The posting
IT MANAGER
Application Management | Project Governance | Security-First Delivery
Role purpose: Lead the secure, reliable and lifecycle-based management of enterprise applications while applying PMBOK-aligned project governance, strong vendor control and disciplined information security practices.
About the Role
Caritas Singapore is seeking an experienced IT Manager to lead application management, IT governance, project delivery and cybersecurity. The role is accountable for ensuring that enterprise applications remain fit for purpose, secure, compliant, well-supported and aligned with organizational and mission objectives throughout their lifecycle.
The successful candidate will combine hands-on application management expertise with PMBOK-aligned project management discipline and a security-first mindset, working closely with business stakeholders, vendors and leadership to deliver controlled, measurable and sustainable technology outcomes.
Key Responsibilities
- Application portfolio and lifecycle management: Own the application portfolio from demand, evaluation and implementation through operation, enhancement, integration, renewal and retirement.
- Application operations and service reliability: Oversee availability, performance, incident and problem management, release coordination, configuration, patching, documentation, support arrangements and service-level performance.
- Business application ownership: Act as the primary IT partner for enterprise platforms such as Microsoft 365, Salesforce, AWS and other line-of-business systems, translating business needs into governed and supportable solutions.
- Requirements and solution governance: Lead requirements gathering, process mapping, fit-gap analysis, functional specifications, solution evaluation, testing, user acceptance and benefits validation.
- PMBOK-aligned project delivery: Apply structured project governance across initiation, planning, execution, monitoring and controlling, and closure, including scope, schedule, cost, quality, resources, communications, risks, procurement and stakeholder management.
- Project controls and reporting: Maintain project charters, plans, milestones, budgets, RAID logs, change controls, decision logs, acceptance criteria, status reports and closure records.
- Security-first application management: Embed security and privacy requirements by design, including least-privilege access, segregation of duties, secure configuration, vulnerability and patch management, logging and monitoring, backup and recovery, data protection and periodic access reviews.
- Risk, compliance and audit readiness: Support PDPA obligations, organizational policies and relevant information security controls; maintain evidence, remediate findings and ensure applications are ready for internal and external audit.
- Vendor and commercial management: Manage vendors, contracts, licensing, procurement, renewals, support performance, security due diligence, data-processing obligations, exit requirements and total cost of ownership.
- Change, adoption and training: Plan stakeholder communications, training, knowledge transfer, support readiness and adoption activities to ensure changes are understood and sustained.
- IT strategy, policy and continuous improvement: Develop application roadmaps, standards, policies, SOPs and improvement plans that increase resilience, interoperability, user experience, operational efficiency and value.
- Budget and resource management: Plan and control application, project and operating expenditure; prioritize investments based on business value, risk, compliance needs and resource capacity.
Requirements
- Degree in Information Technology, Computer Science, Information Systems or a related discipline.
- At least 5 years of relevant experience in IT management, application management, enterprise systems or technology project delivery.
- Demonstrated experience managing business applications across the full lifecycle, including implementation, integration, support, upgrades, vendor coordination and retirement.
- Practical experience in requirements analysis, process improvement, system configuration, testing, UAT, release and change management, incident and problem management, and service-level monitoring.
- Strong knowledge of PMBOK principles and project governance, with experience producing project plans, RAID logs, change requests, status reports, acceptance records and closure documentation.
- Strong security-first mindset with working knowledge of identity and access management, least privilege, segregation of duties, vulnerability and patch management, secure configuration, logging, backup, disaster recovery, privacy and audit controls.
- Experience with at least one enterprise platform such as Microsoft 365, Salesforce or AWS; cross-platform integration experience is an advantage.
- Strong vendor, contract, licensing and stakeholder management capabilities, including the ability to challenge requirements and communicate risks in plain language.
- Experience in nonprofit, regulated or audit-intensive environments is an advantage.
Related Skills and Competencies
Competency Area
Related Skills
Application Management
Application portfolio management; application lifecycle management; service ownership; release, change, incident and problem management; configuration and asset documentation; roadmap and technical debt management.
Project Management
Business case development; project chartering; scope, schedule and cost control; quality planning; RAID management; stakeholder and communications management; procurement; change control; benefits realization and closure.
Business Analysis
Requirements elicitation; process mapping; fit-gap analysis; functional specifications; acceptance criteria; UAT coordination; data and integration requirements.
Information Security and Privacy
Security by design; access governance; secure configuration; vulnerability and patch management; logging and monitoring; backup and recovery; vendor risk; PDPA awareness; audit evidence management.
Technology and Integration
Enterprise SaaS and cloud platforms; APIs and system integration; data migration; identity and access management; reporting and automation; environment and release controls.
Leadership and Communication
Business partnering; vendor governance; negotiation; executive reporting; facilitation; training; change adoption; documentation and knowledge transfer.
Preferred Certifications
- PMP, PRINCE2 or equivalent project management certification.
- ITIL or equivalent IT service management certification.
- Microsoft/Azure, Salesforce, AWS or application/platform certifications.
- Cybersecurity, audit or governance certifications such as CISA, CISSP, CRISC or ISO/IEC 27001-related credentials.
Why Join Us
Be part of a mission-driven organization making a meaningful impact while leading secure application modernization, strengthening project and technology governance, and improving the reliability, efficiency and value of digital services.
- How to Apply Interested candidates are invited to submit their resume and cover letter to [email protected] by 30 September 2026. Caritas Singapore is an equal opportunity employer. We welcome applicants from all backgrounds and encourage individuals passionate about social impact and community service to apply. Important Notice We do not collect the following: NRIC/FIN or national identifiers Photo Date of birth / Age Spouse/Family information Please do not include these in your application.



