Senior Manager - Digital Governance Specialist
GovTech is the lead agency driving Singapore’s Smart Nation initiatives and public sector digital transformation. As the Centre of Excellence for Infocomm Technology and Smart Systems (ICT & SS), GovTech develops the Singapore Government’s capabilities in Data Science & Artificial Intelligence, Application Development, Smart City Technology, Digital Infrastructure, and Cybersecurity.
At GovTech, we offer you a purposeful career to make lives better where we empower our people to master their craft through robust learning and development opportunities all year round.
Play a part in Sigapore’s vision to build a Smart Nation and embark on your meaningful journey to build tech for public good. Join us to advance our mission and shape your future with us today!
Learn more about GovTech at tech.gov.sg.
[What you will be working on]
Some problems are easy to walk past. Others keep nagging at you.
Why are we still doing this manually?
Why does sensible policy become painful when it meets the real world?
Why do we discover risks after the fact when the signals were already there?
How should government govern AI systems that increasingly make decisions and take actions for themselves? And why, when technology can change in minutes, does governance sometimes still move in months?
If questions like these bother you enough that you want to get underneath them, experiment with better answers and solve the real-world problem, we should talk.
We are rethinking what modern governance, risk and assurance could look like across GovTech and, ultimately, the wider Singapore Government.
GovTech is where we can design, build, test and learn. The ambition is bigger.
Why this matters
We are modernising Governance, Risk, and Compliance (GRC) so government can use technology and AI with greater confidence, improve services faster, and keep the essential systems people rely on dependable and resilient.
Ultimately, the test is bigger than GRC: Can government use technology better, serve citizens better, and retain their trust when things go wrong?
That is the problem behind this role. And we do not expect to solve it by designing the perfect framework in a room.
We expect to work on real systems, with real users and real constraints. To experiment. Test assumptions. Prototype, understand behavior and incentives. Learn from what does not work.
And turn what does into something that can work at government scale. One role. Multiple archetypes. This is one modern GRC role, not six separate jobs or six career tracks.
The six archetypes below describe different capabilities a Modern GRC Practitioner can develop and create a problem.
You might begin with strength in one. Over time, you can acquire additional archetypes without giving up the ones you already have. An engineer might combine GRC Platform Engineering with Policy Engineering and AI Governance. An assurance practitioner might bring together Threat-Informed Risk Intelligence, Enterprise Risk Management and Systems Architecture. A policy practitioner might combine Policy Engineering with behavioral insights, systems thinking and platform capability.
Which archetypes you draw on depends on the problem. Some practitioners will build deep expertise in one or two. Others will develop a broader combination across several. Neither is a prescribed progression. The archetypes are not boxes to move between. They are capabilities you can accumulate, combine and apply. The ambition is to build practitioners with an increasingly powerful repertoire for understanding and solving difficult problems. Six capabilities you could build and combine.
Make policy work in the real world
Policy Engineering
How do we design policy that survives contact with engineers, users and actual organisational behavior?
Bring together domain expertise, behavioral insights, human-centered design and technology to create controls that people can understand, systems can implement and organisations can actually operate.
A technically correct policy that everyone works around is not a successful policy.
Turn uncertainty into decisions
Enterprise Risk Management
How do we help leaders decide which risks matter, what needs intervention and what we can deliberately live with? Connect signals across the organisation, expose dependencies and concentration risks, translate risk appetite into practical choices and bring better analysis to difficult decisions.
The output is not another register. It is a better decision.
Build assurance into the technology
GRC Platform Engineering
How do we make governance and assurance part of the delivery environment rather than another checkpoint around it? Build Policy-as-Code, automated evidence, continuous control verification and other infrastructure that makes safer behavior easier and assurance more timely.
Sometimes the answer is automation. Sometimes the smarter answer is removing the process first.
Govern systems that increasingly act for themselves
AI & Agentic Governance
What can an AI agent decide? Where must humans intervene? How should decision boundaries, accountability and assurance work when autonomous systems act at scale?
How do we govern model drift, changing behavior and GRC's own use of AI? Some answers exist. Many do not. You could help develop them.
Find the signal before it becomes the incident
Threat-Informed Risk Intelligence
How do we understand what is changing now rather than explain months later what went wrong? Connect cyber, data, resilience, platform, supply-chain and operational signals to identify patterns and emerging risks earlier.
Less: “Did the control pass?” More: “Is it working now, what changed, and what does that tell us?”
