M

IT Security Lead

salary Salary :

$5,000 - 7,000 monthly

icon briefcase Job Type : Full Time

Number of Applicants

 : 

000+

Click to reveal the number of candidates who applied for this job.

Let AI Supercharge Your Job Hunt!

JobCopilot scans 500,000+ company career sites daily to find jobs for you

Never miss an opportunity Save hours by auto-filling applications forms Land more interviews with tailored applications
happy man
thunder iconActivate JobCopilot

Job Description - IT Security Lead

Singaporean only

Role Overview

The IT Security Lead will be responsible for end-to-end security governance, implementation, compliance, and operational security for mission-critical system operating in a secured environment.

This role covers both:

Day 1 Security (Build / Project Implementation)

Day 2 Security (Operations / Production Support)

The Security Lead will work closely with Infra, System, and Software teams, InfoSec stakeholders, and external auditors to ensure the system complies with government security policies and standards.

Key Responsibilities

Day 1 – Project / Implementation Security

1. Security Architecture & Design

Define system security architecture aligned with Singapore Government security policies.

Review application, middleware, infrastructure, and platform designs for security compliance.

Conduct threat modelling and risk assessments; map risks to mitigating controls.

Translate policy requirements into actionable technical controls across the stack.

2. Compliance & Governance

Ensure compliance with:

IM8 / Government security policies

Whole‑of‑Government (WOG) security requirements

PDPA (where applicable)

Establish and oversee cyber security governance across infrastructure, application, and project teams.

Prepare and maintain documentation for:

Security Risk Assessment (SRA)

Vulnerability Assessment (VA)

Penetration Testing (PT)

Security hardening baselines and reports

3. Secure Development Oversight

Partner with software teams to enforce secure coding standards and DevSecOps practices.

Integrate and govern SAST/DAST, dependency/SCA scanning, and container image scanning in CI/CD.

Review and triage findings from tools (e.g., SonarQube, SCA, container scanners), drive remediation, and risk acceptance where needed.

Provide guidance on API security, token/secret management, and secure service-to-service communication.

4. Security Testing & Certification

Plan, coordinate, and manage VA/PT engagements and vendors.

Track findings through remediation to closure; document residual risk and risk acceptance.

Support all security clearances and go‑live certifications.

5. Security Hardening

Review and approve:

OS and baseline hardening

Middleware hardening

Database security configurations

Kubernetes / container security (RBAC, network policies, admission controls, secrets, image provenance)

API gateway / WAF / rate‑limiting / mTLS / OAuth2/OIDC configurations


Day 2 – Operations / Production Security

1. Incident Management

Lead security incident investigation, containment, and recovery.

Perform root cause analysis (RCA) and define corrective/preventive actions.

Coordinate with Gov SOC and stakeholders; contribute to and refine playbooks.

Provide clear, timely communications to both technical and non-technical audiences.

2. Vulnerability & Patch Management

Oversee continuous vulnerability monitoring and posture management.

Track patch and configuration compliance across infrastructure, middleware, applications, and containers.

Provide risk assessments and compensating controls for deferred patches.

3. Security Monitoring & Audit

Review and tune alerts, detections, and dashboards in SIEM and related tools.

Ensure monitoring coverage for critical systems and high‑value assets.

Support internal/external audits and evidence collection; close audit findings.

4. Compliance & Reporting

Prepare and present security posture, metrics, and trend reports to management.

Maintain risk registers and mitigation plans; ensure up‑to‑date security documentation.

Communicate security assessments and findings effectively to varied stakeholders.

5. Access Control Governance

Oversee and periodically review RBAC, MFA, Privileged Access Management (PAM), and joiner/mover/leaver processes.

Ensure least privilege, SoD, and periodic access recertifications.

6. Security Operations Contribution

Support incident response handling, log analysis, and activity reviews.

Drive continuous improvement across identify → protect → detect → respond → recover functions.


Required Qualifications & Experience

Mandatory

Degree in Computer Science / Cybersecurity / Information Security or equivalent

8–12 years of IT experience, including ≥5 years as a Security Lead or Security Architect

Proven experience in Singapore Government IT projects and IM8/government security compliance

Hands-on experience with:

Kubernetes / Docker security

API security

Identity & Access Management (IAM)

Security tools (SAST/DAST/SIEM) and CI/CD-integrated security

Preferred Certifications (1–2+ of the following)

CISSP, CISM, CISA, CEH, GIAC (e.g., GSEC, GCIA, GCIH, GCSA)

AWS or Azure Security certifications

Key Competencies

Strong stakeholder management (Gov agencies, SOC, auditors, vendors, and delivery teams)

Ability to translate policy and risk into concrete technical controls and pragmatic delivery

Excellent documentation, reporting, and presentation skills

Risk-based decision making with clear rationale and traceability

Hands-on technical depth; able to deep dive in architecture, code, pipelines, and platforms

Clear communicator to both technical and non‑technical audiences

Original job IT Security Lead posted on GrabJobs ©. To flag any issues with this job please use the Report Job button on GrabJobs.
Share Job
Share Job

About the Company

MINDTECK SINGAPORE PTE LTD

MINDTECK SINGAPORE PTE LTD Mindteck, a global technology company established in 1991, provides Product Engineering services to medical device companies, the  energy industry and equipment OEMs, and Information Technology services to government entities, analytical/scientific instrument  manufactu...

Read more about the company

Auto-Apply to Similar Jobs with your AI JobCopilot

thunder icon Auto-Apply with AI
💰

Technology Salaries

Similar Jobs in Singapore

GrabJobs is the no1 job portal in Singapore, connecting you to thousands of jobs fast! Find the best jobs in Singapore, apply in 1 click and get a job today!

Mobile Apps

Copyright © 2026 Grabjobs Pte.Ltd. All Rights Reserved.