Lead Cybersecurity Engineer
GovTech
| Company | GovTech |
| Category | Engineering |
| Location | Singapore |
| Remote | On-site (inferred) |
| Employment | Not stated |
| Level | Lead |
| Salary | Not stated by the employer |
| Posted | 17 Jul 2026 |
| Last verified | 30 Jul 2026 |
| Source | Employer career page (greenhouse) |
Description
GovTech is the lead agency driving Singapore’s Smart Nation initiatives and public sector digital transformation. As the Centre of Excellence for Infocomm Technology and Smart Systems (ICT & SS), GovTech develops the Singapore Government’s capabilities in Data Science & Artificial Intelligence, Application Development, Smart City Technology, Digital Infrastructure, and Cybersecurity. At GovTech, we offer you a purposeful career to make lives better where we empower our people to master their craft through robust learning and development opportunities all year round. Play a part in Singapore’s vision to build a Smart Nation and embark on your meaningful journey to build tech for public good. Join us to advance our mission and shape your future with us today! Learn more about GovTech at tech.gov.sg.
Government Commercial Cloud (GCC) is a key platform within Singapore Government Technology Stacks that enables government agencies to build and operate digital services on commercial cloud. The GCC Engineering team develops platform automations, landing zones, and security tooling across AWS, Azure, and GCP — serving thousands of government systems and thousands of public officers.
Security at GCC is not a side function — it's core to the platform's value proposition. Government agencies trust GCC to be secure by default.
You are the single named owner of security outcomes across all engineering teams in GCC. You define how security works — the standards, processes, escalation paths, and technical approaches — and drive adoption through influence, not authority. You operate through a Security Champions network: persistent, named engineers in each product team who own security judgment locally, coordinated by you. Your accountability is whether GCC is actually secure — measured through process health, incident response quality, and security posture metrics you define.
This role is part of the organisation's domain leadership structure — you join alongside Engineering Managers as a peer, not as a report to any EM. The Security domain is being stood up fresh. The previous model (centralised security team gatekeeping all decisions) has been retired. You inherit a Champions network in early stages, documented runbooks, and interim coverage from a senior security advisor. Your job is to take it from "interim bridge" to "sustainable, scalable security function."
The domain scope will evolve. Today it centres on the areas listed above — but we expect the role to grow into adjacent areas (AI security, detection engineering) as the organisation's needs develop. Adaptability and willingness to define your own frontier matters more than deep expertise in every area on day one.
[What you will be working on]
Security Architecture & Posture
Own the organisation's security posture across all product teams and cloud environments
Architect security frameworks that integrate into engineering workflows without creating bottlenecks
Design and evolve threat modelling methodologies adapted to the organisation's multi-cloud, multi-tenant context
Define escalation paths, severity frameworks, and incident response playbooks
Own the relationship with GCSOC, shaping how external security signals translate into internal action
Drive security tooling strategy — selecting, configuring, and setting alert thresholds that distinguish signal from noise
Standards & Process Design
Define security standards, runbooks, and compliance approaches that teams can self-serve against
Design the Security Champions model: training curriculum, forum cadence, escalation criteria, and what "good" looks like for a champion
Replace gatekeeping with enablement — move from "security reviews everything" to "teams self-certify against clear criteria, you spot-check and c
970,107 openings. Erioun finds yours.Scored against your own profile, every hour.Try the radar →