Lead Cybersecurity Engineer
AI Summary
Lead Cybersecurity Engineer at GovTech’s GCC team, owning security outcomes, architecture, and processes across cloud environments and engineering teams in a multi-cloud setup.
About this role
GovTech is the lead agency driving Singapore’s Smart Nation initiatives and public sector digital transformation. As the Centre of Excellence for Infocomm Technology and Smart Systems (ICT & SS), GovTech develops the Singapore Government’s capabilities in Data Science & Artificial Intelligence, Application Development, Smart City Technology, Digital Infrastructure, and Cybersecurity.
At GovTech, we offer you a purposeful career to make lives better where we empower our people to master their craft through robust learning and development opportunities all year round.
Play a part in Singapore’s vision to build a Smart Nation and embark on your meaningful journey to build tech for public good. Join us to advance our mission and shape your future with us today!
Learn more about GovTech at tech.gov.sg.
Government Commercial Cloud (GCC) is a key platform within Singapore Government Technology Stacks that enables government agencies to build and operate digital services on commercial cloud. The GCC Engineering team develops platform automations, landing zones, and security tooling across AWS, Azure, and GCP — serving thousands of government systems and thousands of public officers.
Security at GCC is not a side function — it's core to the platform's value proposition. Government agencies trust GCC to be secure by default.
You are the single named owner of security outcomes across all engineering teams in GCC. You define how security works — the standards, processes, escalation paths, and technical approaches — and drive adoption through influence, not authority. You operate through a Security Champions network: persistent, named engineers in each product team who own security judgment locally, coordinated by you. Your accountability is whether GCC is actually secure — measured through process health, incident response quality, and security posture metrics you define.
This role is part of the organisation's domain leadership structure — you join alongside Engineering Managers as a peer, not as a report to any EM. The Security domain is being stood up fresh. The previous model (centralised security team gatekeeping all decisions) has been retired. You inherit a Champions network in early stages, documented runbooks, and interim coverage from a senior security advisor. Your job is to take it from "interim bridge" to "sustainable, scalable security function."
The domain scope will evolve. Today it centres on the areas listed above — but we expect the role to grow into adjacent areas (AI security, detection engineering) as the organisation's needs develop. Adaptability and willingness to define your own frontier matters more than deep expertise in every area on day one.
[What you will be working on]
Security Architecture & Posture
- Own the organisation's security posture across all product teams and cloud environments
- Architect security frameworks that integrate into engineering workflows without creating bottlenecks
- Design and evolve threat modelling methodologies adapted to the organisation's multi-cloud, multi-tenant context
- Define escalation paths, severity frameworks, and incident response playbooks
- Own the relationship with GCSOC, shaping how external security signals translate into internal action
- Drive security tooling strategy — selecting, configuring, and setting alert thresholds that distinguish signal from noise
Standards & Process Design
- Define security standards, runbooks, and compliance approaches that teams can self-serve against
- Design the Security Champions model: training curriculum, forum cadence, escalation criteria, and what "good" looks like for a champion
- Replace gatekeeping with enablement — move from "security reviews everything" to "teams self-certify against clear criteria, you spot-check and consult"
- Own security decision records: all posture choices documented, auditable, and transferable
- Reform compliance processes (e.g. IMR8) to reduce ceremony while maintaining assurance
Cross-Org Influence
- Drive security adoption across 5-6 engineering teams through the Champions network
- Run a regular cross-org security forum: shared learning, emerging threats, pattern reviews
- Consult on high-risk designs and architectural trade-offs when teams escalate
- Handle genuine security incidents personally, with Champions as informed participants
- Build security judgment across the engineering organisation — not by centralising decisions, but by raising the floor
- Serve as the organisation's authoritative security voice on technical matters — advising on vendor evaluations, platform-level policy design, and cross-programme security decisions that require deep domain expertise beyond any single team's scope
Technical Depth