See the system everyone else sees in pieces
GRC Systems Architecture
How do policy, risk, controls, evidence, engineering and assurance fit together?
Design the taxonomies, information flows, feedback loops and operating models that allow them to work as one system. Ask some people about one control and they will explain the other three things it affects.
We like those people.
[What we are looking for]
Break the Frame
We are not looking for people to make yesterday's processes 10% faster. We want people willing to ask:
-
Why does this exist?
-
What risk are we actually managing?
-
What evidence says it works?
-
What behavior are we creating?
-
Could technology remove this step?
-
Could we design the problem away?
Sometimes the answer is better policy. Sometimes automation. Sometimes a different operating model. Occasionally, the right answer is to stop doing something altogether.
The expectation is not to challenge everything. It is to know what deserves to be challenged, why, and what should replace it.
What working here may feel like:
-
You will not always inherit a neatly defined problem.
-
Evidence may be incomplete. People may disagree about what is wrong.
-
A process may have existed so long that nobody quite remembers why.
-
Sometimes the problem you were asked to solve will turn out not to be the real problem.
That is part of the work.
Investigate before recommending. Prototype before standardising. Sit with engineers and users before writing policy. Use evidence before forming conclusions. Connect signals that others have not put together. And be willing to change your mind when your first hypothesis is wrong. We consider that progress.
What good looks like
Success is not the number of policies, findings, reports or dashboards produced. We are making progress when:
-
important risks are seen earlier
-
leaders make difficult decisions with better evidence
-
teams encounter fewer unnecessary governance touchpoints
-
policy is easier to understand, implement and verify
-
more assurance comes from live evidence
-
recurring problems are solved at system level
-
safer behavior happens increasingly by design
-
government can adopt AI and emerging technologies with greater confidence
-
governance helps delivery move faster rather than becoming the reason it slows down
And ultimately: Government uses technology better, essential services remain dependable, and citizens experience better public services without sacrificing trust. That is the measure that matters.
Who might find this interesting
There is no single background we are looking for.
You may come from engineering, cybersecurity, risk, assurance, resilience, AI, architecture, digital policy, product delivery, behavioural science, service design, design research, or somewhere less obvious.
Depth matters. But so does what happens when you reach the edge of what you know.
-
Do you get curious?
-
Can you make sense of messy information?
-
Can you work with people who see the problem differently?
-
Can you connect technical, organisational and human factors?
-
Can you turn an idea into something testable?
-
And when something clearly could work better, do you find it difficult to simply walk past?
For some of the problems we are tackling, the answer does not exist yet. That is precisely what makes them worth working on.
This may not be for everyone
If you are looking for a mature playbook, tightly defined boundaries and a portfolio that mainly needs maintaining, there are probably better roles. This work involves ambiguity, experimentation, difficult trade-offs and the occasional failed idea. But if a stubborn problem bothers you enough that you want to understand it, challenge assumptions and build something better, we should probably have a conversation.
Why GovTech
GovTech is in an unusual position. We help shape government technology policy. We build and operate major digital platforms. We can engineer governance and assurance into real delivery environments. We can test ideas against real-world problems and see whether they actually work. And what works here can become capability that benefits the wider Singapore Government.
So, this is not simply a chance to practice GRC differently. It is a chance to help discover what modern governance, risk and assurance needs to become.
What difficult problem would you like to help us solve?
What we offer you:
GovTech is an equal opportunity employer committed to fostering an inclusive workplace that values diverse voices and perspectives, as we believe that diversity is the foundation to innovation.
Our employee benefits are based on a total rewards approach, offering a holistic and market-competitive suite of perks. These include leave benefits to meet your work-life needs and employee wellness programs.
We champion flexible work arrangements (subject to your job role) and trust that you will manage your own time to deliver your best, wherever you are, and whatever works best for you.
Learn more about life inside GovTech at go.gov.sg/GovTechCareers.
Stay connected with us on social media at go.gov.sg/ConnectWithGovTech
Skills
As published by greenhouse · 4 questions
Basics
First Name, Last Name, Email, Phone, Resume/CV, Cover Letter
Short answers (2)
- Preferred First Name optional
- Share your LinkedIn Profile with us optional
Pick from a list (2)
- What is your work eligibility in Singapore?
- By submitting my application, I hereby give my consent to GovTech to obtain, verify and share my information with other Government agencies for the purposes of recruitment and review of recruitment practices.