Senior Cybersecurity Engineer (GeBIZ X)
GovTech
| Company | GovTech |
| Category | Engineering |
| Location | Singapore |
| Remote | On-site (inferred) |
| Employment | Not stated |
| Level | Senior |
| Salary | Not stated by the employer |
| Posted | 21 Jul 2026 |
| Last verified | 9 Aug 2026 |
| Source | Employer ATS (greenhouse) |
Description
Our multidisciplinary team comprises product managers, engineers, designers professionals passionate about delivering secure digital services for the Singapore Public Service.
You will work closely with CISOs, business owners, GovTech, technology partners and government agencies to build secure-by-design capabilities while shaping cybersecurity practices across the GeBIZ X ecosystem.
We are looking for an experienced Senior Cybersecurity Engineer who is passionate about designing secure, resilient, and scalable digital platforms across cloud, SaaS, and enterprise environments.
In this role, you will lead the design, implementation, and continual improvement of cybersecurity controls across the GeBIZ X ecosystem, encompassing the Ivalua SaaS platform, integrated Whole-of-Government (WOG) agency systems, and the Singapore Government Tech Stack (SGTS), connected through the MOF Orchestrator—the common integration platform.
Beyond engineering, you will play a pivotal role in cybersecurity governance, risk management, audit readiness, and security assurance. Working closely with GovTech, WOG agencies, business stakeholders, and technology partners, you will champion secure-by-design principles, strengthen cyber resilience, and ensure compliance with Singapore Government ICT security policies, standards, and regulatory requirements.
You will apply Singapore Government ICT security policies, standards, and industry best practices, including IM8, the GovTech Cybersecurity Playbooks for Software-as-a-Service (SaaS) Security and Large Language Model (LLM) Applications, as well as ISO/IEC 27001 and ISO/IEC 27018, to drive secure SaaS configuration, vendor risk management, protection of Personally Identifiable Information (PII) in cloud environments, and compliance with AI governance and security directives issued by the Smart Nation and Digital Government Office (SNDGO) and the AI Governance Division (AIDG).
Technical Leadership Expectations
Lead the design, implementation, and continual improvement of cybersecurity controls across the GeBIZ X ecosystem, ensuring secure-by-design principles are embedded throughout the solution lifecycle.
Define cybersecurity requirements and provide technical consultancy on application, cloud, and system security architecture, ensuring compliance with IM8 and prevailing Government ICT security policies and standards.
Lead security architecture reviews, threat modelling, security design reviews, and VAPT remediation planning for cloud-native, SaaS, COTS, and enterprise integrations.
Drive cybersecurity risk assessments and recommend appropriate security controls to address emerging threats and evolving business requirements.
Strengthen GeBIZ X's cybersecurity posture by applying Singapore Government ICT security policies, standards, and industry best practices, including IM8, the GovTech Cybersecurity Playbooks for Software-as-a-Service (SaaS) Security and Large Language Model (LLM) Applications, as well as ISO/IEC 27001 and ISO/IEC 27018, to drive secure SaaS configuration, vendor risk management, protection of Personally Identifiable Information (PII) in cloud environments, and compliance with AI governance and security directives issued by the Smart Nation and Digital Government Office (SNDGO) and the AI Governance Division (AIDG).
Ownership
Take ownership of the end-to-end cybersecurity delivery for complex and ambiguously scoped initiatives, making sound technical decisions and driving workstreams through to successful implementation.
Lead the development and maintenance of cybersecurity governance artefacts, including System Security Plans (SSPs), System Criticality Assessments (SCAs), Security Risk Assessments (SRAs), Risk Treatment Plans, and audit remediation reports.
Lead and coordinate internal and external cybersecurity audits, including GIROC and IM8 audits, ensuring audit readiness, timely evidence subm