agency develops and manages key national digital infrastructure and public platforms, including Singpass, LifeSG, and the CODEX government tech stack. By building in-house capabilities in software engineering, cybersecurity, data science, and AI, GovTech delivers secure, citizen-centric digital services to modernize public administration.

[What the role is]

As a Governance Risk and Compliance Specialist & Application Security Engineer, this role is crucial in developing and maintaining a robust culture of technology and cybersecurity risk governance across our organization.

The ideal candidate will have at least 5 years of relevant experience in ICT cybersecurity, data security, audit management, governance, and risk compliance management. He or She will be responsible for providing expert advice on cyber security requirements, reviewing and establishing ICT policies, and supporting various aspects of our tech governance framework.

Putting on the Application Security hat, he or she will also be responsible for identifying, assessing, and mitigating security vulnerabilities in software applications. They work closely with development teams to integrate security practices into the software development lifecycle (SDLC) and help ensure that applications are secure and compliant with relevant standards and regulations.

This role offers an opportunity to make a significant impact on our organization's ICT risk management and governance practices. The successful candidate will work with cross-functional teams for maintaining the highest standards of cybersecurity and ICT compliance.

[What you will be working on]

Governance, Risk and Compliance (GRC)

  • Develop and promote a culture of technology risk governance and management across the organisation, ensuring proper accountability in managing, tracking, and reporting technology and cyber risks
  • Provide subject matter expertise to internal stakeholders on cybersecurity requirements, including compliance with MAS internal policies and standards, as well as policies from GovTech and Cyber Security Agency of Singapore
  • Review and establish ICT policies and process controls, conducting regular compliance checks to ensure adherence • Track and monitor technology projects and initiatives to meet compliance requirements, including Key Risk Indicators and Control Self-Assessment as part of the technology governance framework
  • Monitor incident reporting processes, reviewing and reporting on corrective measures and improvement areas
  • Participate in consultations and conduct gap analysis against new or revised regulatory requirements • Assess and seek waiver approvals for deviations and develop risk treatment strategies
  • Organise risk forums and monitor action plans, coordinate and facilitate IT and cybersecurity audits
  • Track remediation plans to address audit findings and follow up on remediation actions with stakeholders, project managers, and application managers

Application Security

  • Establish clear guidelines and best practices for secure coding, vulnerability management, and incident response across development teams
  • Serve as Subject Matter Expert in application security for enterprise projects during development phases, providing information security consulting and recommendations
  • Discover security vulnerabilities and devise mitigation strategies, reporting and resolving technical debt effectively • Track and address security issues with timely remediation and patching processes
  • Integrate security tools and processes into DevOps pipelines, automating security scans and tests
  • Collaborate with developers and software teams to ensure security integration at every stage of software development
  • Work with development teams to remediate application security vulnerabilities and prevent future incidents
  • Implement and promote secure coding practices throughout the organisation

Strategic and Operational Excellence

  • Recommend re-engineering and streamlining of processes to enhance control effectiveness
  • Present management reporting to stakeholders with data analysis, trend identification, and strategic recommendations
  • Enhance training materials and documentation in ICT risk management, developing case studies and best practices • Stay updated on latest security threats, trends, and emerging technologies
  • Identify opportunities for incorporating AI assistant tools into development processes and analyse efficacy of potential use cases

This integrated role ensures comprehensive security coverage from governance oversight through to technical implementation, creating a robust security posture across the organisation's technology landscape.

[What we are looking for]

  • At least 5 years relevant experience in ICT cybersecurity, data security, audit management, governance, risk and compliance management, security engineer or security architect role

  • Relevant certifications in IT governance, IT audit, cyber or data security (e.g. CISSP, CISM, CISA, etc.) preferred.

  • Ability to work with cross-functional, multi-disciplined team to operationalise monitor security policies and procedures.

  • Knowledge of Instruction Manual 8 and CSA Cybersecurity Code of Practice preferred.

  • Technical knowledge of security vulnerabilities, validation of remediations and risk assessments.

  • Experience in performing penetration testing, secure code review, static, dynamic and manual source code review.

  • Experience in identifying and remediating common web application vulnerabilities such as OWASP Top 10

  • Hands-on experience with Web Application Scanning Tools

  • Proven experience in secure coding practices, vulnerability assessment, and penetration testing

  • Relevant experience in data visualisation and analytics.

Skillset:

  • Strong analytical, reasoning and problem-solving skills.

  • Meticulous with an eye for detail.

  • Good oral and written communication skills

  • Ability to work independently and assume responsibility for project deliverables.

  • Team player who is proactive and collaborative

  • Experience in reporting and dashboard using JIRA is preferred.

As part of the shortlisting process for this role, you may be required to complete a medical declaration and/or undergo further assessment.

