Sign up to access all features of our service
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

IT Security Lead

8500 - 11000 SGD
Full-time

Tescom-APAC

Role Overview

The IT Security Lead will be responsible for end-to-end security governance, implementation, compliance, and operational security for mission-critical system operating in a secured environment.

This role covers both:

Day 1 Security (Build / Project Implementation)

Day 2 Security (Operations / Production Support)

The Security Lead will work closely with Infra, System, and Software teams, InfoSec stakeholders, and external auditors to ensure the system complies with government security policies and standards.

Key Responsibilities

Day 1 – Project / Implementation Security

1. Security Architecture &Design
Define system security architecture aligned with Singapore Government security policies
Review application, middleware, infrastructure, and platform designs for security compliance.
Conduct threat modelling and risk assessments; map risks to mitigating controls
Translate policy requirements into actionable technical controls across the stack.

2. Compliance & Governance

Ensure compliance with:

IM8 / Government security policies
Whole‑of‑Government (WOG) security requirements
PDPA (where applicable)
Establish and oversee cyber security governance across infrastructure, application, and project teams.

Prepare and maintain documentation for:

Security Risk Assessment (SRA)
Vulnerability Assessment (VA)
Penetration Testing (PT)
Security hardening baselines and reports

3. Secure Development Oversight

Partner with software teams to enforce secure coding standards and DevSecOps practices.

Integrate and govern SAST/DAST, dependency/SCA scanning, and container image scanning in CI/CD.

Review and triage findings from tools (e.g., SonarQube, SCA, container scanners), drive remediation, and risk acceptance where needed.

Provide guidance on API security, token/secret management, and secure service-to-service communication.

4. Security Testing & Certification

Plan, coordinate, and manage VA/PT engagements and vendors.

Track findings through remediation to closure; document residual risk and risk acceptance.

Support all security clearances and go‑live certifications.

5. Security Hardening

Review and approve:

OS and baseline hardening
Middleware hardening
Database security configurations
Kubernetes / container security (RBAC, network policies, admission controls, secrets, image provenance)
API gateway / WAF / rate‑limiting / mTLS / OAuth2/OIDC configurations

Day 2 – Operations / Production Security

1. Incident Management

Lead security incident investigation, containment, and recovery.

Perform root cause analysis (RCA) and define corrective/preventive actions.

Coordinate with Gov SOC and stakeholders; contribute to and refine playbooks.

Provide clear, timely communications to both technical and non-technical audiences.

2. Vulnerability & Patch Management

Oversee continuous vulnerability monitoring and posture management.

Track patch and configuration compliance across infrastructure, middleware, applications, and containers.

Provide risk assessments and compensating controls for deferred patches.

3. Security Monitoring & Audit

Review and tune alerts, detections, and dashboards in SIEM and related tools.
Ensure monitoring coverage for critical systems and high‑value assets.
Support internal/external audits and evidence collection; close audit findings.

4. Compliance & Reporting

Prepare and present security posture, metrics, and trend reports to management.

Maintain risk registers and mitigation plans; ensure up‑to‑date security documentation.

Communicate security assessments and findings effectively to varied stakeholders.

5. Access Control Governance

Oversee and periodically review RBAC, MFA, Privileged Access Management (PAM), and joiner/mover/leaver processes.

Ensure least privilege, SoD, and periodic access recertifications.

6. Security Operations Contribution

Support incident response handling, log analysis, and activity reviews.

Drive continuous improvement across identify → protect → detect → respond → recover functions.

