IT Security Lead

Job description

Job Description

This role covers both:

Day 1 Security (Build / Project Implementation)

Day 2 Security (Operations / Production Support) The Security Lead will work closely with Infra, System, and Software teams, InfoSec stakeholders, and external auditors to ensure the system complies with government security policies and standards.

Key Responsibilities

Day 1 – Project / Implementation Security

1. Security Architecture & Design

  • Define system security architecture aligned with Singapore Government security policies.

  • Review application, middleware, infrastructure, and platform designs for security compliance.

  • Conduct threat modelling and risk assessments; map risks to mitigating controls.

  • Translate policy requirements into actionable technical controls across the stack.

2. Compliance & Governance

  • Ensure compliance with: IM8 / Government security policies Whole‑of‑Government (WOG) security requirements PDPA (where applicable)

  • Establish and oversee cyber security governance across infrastructure, application, and project teams.

  • Prepare and maintain documentation for: 

  • Security Risk Assessment (SRA)Vulnerability Assessment (VA)Penetration Testing (PT)Security hardening baselines and reports

3. Secure Development Oversight Partner with software teams to enforce secure coding standards and Dev SecOps practices.

  • Integrate and govern SAST/DAST, dependency/SCA scanning, and container image scanning in CI/CD.

  • Review and triage findings from tools (e.g., SonarQube, SCA, container scanners), drive remediation, and risk acceptance where needed.

  • Provide guidance on API security, token/secret management, and secure service-to-service communication.

4. Security Testing & Certification

  • Plan, coordinate, and manage VA/PT engagements and vendors.

  • Track findings through remediation to closure; document residual risk and risk acceptance.

  • Support all security clearances and go‑live certifications.

  • Security Hardening Review and approve: 

  • OS and baseline hardening

  • Middleware hardening

  • Database security configurations

  • Kubernetes / container security (RBAC, network policies, admission controls, secrets, image provenance)

  • API gateway / WAF / rate‑limiting / mTLS / OAuth2/OIDC configurations

Day 2 – Operations / Production Security

1. Incident Management

  • Lead security incident investigation, containment, and recovery.

  • Perform root cause analysis (RCA) and define corrective/preventive actions.

  • Coordinate with Gov SOC and stakeholders; contribute to and refine playbooks.

  • Provide clear, timely communications to both technical and non-technical audiences.

2. Vulnerability & Patch Management

  • Oversee continuous vulnerability monitoring and posture management.

  • Track patch and configuration compliance across infrastructure, middleware, applications, and containers.

  • Provide risk assessments and compensating controls for deferred patches.

3. Security Monitoring & Audit Review and tune alerts, detections, and dashboards in SIEM and related tools.

  • Ensure monitoring coverage for critical systems and high‑value assets.

  • Support internal/external audits and evidence collection; close audit findings.

4. Compliance & Reporting

  • Prepare and present security posture, metrics, and trend reports to management.

  • Maintain risk registers and mitigation plans; ensure up‑to‑date security documentation.

  • Communicate security assessments and findings effectively to varied stakeholders.

5. Access Control Governance

  • Oversee and periodically review RBAC, MFA, Privileged Access Management (PAM), and joiner/mover/leaver processes.

  • Ensure least privilege, SoD, and periodic access recertifications.

6. Security Operations Contribution

  • Support incident response handling, log analysis, and activity reviews.

  • Drive continuous improvement across identify → protect → detect → respond → recover functions.

Requirements:

Bachelor’s degree in computer science / Cybersecurity / Information Security or equivalent

Preferred Certifications: CISSP, CISM, CISA, CEH, GIAC (e.g., GSEC, GCIA, GCIH, GCSA)
Experience in: Kubernetes, Docker security, API security, Identity & Access Management (IAM), Security tools (SAST/DAST/SIEM) and CI/CD-integrated security

To Apply, please kindly email your updated resume ashwathy.pillai@tg-hr.com
Regret to inform that only shortlisted candidates will be notified.

CEI: R1988671

EA License: 14C7275




Login is optional, you may send application via email

Login to Save Login to Apply

Get AI to assess your suitability to this job

Use AI chat of your choice: ChatGPT, Gemini, Claude — and:

  1. Paste this into the prompt:
    I am a jobseeker. Below is a job posting. Please: 1. Give a match score (0–100) based on my resume vs the job requirements 2. List my 3–5 key strengths that align with this role 3. List 2–3 areas to improve or gaps to address before applying 4. Give a one-sentence verdict: should I apply, apply with adjustments, or skip? Job posting URL: https://singapore.job-q.com/jobs/detail/it-security-lead After reading the job, ask me to upload or paste my resume.
  2. Upload your resume in the same chat.

Similar Jobs

Service Delivery Manager

The Service Delivery Manager is responsible for managing all aspects of day-to-day...

On site

Contract

APBA TG HUMAN RESOURCE PTE. LTD.

Sales Representative / Sales Coordinator #78230

Job DescriptionIndustry/ Organization Type: IT ServicePosition Title: Sales Representative / Sales CoordinatorWorking...

On site

Permanent

ANRADUS PTE. LTD.

Information Technology Consultant

Responsibilities:Planning, setup, installation, patching & upgrades, troubleshooting issuesDevelop, document and implement standard...

On site

Contract

PERSOL SINGAPORE PTE. LTD.

Program Manager

ResponsibilitiesThe ideal candidate should have strong experience in managing complex, cross-functional program,...

On site

Contract

WSH EXPERTS PTE. LTD.

Job Summary

  • Published on: 11 May, 2026
  • Category: Information Technology (IT)
  • Vacancy: 1
  • Job type: Contract
  • Salary: 8000
  • Location: On site
  • Job Nature: Contract

Company Details

APBA TG Human Resource Pte Ltd

(a wholly owned subsidiary of the TG Group)


TG Group (“TG”) is a global workforce solutions provider with an international reach in over 50 markets across the globe. Headquartered in Singapore with Shanghai Foreign Service (Group) Co Ltd ("FSG") as a strategic shareholder, TG delivers a comprehensive suite of innovative human capital solutions to help our clients achieve greater business success.

TG adopts a future-centric approach where we aspire to be at the forefront of the evolution of the future of work. We believe that human capital is the greatest asset to any institution. With a wealth of experience in the Human Resources (HR) industry, we combine our international expertise and local know-how to deliver bespoke and innovative workforce solutions.

Our diverse portfolio of client-centric workforce solutions includes Contingent Workforce Management (CWM), Business Process Outsourcing (BPO), Permanent Placements, Recruitment Process Outsourcing (RPO), Professional Employer Organisation (PEO), and Payroll Process Outsourcing (PPO).