Role Summary
We are looking for an experienced Security Manager to lead cybersecurity governance, risk, compliance, and security operations for large-scale public sector projects.
You will work closely with government stakeholders, auditors, vendors, and technology teams to ensure systems and infrastructure remain secure, compliant, and well-governed throughout the project lifecycle.
Key Responsibilities
- Lead cybersecurity governance, risk, compliance, and security assurance activities.
- Develop and maintain security policies, standards, procedures, and governance frameworks.
- Manage security assessments, VA/PT, remediation, and audit activities through to closure.
- Oversee vulnerability management, patch governance, security monitoring, and incident response.
- Ensure Secure-by-Design and Security-by-Default principles are incorporated into applications and infrastructure.
- Serve as the key cybersecurity contact for government stakeholders, auditors, vendors, and project teams.
- Identify security risks, recommend mitigation measures, and drive continuous security improvements.
- Lead and mentor security team members while promoting security awareness across project teams.
- Prepare and present updates on security posture, risks, compliance, vulnerabilities, and remediation status to management.
Requirements
- Degree in Cybersecurity, Information Security, Computer Science, or a related discipline.
- 8 years of cybersecurity experience, with at least 3-5 years in a leadership or managerial capacity.
- Strong experience in security governance, risk management, compliance, security operations, and security assurance.
- Hands-on experience managing VA/PT, vulnerability remediation, security assessments, and security audits.
- Good understanding of security controls across applications, infrastructure, and enterprise IT environments.
- Experience supporting Singapore Government or highly regulated environments is an advantage.
- Knowledge of ISO/IEC 27001, ISO 9001, and ISO/IEC 12207 is beneficial.
- Strong stakeholder management, leadership, communication, and reporting skills.
- Certifications such as CISSP, CISM, CRISC, CCSP, or ISO 27001 Lead Auditor are highly desirable.