This is a 2-Year Contract. All applicants will be notified on whether they are shortlisted or not within 4 weeks of the closing date of this job posting.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,657 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Singapore
$21k – $42k per year (net) • Remote/Hybrid • Full-Time • 2+ years exp • Rostov-on-Don
Databases
ElasticSearch
DevOps
CI/CD
Docker
Kubernetes
Grafana
Prometheus
Zabbix
Cybersecurity
OWASP Top 10
Wazuh
Apply
$67k – $173k per year (Estimated) • In office • Contractor • 3+ years exp • Bachelor's Degree • Singapore
JavaScript
Python
DevOps
AWS
Azure
GCP
Cybersecurity
ISO 27001
OWASP Top 10
Apply
$185k – $260k per year • Remote • Full-Time • 8+ years exp • Bachelor's Degree
DevOps
AWS
CI/CD
GCP
Kubernetes
GitHub
Cybersecurity
Clair
Dependabot
OWASP Top 10
OWASP ZAP
Snyk
Trivy
Apply
Senior AI Engineer 2 days ago
In office • New Cairo
Python
SQL
Databases
Azure Cosmos DB
Databricks
pgvector
Pinecone
PostgreSQL
Weaviate
AI/ML
AI Agents
AutoGen
AWS Bedrock
Computer Vision
Embeddings
Fine-tuning
Function Calling
LangChain
Langfuse
Llama
LLM
LoRA
Mistral
MLFlow
NLP
ONNX
PEFT
Prompt Engineering
Quantization
RAG
Semantic Kernel
Tokenization
Vertex AI
vLLM
Weights & Biases
Transformers
Amazon SageMaker
EU AI Act
Google AI Studio
Hugging Face
LLM Guardrails
LLMOps
NIST AI RMF
OpenAI
DevOps
AWS
Azure
Azure AKS
Azure DevOps
CI/CD
GCP
GitHub Actions
gRPC
Kubernetes
Vector
GitHub
Cybersecurity
GDPR
Microsoft Entra ID
OWASP Top 10
Threat Modeling
Apply
$136k – $336k per year (Estimated) • In office • Full-Time • Master's Degree • Singapore
AI/ML
AI Agents
Copilot
LLM
RAG
LLM Guardrails
NIST AI RMF
OpenAI
Red Teaming
DevOps
Azure
Kubernetes
IAM
Cybersecurity
OWASP Top 10
Web3
Smart Contracts
Apply
$77k – $215k per year (Estimated) • In office • Contractor • 3+ years exp • Singapore
JavaScript
Python
TypeScript
Python
Django
FastAPI
Databases
PostgreSQL
Redis
AI/ML
AI Agents
LangGraph
LLM
Prompt Engineering
LangChain
Edge AI
Frontend
Angular
React.js
Vue.js
Apply
Apply
$110k – $239k per year (Estimated) • In office • Contractor • 3+ years exp • Singapore
AI/ML
ChatGPT
Claude
Claude Code
Copilot
Apply
$93k – $210k per year (Estimated) • In office • Contractor • 8+ years exp • Bachelor's Degree • Singapore
DevOps
CI/CD
Apply
$67k – $173k per year (Estimated) • In office • Contractor • 3+ years exp • Bachelor's Degree • Singapore
JavaScript
Python
DevOps
AWS
Azure
GCP
Cybersecurity
ISO 27001
OWASP Top 10
Apply
$117k – $251k per year (Estimated) • Remote/Hybrid • Full-Time • Singapore
Apply
$74k – $126k per year (Estimated) • In office • Full-Time • Singapore
Python
Apply
$88k – $191k per year (Estimated) • Remote/Hybrid • Full-Time • 5+ years exp • Singapore
C++
Java
Kotlin
Python
Mobile
JUnit
DevOps
Git
gRPC
Jenkins
JFrog Artifactory
Shift-Left
Cybersecurity
Shift-Left Security
QA
Pytest
Robot Framework
TestNG
Apply
Senior AI Architect 7 hours ago
$138k – $304k per year (Estimated) • In office • Full-Time • 6+ years exp • Bachelor's Degree • Singapore
Python
SQL
Databases
Databricks
AI/ML
AI Agents
LangGraph
OpenAI
RAG
Spark
LangChain
DevOps
Azure
Apply
$64k – $189k per year (Estimated) • Remote/Hybrid • Full-Time • 1+ year exp • Bachelor's Degree • Singapore
Python
SQL
Databases
Apache Kafka
AI/ML
Amazon SageMaker
Kubeflow
MLFlow
Spark
Vertex AI
DevOps
AWS
Azure
Azure DevOps
CI/CD
Docker
GCP
GitLab
GitLab CI
Jenkins
Kubernetes
Apply
See all jobs
This is one of many
368,657 more open roles from verified company boards, updated every day.