IT Security Lead
8500 - 11000 SGDTescom-APAC
Role Overview
The IT Security Lead will be responsible for end-to-end security governance, implementation, compliance, and operational security for mission-critical system operating in a secured environment.
This role covers both:
Day 1 Security (Build / Project Implementation)
Day 2 Security (Operations / Production Support)
The Security Lead will work closely with Infra, System, and Software teams, InfoSec stakeholders, and external auditors to ensure the system complies with government security policies and standards.
Key Responsibilities
Day 1 – Project / Implementation Security
1. Security Architecture &Design
Define system security architecture aligned with Singapore Government security policies
Review application, middleware, infrastructure, and platform designs for security compliance.
Conduct threat modelling and risk assessments; map risks to mitigating controls
Translate policy requirements into actionable technical controls across the stack.
2. Compliance & Governance
Ensure compliance with:
IM8 / Government security policies
Whole‑of‑Government (WOG) security requirements
PDPA (where applicable)
Establish and oversee cyber security governance across infrastructure, application, and project teams.
Prepare and maintain documentation for:
Security Risk Assessment (SRA)
Vulnerability Assessment (VA)
Penetration Testing (PT)
Security hardening baselines and reports
3. Secure Development Oversight
Partner with software teams to enforce secure coding standards and DevSecOps practices.
Integrate and govern SAST/DAST, dependency/SCA scanning, and container image scanning in CI/CD.
Review and triage findings from tools (e.g., SonarQube, SCA, container scanners), drive remediation, and risk acceptance where needed.
Provide guidance on API security, token/secret management, and secure service-to-service communication.
4. Security Testing & Certification
Plan, coordinate, and manage VA/PT engagements and vendors.
Track findings through remediation to closure; document residual risk and risk acceptance.
Support all security clearances and go‑live certifications.
5. Security Hardening
Review and approve:
OS and baseline hardening
Middleware hardening
Database security configurations
Kubernetes / container security (RBAC, network policies, admission controls, secrets, image provenance)
API gateway / WAF / rate‑limiting / mTLS / OAuth2/OIDC configurations
Day 2 – Operations / Production Security
1. Incident Management
Lead security incident investigation, containment, and recovery.
Perform root cause analysis (RCA) and define corrective/preventive actions.
Coordinate with Gov SOC and stakeholders; contribute to and refine playbooks.
Provide clear, timely communications to both technical and non-technical audiences.
2. Vulnerability & Patch Management
Oversee continuous vulnerability monitoring and posture management.
Track patch and configuration compliance across infrastructure, middleware, applications, and containers.
Provide risk assessments and compensating controls for deferred patches.
3. Security Monitoring & Audit
Review and tune alerts, detections, and dashboards in SIEM and related tools.
Ensure monitoring coverage for critical systems and high‑value assets.
Support internal/external audits and evidence collection; close audit findings.
4. Compliance & Reporting
Prepare and present security posture, metrics, and trend reports to management.
Maintain risk registers and mitigation plans; ensure up‑to‑date security documentation.
Communicate security assessments and findings effectively to varied stakeholders.
5. Access Control Governance
Oversee and periodically review RBAC, MFA, Privileged Access Management (PAM), and joiner/mover/leaver processes.
Ensure least privilege, SoD, and periodic access recertifications.
6. Security Operations Contribution
Support incident response handling, log analysis, and activity reviews.
Drive continuous improvement across identify → protect → detect → respond → recover functions.