Required Qualifications & Experience

Mandatory

Singapore Citizen

Degree in Computer Science / Cybersecurity / Information Security or equivalent

8–12 years of IT experience, including ≥5 years as a Security Lead or Security Architect

Proven experience in Singapore Government IT projects and IM8/government security compliance

Hands-on experience with:

Kubernetes / Docker security
API security
Identity & Access Management (IAM)
Security tools (SAST/DAST/SIEM) and CI/CD-integrated security

Preferred Certifications (1–2+ of the following)

CISSP, CISM, CISA, CEH, GIAC (e.g., GSEC, GCIA, GCIH, GCSA)

AWS or Azure Security certifications

Key Competencies

Strong stakeholder management (Gov agencies, SOC, auditors, vendors, and delivery teams)

Ability to translate policy and risk into concrete technical controls and pragmatic delivery

Excellent documentation, reporting, and presentation skills

Risk-based decision making with clear rationale and traceability

Hands-on technical depth; able to deep dive in architecture, code, pipelines, and platforms

Clear communicator to both technical and non‑technical audiences

Vacancy posted 13 days ago
Similar jobs that could be interesting for youBased on the IT Security Lead in Singapore vacancy
  • 9000 - 11000 SGD

     ...Job Responsibilities Lead the design, implementation, and governance of enterprise security infrastructure across Identity & Access Management (IAM), Microsoft Entra ID...  ...projects. Requirements ~9–12 years of experience in IT Infrastructure Security, IAM, and Cloud Security.... 

    SAGL CONSULTING PTE. LTD.

    Singapore
    12 days ago
  • 6000 - 8000 SGD

     ...Job Summary The IT Security Lead manages end-to-end security governance, compliance, and operations for mission-critical systems, collaborating with cross-functional teams and external auditors to ensure adherence to government security policies. Responsibilities... 

    MAESTRO HUMAN RESOURCE PTE. LTD.

    Singapore
    a month ago
  • 4800 - 7000 SGD

     ...to be responsible for the implementation of physical and logical security policies and practices in SGP Card Production, Perso Center, and...  ...network access controls and firewall rules To participate in new IT projects or solution implementations. To conduct security risk... 

    THALES DIS (SINGAPORE) PTE. LTD.

    Singapore
    3 days ago
  • 8500 - 10000 SGD

     ...The Information Technology Security Officer(ITSO) is responsible for supporting the organization's cybersecuritygovernance, risk management...  ...response, and security operationsactivities. The role ensures that IT systems, applications, and infrastructureare protected in... 

    TESCOM (SINGAPORE) SOFTWARE SYSTEMS TESTING PTE LTD.

    Singapore
    5 days ago
  • 14000 - 15000 SGD

     ...We are partnering with a leading financial services firm to hire a Security Governance Lead for its Singapore office. This role will own the cybersecurity governance...  ...across cybersecurity governance, technology risk, IT GRC, risk assurance, or technology audit ~ Strong... 

    PINPOINT ASIA INFOTECH PTE. LTD.

    Singapore
    17 days ago
  • 7500 - 8500 SGD

     ...IT Security Officer (ITSO) In this role, you will help ensure that vulnerabilities and exposures across our environment are identified, validated, and remediated in a timely manner, responsible for IM8 cybersecurity policy development work. You will work closely with system... 

    RAPSYS TECHNOLOGIES PTE. LTD.

    Singapore
    3 days ago
  • 10000 - 13000 SGD

     ...Our Client is an established company in Singapore, who is seeking to recruit an IT Security Architect. Responsibilities Security Architect is expected to lead solutioning partnerships with E level stakeholders from IT and business to define and deliver API, Cloud and... 

    JJ CONSULTING SERVICES

    Singapore
    5 days ago
  • 7000 - 9000 SGD

     ...Responsibilities: Incident Response & Security Monitoring Track, manage, and escalate cybersecurity incidents and critical security...  ...Compliance Conduct periodic security reviews to ensure adherence to IT Security Policies, Standards, Controls and industry best... 

    PCCW SOLUTIONS INSYS PTE. LTD.

    Singapore
    10 days ago
  • 5000 - 5800 SGD

     ...exceed expectations. Job Summary You will develop and maintain security policies for cloud and hybrid environments, collaborate with...  ...competencies and certifications Minimum eight (8) years of relevant IT experience deploying and managing security services for on-... 

