Job Opportunities API

The Public Ledger of Openings

← Back to the ledger

Lead Cybersecurity Engineer

GovTech
CompanyGovTech
CategoryEngineering
LocationSingapore
RemoteOn-site (inferred)
EmploymentNot stated
LevelLead
SalaryNot stated by the employer
Posted17 Jul 2026
Last verified30 Jul 2026
SourceEmployer career page (greenhouse)
Applications are handled by the employer, not by us.Apply on the employer's site →
Description
GovTech is the lead agency driving Singapore’s Smart Nation initiatives and public sector digital transformation. As the Centre of Excellence for Infocomm Technology and Smart Systems (ICT & SS), GovTech develops the Singapore Government’s capabilities in Data Science & Artificial Intelligence, Application Development, Smart City Technology, Digital Infrastructure, and Cybersecurity.      At GovTech, we offer you a purposeful career to make lives better where we empower our people to master their craft through robust learning and development opportunities all year round.     Play a part in Singapore’s vision to build a Smart Nation and embark on your meaningful journey to build tech for public good. Join us to advance our mission and shape your future with us today!      Learn more about GovTech at tech.gov.sg.     Government Commercial Cloud (GCC) is a key platform within Singapore Government Technology Stacks that enables government agencies to build and operate digital services on commercial cloud. The GCC Engineering team develops platform automations, landing zones, and security tooling across AWS, Azure, and GCP — serving thousands of government systems and thousands of public officers. Security at GCC is not a side function — it's core to the platform's value proposition. Government agencies trust GCC to be secure by default. You are the single named owner of security outcomes across all engineering teams in GCC. You define how security works — the standards, processes, escalation paths, and technical approaches — and drive adoption through influence, not authority. You operate through a Security Champions network: persistent, named engineers in each product team who own security judgment locally, coordinated by you. Your accountability is whether GCC is actually secure — measured through process health, incident response quality, and security posture metrics you define. This role is part of the organisation's domain leadership structure — you join alongside Engineering Managers as a peer, not as a report to any EM. The Security domain is being stood up fresh. The previous model (centralised security team gatekeeping all decisions) has been retired. You inherit a Champions network in early stages, documented runbooks, and interim coverage from a senior security advisor. Your job is to take it from "interim bridge" to "sustainable, scalable security function." The domain scope will evolve. Today it centres on the areas listed above — but we expect the role to grow into adjacent areas (AI security, detection engineering) as the organisation's needs develop. Adaptability and willingness to define your own frontier matters more than deep expertise in every area on day one.   [What you will be working on]   Security Architecture & Posture Own the organisation's security posture across all product teams and cloud environments Architect security frameworks that integrate into engineering workflows without creating bottlenecks Design and evolve threat modelling methodologies adapted to the organisation's multi-cloud, multi-tenant context Define escalation paths, severity frameworks, and incident response playbooks Own the relationship with GCSOC, shaping how external security signals translate into internal action Drive security tooling strategy — selecting, configuring, and setting alert thresholds that distinguish signal from noise Standards & Process Design Define security standards, runbooks, and compliance approaches that teams can self-serve against Design the Security Champions model: training curriculum, forum cadence, escalation criteria, and what "good" looks like for a champion Replace gatekeeping with enablement — move from "security reviews everything" to "teams self-certify against clear criteria, you spot-check and c
HOUSE AD970,107 openings. Erioun finds yours.Scored against your own profile, every hour.Try the radar →