Skip to content

Open nowPosted 30 days ago

Senior IT Security Officer for MOE (2 years contract)

MyCareersFuture94,028 open roles

Pay
SGD 8,500 – SGD 10,000 a month
Where
Central, Singapore
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSenior IT Security Officer for MOE (2 years contract)MyCareersFuture · Central, Singapore
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on MyCareersFuture's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.7% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.6%1 day
  2. 3.3%3 days
  3. 7.7%7 days
  4. 14.0%14 days
  5. 33.7%30 days
This job: posted 30 days ago

The posting

[2 years contract]

1. Role Purpose

The Senior IT Security Officer is responsible for providingcybersecurity governance, risk management, security assurance and securityadvisory across ICT systems, digital services, cloud platforms andinfrastructure supporting a Singapore Public Sector organisation.

The role works closely with system owners, application teams,infrastructure and cloud teams, cybersecurity operations, enterprisearchitects, project managers, vendors and management to ensure that securityrisks are identified early, controls are proportionate and effective, andsystems are operated in accordance with applicable Government ICT&SSpolicies and standards, organisational requirements, contractual obligationsand recognised cybersecurity good practices.

2. Key Responsibilities

2.1 Cybersecurity Governance and Risk Management

· Provide independentcybersecurity governance and advisory across the project and system lifecycle.

· Lead or review cybersecurityrisk assessments, including threat identification, vulnerability analysis,attack-path considerations, inherent risk, residual risk, compensating controlsand risk treatment plans.

· Ensure material security risks,deviations and exceptions are properly documented, justified, tracked,escalated and formally accepted by the appropriate risk owner when required.

· Monitor recurring control gaps,overdue remediation and systemic risks, and recommend programme-levelcorrective actions.

· Maintain clear securitydecision records, evidence and audit trails for governance and managementassurance.

2.2 Security Architecture and Security-by-Design

· Review application, cloud,infrastructure, network, identity and integration architectures for securityrisks and control gaps.

· Assess trust boundaries, dataflows, privileged access paths, external exposure, administrative interfaces,API integrations and dependency risks.

· Challenge security assumptionsand ensure proportionate preventive, detective and recovery controls areincluded before production implementation.

· Advise teams on secure designpatterns for authentication, authorisation, encryption, secrets, logging,segmentation, resilience and least privilege.

· Participate in architecturereview boards, design reviews, go-live readiness reviews and securityacceptance decisions.

2.3 Cloud, Identity and Platform Security

· Assess cloud security designsand configurations across AWS, Microsoft Azure and/or Google Cloud, includingIAM, network controls, workload protection, encryption, key management, loggingand monitoring.

· Review identity and accessmanagement controls including MFA, privileged access, RBAC, service accounts,workload identities, conditional access and access lifecycle management.

· Assess Zero Trust, ZTNA, remoteaccess, endpoint security and security service integrations where applicable.

· Evaluate security implicationsof SaaS, managed services, containers, Kubernetes and other modern platformtechnologies.

2.4 Vulnerability Management, VA/PT and Security Testing

· Review vulnerability findingsand determine practical risk, remediation priority and required treatment basedon business context and exploitability.

· Track remediation againstapplicable service levels and escalate overdue or repeated high-risk findings.

· Define or review securitytesting requirements, including vulnerability assessment, penetration testing,application security testing, configuration review and other assuranceactivities.

· Review test reports, validateremediation evidence and challenge inappropriate risk acceptance or weakcompensating controls.

· Support secure developmentpractices by reviewing relevant SAST, DAST, SCA, API security and CI/CDsecurity evidence where applicable.

2.5 Security Operations and Incident Response

· Work with SOC and securityoperations teams to ensure appropriate logging, telemetry, alerting, detectionuse cases and escalation paths exist for critical systems.

· Participate in or coordinatecybersecurity incident response, investigation, containment, eradication,recovery and lessons-learned activities as required.

· Translate incident findings andadversary techniques into preventive improvements, detection requirements andremediation actions.

· Assess emergingvulnerabilities, CVEs and threat intelligence to determine applicability andpriority for systems within the assigned portfolio.

· Support cyber exercises,tabletop exercises and operational readiness testing.

2.6 Cyber Resilience and Recovery

· Review cybersecurity aspects ofbusiness continuity, disaster recovery, backup, restoration and ransomwareresilience arrangements.

· Assess recovery dependencies,privileged recovery paths, backup protection, immutability and recovery testevidence.

· Participate in disasterrecovery and cyber resilience exercises and ensure security lessons are trackedto closure.

2.7 Stakeholder Management, Reporting and Leadership

· Act as a trusted cybersecurityadvisor to project teams, system owners, business stakeholders and seniormanagement.

· Explain complex cybersecurityrisks in clear business language and recommend practical options fordecision-making.

· Prepare concise managementreports covering key risks, vulnerabilities, incidents, audit findings,remediation progress and security posture.

· Mentor junior ITSOs andcontribute to consistent security assessment methods, templates, playbooks andstandards across the organisation.

· Escalate material risksobjectively and maintain independence when reviewing solutions or riskacceptance requests.

3. Minimum Requirements

· Minimum 7 years of relevant ITor cybersecurity experience, with substantial experience in cybersecuritygovernance, risk management, security assurance, architecture, operations,cloud security, audit or security consulting.

· At least 3 years of experienceindependently reviewing or governing enterprise-scale systems, major ICTprojects or government/public-sector environments.

· Demonstrated ability to conductor critically review cybersecurity risk assessments and recommend proportionatetechnical and governance controls.

· Strong understanding ofenterprise security architecture across applications, infrastructure, networks,cloud, identity and security operations.

· Experience working withtechnical teams, project management, auditors, vendors and senior stakeholders.

· Strong written and verbalcommunication skills, including the ability to produce clear risk statements,security recommendations, management papers and audit responses.

· Ability to work independently,exercise professional judgement and escalate material risk where necessary.

· Relevant degree inCybersecurity, Information Systems, Computer Science, Engineering or a relateddiscipline; equivalent professional experience may be considered.

4. Professional Certifications

The candidate should possess at least one current recognisedprofessional cybersecurity certification. Suitable certifications include:

·CISSP - Certified InformationSystems Security Professional

·CISM - Certified InformationSecurity Manager

·CRISC - Certified in Risk andInformation Systems Control

·CISA - Certified InformationSystems Auditor

·CCSP - Certified Cloud SecurityProfessional

·CGEIT - Certified in theGovernance of Enterprise IT

·Relevant GIAC certifications orequivalent professional cybersecurity certifications

5. Framework and Standards Knowledge

The Senior ITSO should have practical working knowledge of relevantframeworks and be able to apply them proportionately rather than as achecklist. Useful knowledge includes:

·Applicable Singapore GovernmentICT&SS cybersecurity policies, standards, control requirements andagency-specific security directives.

· ISO/IEC 27001 and ISO/IEC27002.

·NIST Cybersecurity Frameworkand relevant NIST SP 800-series guidance.

· CIS Controls and CISBenchmarks.

·MITRE ATT&CK forunderstanding adversary tactics and techniques.

·OWASP guidance for webapplication and API security.

·Cloud security good practicesand shared-responsibility principles.

·Applicable legal, regulatoryand data-protection requirements, including PDPA and sector-specificobligations where relevant.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against MyCareersFuture's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on MyCareersFuture's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    MyCareersFuture's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.