    RAPSYS TECHNOLOGIES PTE. LTD.

    Singapore
    13 days ago
  • 7500 - 8500 SGD

     ...Summary: Lead the project delivery and implementation of security-related products across infrastructure and systems. Provide configuration, testing, and maintenance...  ...assessments, and incident resolution. Ensure IT infrastructure and services meet prescribed service levels... 

    NEWTONE CONSULTING PTE. LTD.

    Singapore
    18 days ago
  • 4300 - 5400 SGD

     ...Job Description · We are looking for a detail-oriented Consultant, IT Security to support the organization's cybersecurity, governance, risk, and compliance initiatives.  · The ideal candidate will have hands-on experience in IT security operations, vulnerability management... 

    ELLIOTT MOSS CONSULTING PTE. LTD.

    Singapore
    18 days ago
  • 6000 - 8000 SGD

     ...About us: Our client are looking for an experienced IT Security Solution Engineer to design, implement, maintain, and support enterprise IT security infrastructure for customer environments. This role is ideal for someone with strong hands-on experience in firewall technologies... 

    ALWAYSHIRED PTE. LTD.

    Singapore
    5 days ago
  • 5500 - 7500 SGD

     ...are seeking a skilled and experienced Network Engineer to join our IT team. The successful candidate will be responsible for designing,...  ...our growing network infrastructure, and to implement HO security policy to local infrastructure. This role requires deep knowledge... 

    CHINA MERCHANTS BANK CO., LTD

    Singapore
    2 days ago
  • 15000 - 22000 SGD

     ...Aboutthe Job: The Head of IT Security and Architecture owns both the security and architectural backbone of Tonik Bank's technology estate...  ...assessments, and penetration testing. Establish and lead incident response efforts when necessary. • Security Awareness... 

    TONIK FINANCIAL PTE. LTD.

    Singapore
    16 days ago
  • 8000 - 13500 SGD

     ...As an AI Security & Governance Architect, you will be responsible for embedding security, privacy, and compliance principles into the design...  ...both technical and policy-level decisions • Good internal (IT, Networks, business) and external (suppliers, government) stakeholders... 

    ITCAN PTE. LIMITED

    Singapore
    2 days ago
  • 5000 - 8500 SGD

     ...As part of strengthening its technology governance and security function, the firm is looking to hire an IT Security Analyst (Governance & Security Operations) to...  ...and incident response, working alongside the team lead. Job requirements At least 4 years of experience... 

    BEATHCHAPMAN (PTE. LTD.)

    Singapore
    2 days ago
  • 7000 - 8100 SGD

     ...The IT Security Officer is responsible for protecting the integrity, availability, and confidentiality of key operational technology infrastructure. This role bridges cybersecurity expertise with an understanding of specialized environmental monitoring technologies, ensuring... 

    RAPSYS TECHNOLOGIES PTE. LTD.

    Singapore
    24 days ago
  • 6000 - 6800 SGD

     ...Job Summary The IT Security Officer safeguards the integrity, availability, and confidentiality of operational technology infrastructure supporting weather observation and forecasting systems, ensuring security, resilience, and compliance with national standards. Responsibilities... 

    KNOWLEDGE COMPUTERS PTE. LTD.

    Singapore
    26 days ago
  • 16000 - 18000 SGD

     ...transformation journey. The company is committed to strengthening its security posture, enhancing cyber resilience, and building a robust...  ...strategy, roadmap, and security transformation initiatives. Lead information security governance, risk management, compliance, and... 

    ROBERT HALF INTERNATIONAL PTE. LTD.

    Singapore
    24 days ago
  •  ...Response Expertise About Our Client An organisation in the Technology & Telecoms industry. Job Description Monitor and manage security alerts and incidents to ensure a secure environment. Conduct in-depth analysis and investigation of security events and... 

