
Search by job, company or skills
[What the role is]
Plaque of Commendation (Gold) - NTUC May Day Awards 2026[What you will be working on]
Technical Cybersecurity Engineer and Subject-Matter-Expert
To propose, lead, and conduct threat modelling activities (e.g. STRIDE) using the MITRE ATT&CK framework for enterprise systems and applications to identify potential threats, attack vectors, and security risk.
To facilitate internal IT security compliance assessment and ensure IT security requirements are adequately and properly implemented.
To conduct IT security related briefing/training to end-users and administrators.
To manage IT security projects and implementations.
Incident Response, Security monitoring & Threat intelligence
To monitor, analyse, investigate and resolve security incidents (this role may require you to respond to security incidents after office hours).
To conduct post-incident reviews and recommend procedural and technical measures to prevent similar incidents in future.
To ensure timely and adequate response to IT security alerts, and escalation of security events.
Data Governance
Propose, implement and maintain data governance policies, standards, and procedures across enterprise and learning platforms.
Maintain data classification, ownership, stewardship, and accountability frameworks.
Monitor and improve data quality, integrity, consistency, and completeness through governance processes and controls.
Oversee data lifecycle management, including data creation, storage, retention, archival, and secure disposal.
Ensure compliance with organisational policies and applicable data protection and privacy regulations.
Collaborate with business units to identify critical data assets and define governance requirements.
[What we are looking for]
Relevant qualifications in Computer Science and related disciplines.
Professional and recognised certifications in cybersecurity, information security, or data governance (e.g. CISSP, CISA, CISM, CDPSE, CDMP).
Good understanding of cybersecurity principles, information security frameworks, and data governance best practices.
Familiarity with the MITRE ATT&CK framework and ability to map identified threats, attack techniques, and mitigations to relevant security controls.
Familiarity with data privacy and protection regulations such as Personal Data Protection Act (PDPA).
Ability to leverage Artificial Intelligence (AI) tools and technologies to enhance cybersecurity operations, data governance processes, security analysis, and productivity.
Experience conducting security or compliance assessments and supporting audit activities.
Experience implementing or supporting data governance frameworks, data classification, metadata management, and data lifecycle management.
General competencies:
Versatile and adaptable individual who is comfortable handling a different range of responsibilities and collaborating with diverse stakeholders in a dynamic environment
Demonstrated ability to multitask, adapt quickly to new challenges, and maintain effective working relationships with technical and non-technical stakeholders
Excellent analytical and problem-solving skills
Strong communication skills to engage stakeholders and end-users
Self-driven, independent, professional and an excellent collaborator/partner in teams
Successful candidate will be offered a 2-year contract in the first instance.
If you are shortlisted for the position, you should hear from us within 30 days of the closing date of the advertisement.
Job ID: 151643167
Skills:
cloud security, Vulnerability Management, PowerShell, Incident Response, Siem, Threat Intelligence, Python, Microsoft 365 security ecosystem, KQL, Defender XDR, SOAR, external attack surface management, identity security, EDR, Microsoft Sentinel, MDR
Skills:
compliance assurance , Data Governance, Incident Response, Data Protection, Cism, MITRE ATT CK framework, Cisa, Security Monitoring, CDPSE, Cissp, CDMP, Risk management, Threat modelling
Skills:
red teaming , Cloud Security, Ceh, Penetration Testing, Web Application Security, Digital Forensics, Oscp, Firewall Configuration, Cism, IT Audit and Compliance, Cisa, personal data protection, Cissp, SOC Operations
Skills:
Cism, cybersecurity risk assessment, Cisa, CP8, cybersecurity audits, data security governance, IM8, nist, Cissp, Security-by-Design principles, ISO IEC 62443, CRISC, CCoP
Skills:
Dlp, Waf, Iam, Incident Response, Vulnerability Management, Zero Trust, EDR, Security Risk Assessments