Required Qualifications & Experience
Mandatory
Singapore Citizen
Degree in Computer Science / Cybersecurity / Information Security or equivalent
8–12 years of IT experience, including ≥5 years as a Security Lead or Security Architect
Proven experience in Singapore Government IT projects and IM8/government security compliance
Hands-on experience with:
Kubernetes / Docker security
API security
Identity & Access Management (IAM)
Security tools (SAST/DAST/SIEM) and CI/CD-integrated security
Preferred Certifications (1–2+ of the following)
CISSP, CISM, CISA, CEH, GIAC (e.g., GSEC, GCIA, GCIH, GCSA)
AWS or Azure Security certifications
Key Competencies
Strong stakeholder management (Gov agencies, SOC, auditors, vendors, and delivery teams)
Ability to translate policy and risk into concrete technical controls and pragmatic delivery
Excellent documentation, reporting, and presentation skills
Risk-based decision making with clear rationale and traceability
Hands-on technical depth; able to deep dive in architecture, code, pipelines, and platforms
Clear communicator to both technical and non‑technical audiences
9000 - 11000 SGD
...Job Responsibilities Lead the design, implementation, and governance of enterprise security infrastructure across Identity & Access Management (IAM), Microsoft Entra ID... ...projects. Requirements ~9–12 years of experience in IT Infrastructure Security, IAM, and Cloud Security....6000 - 8000 SGD
...Job Summary The IT Security Lead manages end-to-end security governance, compliance, and operations for mission-critical systems, collaborating with cross-functional teams and external auditors to ensure adherence to government security policies. Responsibilities...4800 - 7000 SGD
...to be responsible for the implementation of physical and logical security policies and practices in SGP Card Production, Perso Center, and... ...network access controls and firewall rules To participate in new IT projects or solution implementations. To conduct security risk...8500 - 10000 SGD
...The Information Technology Security Officer(ITSO) is responsible for supporting the organization's cybersecuritygovernance, risk management... ...response, and security operationsactivities. The role ensures that IT systems, applications, and infrastructureare protected in...14000 - 15000 SGD
...We are partnering with a leading financial services firm to hire a Security Governance Lead for its Singapore office. This role will own the cybersecurity governance... ...across cybersecurity governance, technology risk, IT GRC, risk assurance, or technology audit ~ Strong...7500 - 8500 SGD
...IT Security Officer (ITSO) In this role, you will help ensure that vulnerabilities and exposures across our environment are identified, validated, and remediated in a timely manner, responsible for IM8 cybersecurity policy development work. You will work closely with system...10000 - 13000 SGD
...Our Client is an established company in Singapore, who is seeking to recruit an IT Security Architect. Responsibilities Security Architect is expected to lead solutioning partnerships with E level stakeholders from IT and business to define and deliver API, Cloud and...7000 - 9000 SGD
...Responsibilities: Incident Response & Security Monitoring Track, manage, and escalate cybersecurity incidents and critical security... ...Compliance Conduct periodic security reviews to ensure adherence to IT Security Policies, Standards, Controls and industry best...5000 - 5800 SGD
...exceed expectations. Job Summary You will develop and maintain security policies for cloud and hybrid environments, collaborate with... ...competencies and certifications Minimum eight (8) years of relevant IT experience deploying and managing security services for on-...7500 - 8500 SGD
...Summary: Lead the project delivery and implementation of security-related products across infrastructure and systems. Provide configuration, testing, and maintenance... ...assessments, and incident resolution. Ensure IT infrastructure and services meet prescribed service levels...4300 - 5400 SGD
...Job Description · We are looking for a detail-oriented Consultant, IT Security to support the organization's cybersecurity, governance, risk, and compliance initiatives. · The ideal candidate will have hands-on experience in IT security operations, vulnerability management...6000 - 8000 SGD
...About us: Our client are looking for an experienced IT Security Solution Engineer to design, implement, maintain, and support enterprise IT security infrastructure for customer environments. This role is ideal for someone with strong hands-on experience in firewall technologies...5500 - 7500 SGD
...are seeking a skilled and experienced Network Engineer to join our IT team. The successful candidate will be responsible for designing,... ...our growing network infrastructure, and to implement HO security policy to local infrastructure. This role requires deep knowledge...15000 - 22000 SGD