    Michael Page

    Singapore
    5 days ago
  • 6500 - 10500 SGD

     ...government/regulated environment experience preferred ~ Ability to plan leave around scheduled GBBP and Pre-GBBP cycles ~ Experience with security tools and technologies, such as Security Information and Events Management, Data Loss Prevention, Database Activity Monitoring, Data... 

    OPTIMUM SOLUTIONS (SINGAPORE) PTE LTD

    Singapore
    16 days ago
  • 6500 - 9500 SGD

     ...We are looking for an experienced IT Infrastructure Team Lead / Manager to join our client’s project team. In this role, you will provide expert...  ...projects are delivered on schedule, adhering to quality and security standards. Manage team activities, including planning,... 

    NEWTONE CONSULTING PTE. LTD.

    Singapore
    24 days ago
  • 11000 - 13800 SGD

     ...extensive networks, and a passion for matching talent to opportunities. Job Summary Join a fast-growing hedge fund as a Security Governance Lead to shape and drive cybersecurity governance, risk, and compliance programs within a lean, high-performing team.... 

    DAULFIN GREY HR PTE. LTD.

    Singapore
    13 days ago
  • 10000 - 14000 SGD

     ...established company in Singapore, who is seeking to recruit a Lead Cybersecurity Specialist (Security Operations). Lead Cybersecurity Specialist (Security...  ...: Partner with CIOs to maintain a robust and updated IT asset inventory, ensuring that "you cannot protect what you... 

    JJ CONSULTING SERVICES

    Singapore
    4 days ago
  • 3000 - 4000 SGD

     ...Job Description Industry/ Organization Type: Security Solutions Provider Position Title: Security System IT Technician Working Location: Islandwide (office at Woodlands) Working Hours: 5.5 days (Mon – Fri: 9am - 6pm, Sat: 9am – 1pm) Salary Package: Basic + OT... 

    ANRADUS PTE. LTD.

    Singapore
    2 days ago
  • 6000 - 6500 SGD

     ...Job Responsibilities 1. Security Operations & BAU · Manage and administer configuration changes on production Firewalls, Web Application...  ...Governance, Risk & Compliance · Partner hand in hand with the IT Governance team on setup alignment · Ensure day-to-day IT... 

    AUTO & GENERAL (SEA) SERVICES PTE. LIMITED

    Singapore
    3 days ago
  • 7000 - 10000 SGD

     ...operational initiatives Collaborate with regional IT teams, including the China IT function, to...  ...local regulations and organisational security standards, while maintaining alignment with...  ...and connectivity requirements Lead and coordinate major incident response, operational... 

    HEPTAGON PHOTONICS PTE. LTD.

    Singapore
    17 days ago
  • 7000 - 9000 SGD

     ...Key Responsibilities Project Manage key IT asset related projects. Establish and lead the enterprise-wide IT Asset Management strategy, covering hardware...  ..., and asset tracking processes.​ Collaborate with security teams to ensure asset hygiene, patch posture, and end‑... 

    TANGSPAC CONSULTING PTE LTD

    Singapore
    17 days ago
  • 13000 - 16000 SGD

     ...will be a 2-years direct contract position. Responsibilities Lead and mentor junior PM. Define standards for discovery, PRDs,...  ...dashboards for adoption/efficiency/quality. Manage risks (privacy/security, data quality, operational readiness). Responsibilities... 

    ETHOS SEARCH ASSOCIATES PTE. LTD.

    Singapore
    17 days ago
  • 5000 - 10000 SGD

     ...general corporate systems and guest/remote access. Own endpoint security, patch management, backup and disaster recovery for the entire...  ...continuity, alongside routine backup operations. Establish and enforce IT security policy, acceptable use policy and onboarding/offboarding... 

    STAR LABS SG PTE. LTD.

    Singapore
    21 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to IT Security Lead. Be the first to apply!