IT Security manager
Summary
Security Manager leading cybersecurity governance, risk, compliance, and operational security for large-scale Singapore public sector projects, acting as the primary security contact for government agencies, auditors, and vendors. Day-to-day covers security policies and frameworks, VA/PT accreditation, vulnerability and patch management, and incident response.
We are looking for an experienced Security Manager to lead cybersecurity governance, risk, compliance, and operational security for large-scale public sector projects. You will work closely with government stakeholders, auditors, vendors, and technology teams to ensure systems and infrastructure maintain a strong and compliant security posture throughout their lifecycle.
Key Responsibilities
- Lead cybersecurity governance, risk management, compliance, and security assurance activities.
- Establish and maintain security policies,standards, procedures, and governance frameworks.
- Manage security accreditation activitiesincluding VA/PT, security assessments, remediation, and closure.
- Oversee vulnerability management, patchgovernance, security monitoring, and incident response.
- Ensure security controls and Secure-by-Design/ Security-by-Default principles are implemented across applicationsand infrastructure.
- Act as the primary cybersecurity contact forgovernment agencies, auditors, vendors, and project stakeholders.
- Identify security risks and drive appropriatemitigation and continuous improvement initiatives.
- Lead and mentor cybersecurity personnel andpromote security awareness across project teams.
- Provide management with security posture, risk,compliance, and remediation updates.
Requirements
- Degree in Cybersecurity, Information Security,Computer Science, or related discipline.
- 8+ years of cybersecurity experience,including 3–5 years in a leadership role.
- Strong experience in cybersecuritygovernance, risk, compliance, security operations, and assurance.
- Experience managing vulnerability assessments,penetration testing, remediation, and security audits.
- Good understanding of security controls acrossapplications, infrastructure, and enterprise environments.
- Experience with Singapore Government or otherhighly regulated environments is advantageous.
- Knowledge of ISO/IEC 27001, ISO 9001 andISO/IEC 12207 is beneficial.
- Strong stakeholder management, leadership,communication, and reporting skills.
- Certifications such as CISSP, CISM,CRISC, CCSP or ISO 27001 Lead Auditor are highly desirable.