...Aboutthe Job: The Head of IT Security and Architecture owns both the security and architectural backbone of Tonik Bank's technology estate... ...assessments, and penetration testing. Establish and lead incident response efforts when necessary. • Security Awareness...8000 - 13500 SGD
...As an AI Security & Governance Architect, you will be responsible for embedding security, privacy, and compliance principles into the design... ...both technical and policy-level decisions • Good internal (IT, Networks, business) and external (suppliers, government) stakeholders...5000 - 8500 SGD
...As part of strengthening its technology governance and security function, the firm is looking to hire an IT Security Analyst (Governance & Security Operations) to... ...and incident response, working alongside the team lead. Job requirements At least 4 years of experience...7000 - 8100 SGD
...The IT Security Officer is responsible for protecting the integrity, availability, and confidentiality of key operational technology infrastructure. This role bridges cybersecurity expertise with an understanding of specialized environmental monitoring technologies, ensuring...6000 - 6800 SGD
...Job Summary The IT Security Officer safeguards the integrity, availability, and confidentiality of operational technology infrastructure supporting weather observation and forecasting systems, ensuring security, resilience, and compliance with national standards. Responsibilities...16000 - 18000 SGD
...transformation journey. The company is committed to strengthening its security posture, enhancing cyber resilience, and building a robust... ...strategy, roadmap, and security transformation initiatives. Lead information security governance, risk management, compliance, and...- ...Response Expertise About Our Client An organisation in the Technology & Telecoms industry. Job Description Monitor and manage security alerts and incidents to ensure a secure environment. Conduct in-depth analysis and investigation of security events and...
6500 - 10500 SGD
...government/regulated environment experience preferred ~ Ability to plan leave around scheduled GBBP and Pre-GBBP cycles ~ Experience with security tools and technologies, such as Security Information and Events Management, Data Loss Prevention, Database Activity Monitoring, Data...6500 - 9500 SGD
...We are looking for an experienced IT Infrastructure Team Lead / Manager to join our client’s project team. In this role, you will provide expert... ...projects are delivered on schedule, adhering to quality and security standards. Manage team activities, including planning,...11000 - 13800 SGD
...extensive networks, and a passion for matching talent to opportunities. Job Summary Join a fast-growing hedge fund as a Security Governance Lead to shape and drive cybersecurity governance, risk, and compliance programs within a lean, high-performing team....10000 - 14000 SGD
...established company in Singapore, who is seeking to recruit a Lead Cybersecurity Specialist (Security Operations). Lead Cybersecurity Specialist (Security... ...: Partner with CIOs to maintain a robust and updated IT asset inventory, ensuring that "you cannot protect what you...3000 - 4000 SGD
...Job Description Industry/ Organization Type: Security Solutions Provider Position Title: Security System IT Technician Working Location: Islandwide (office at Woodlands) Working Hours: 5.5 days (Mon – Fri: 9am - 6pm, Sat: 9am – 1pm) Salary Package: Basic + OT...6000 - 6500 SGD
...Job Responsibilities 1. Security Operations & BAU · Manage and administer configuration changes on production Firewalls, Web Application... ...Governance, Risk & Compliance · Partner hand in hand with the IT Governance team on setup alignment · Ensure day-to-day IT...7000 - 10000 SGD
...operational initiatives Collaborate with regional IT teams, including the China IT function, to... ...local regulations and organisational security standards, while maintaining alignment with... ...and connectivity requirements Lead and coordinate major incident response, operational...7000 - 9000 SGD
...Key Responsibilities Project Manage key IT asset related projects. Establish and lead the enterprise-wide IT Asset Management strategy, covering hardware... ..., and asset tracking processes. Collaborate with security teams to ensure asset hygiene, patch posture, and end‑...13000 - 16000 SGD
...will be a 2-years direct contract position. Responsibilities Lead and mentor junior PM. Define standards for discovery, PRDs,... ...dashboards for adoption/efficiency/quality. Manage risks (privacy/security, data quality, operational readiness). Responsibilities...5000 - 10000 SGD
...general corporate systems and guest/remote access. Own endpoint security, patch management, backup and disaster recovery for the entire... ...continuity, alongside routine backup operations. Establish and enforce IT security policy, acceptable use policy and onboarding/offboarding...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to IT Security Lead. Be the first to apply!