- Maintain hands-on capability in at least two of: cloud security architecture, application security, supply chain security, detection engineering
- Evaluate and prototype security tooling; make build-vs-buy recommendations grounded in the org's actual threat model
- Contribute to or lead security incident post-mortems with root cause analysis that drives systemic improvement
- Stay current on emerging threats and translate external signals into organisational action
[What we are looking for]
Must-Have
- Deep security engineering expertise (architecture, not just operations) — you've designed security frameworks, not just followed them
- Demonstrated ability to influence without authority across multiple engineering teams
- Experience designing security processes that scale through enablement rather than gatekeeping
- Strong enough as an engineer to review designs, read code, and earn credibility with senior SWEs
- Clear, structured communication — you'll write strategies, runbooks, and decision records that outlive you
- Comfort operating with ambiguity: this role is being stood up for the first time, and you'll shape what it becomes
- Proficiency in scripting (Python, Bash) and working with APIs — you'll build and review automation, not just specify it
- Solid understanding of identity, networking, logging, monitoring, and data security in cloud environments
Strong Signals
- Experience with cloud security across multiple CSPs — ideally hands-on with native security services, not just console-level familiarity
- Background in both offensive (threat modelling, VAPT, red team) and defensive (SIEM, detection engineering, incident response) security
- Track record of building security champion or embedded security programs
- Experience with CNAPP/CSPM platforms and vulnerability management tooling
- Experience integrating security controls into CI/CD pipelines and DevSecOps workflows
- Familiarity with compliance and threat frameworks and the judgment to know when compliance ≠ security
- Experience working in government or highly regulated environments
- Awareness of AI security risks and emerging governance frameworks
Technology Landscape
You'll encounter the following in this role. We don't expect mastery of all of these on day one — what matters is the ability to learn quickly and form sound judgment across unfamiliar tools.
| Area | Technologies |
|------|-------------|
| Cloud providers | AWS, Azure, GCP (multi-account/subscription/project at scale) |
| Security posture | Wiz, AWS Security Hub, Azure Defender, GCP Security Command Center |
| Vulnerability management | Nessus, Trivy, AWS Inspector, container scanning |
| SIEM & detection | Elastic SIEM, GuardDuty, Sentinel, CloudTrail/Activity Log |
| Identity & access | IAM (all CSPs), Entra ID, workload identity, RBAC/ABAC patterns |
| IaC & pipelines | Terraform, GitLab CI/CD, policy-as-code (OPA, Sentinel) |
| Secrets & supply chain | Vault, AWS Secrets Manager, SBOM tooling, dependency scanning |
| Compliance frameworks | IMR8, CIS Benchmarks, NIST CSF, ISO 27001, MITRE ATT&CK |
| Scripting & automation | Python, Bash, REST APIs |
| Emerging | AI/LLM security (OWASP LLM Top 10, NIST AI RMF), detection-as-code |
Preferred Certifications
Not required, but signal depth in relevant areas:
- Cloud security: AWS Security Specialty, Azure Security Engineer Associate, GCP Professional Cloud Security Engineer
- Security generalist: CISSP, CCSP, or relevant GIAC certifications
- Offensive: OSCP, GPEN, or equivalent hands-on security testing credentials
Dealbreakers
- Pure compliance/audit background with no engineering depth — this role requires technical credibility with senior engineers
- Preference for centralised control ("everything goes through security") — the operating model is distributed enablement
- Inability to document and codify decisions — if you leave, someone else must be able to pick up without an information gap
What we offer you:
GovTech is an equal opportunity employer committed to fostering an inclusive workplace that values diverse voices and perspectives, as we believe that diversity is the foundation to innovation.
Our employee benefits are based on a total rewards approach, offering a holistic and market-competitive suite of perks. These include leave benefits to meet your work-life needs and employee wellness programs.
We champion flexible work arrangements (subject to your job role) and trust that you will manage your own time to deliver your best, wherever you are, and whatever works best for you.
Learn more about life inside GovTech at go.gov.sg/GovTechCareers.
Stay connected with us on social media at go.gov.sg/ConnectWithGovTech
Skills
Explore related jobs
More jobs at govtech
Similar AWS jobs
Jobs in Singapore
Product Lead - Finance Super App (Singapore)Bjak · Singapore
Product Manager - Finance Super App (Singapore)Bjak · Singapore
Product Owner - Finance Super App (Singapore)Bjak · Singapore
Head of AIThe Stakeholder Company Pte. Ltd. · Singapore, Singapore
Brand Communications ManagerBandLab Technologies · Singapore