Senior Cybersecurity Governance Specialist
GovTech
| Company | GovTech |
| Category | Security |
| Location | Singapore |
| Remote | On-site (inferred) |
| Employment | Not stated |
| Level | Senior |
| Salary | Not stated by the employer |
| Posted | 22 May 2026 |
| Last verified | 9 Aug 2026 |
| Source | Employer ATS (greenhouse) |
Description
[What the role is]
GovTech is the lead agency driving Singapore’s Smart Nation initiatives and public sector digital transformation. As the Centre of Excellence for Infocomm Technology and Smart Systems (ICT & SS), GovTech develops the Singapore Government’s capabilities in Data Science & Artificial Intelligence, Application Development, Smart City Technology, Digital Infrastructure, and Cybersecurity.
At GovTech, we offer you a purposeful career to make lives better where we empower our people to master their craft through robust learning and development opportunities all year round.
Play a part in Singapore’s vision to build a Smart Nation and embark on your meaningful journey to build tech for public good. Join us to advance our mission and shape your future with us today!
Learn more about GovTech at tech.gov.sg.
[What you will be working on]
The Cyber Security Group (CSG) is the cybersecurity arm of GovTech. CSG is committed to create a digital government that is safe and secure. CSG delivers technical and operational capabilities to counteract cyber threats, provides thought leadership on transformative cybersecurity governance and policies and to strengthen the cybersecurity posture of government agencies in a manner that is sustainable, pragmatic, and effective.
To enhance infocomm security capabilities in GovTech and the Whole-of-Government (WOG), GovTech appoints Chief Information Security Officer (CISO) teams at the various ministries to oversee infocomm security management.
Reporting to the Ministry CISO (MCISO), you will be the primary architect of the Ministry’s security governance and risk management framework. You will ensure that all agencies within the Ministry Family operate under a unified, effective, and modern security standard. Your mission is to transform GRC from a compliance-heavy exercise into a strategic enabler. You will establish the frameworks that allow the Ministry Family to adopt new technologies with confidence, moving away from a "risk-averse" posture toward a "risk-informed" one . You will ensure that risk management is deeply integrated into the lifecycle of every digital system, from web applications to critical Operational Technology (OT) environments.
Key Responsibilities
Enterprise Risk Governance & Management
Dynamic Risk Registers: Establish and oversee the Ministry-wide security risk register. You will ensure that registers are not static documents but "living" tools that accurately reflect the current threat landscape and project status across all agencies.
Senior Management Facilitation: Lead and facilitate high-level risk conversations with Senior Management and Agency CIOs. You must be able to translate complex technical risks into clear business impacts to drive informed resource allocation and prioritisation.
Risk Analysis Framework: Develop a robust framework to guide agencies in performing consistent, high-quality risk analysis. This framework should empower agencies to take calculated risks for innovation rather than defaulting to "no" due to risk aversion.
Threat Risk Assessment (TRA) & Standards
Unified TRA Framework: Establish and maintain Ministry-wide standards for conducting Threat Risk Assessments across diverse domains, including Cloud (GCC), Web Applications, and OT/ICS systems.
Crown Jewel Identification: Develop SOPs to guide agency project teams in identifying "Crown Jewels" (Critical Information Assets) and mapping comprehensive threat vectors.
Standardisation of Controls: D