Free with a WorkJio account: we compare your profile with this job and show what you already meet.
Share with a friend
Start
Not stated
Work mode
On-site
Experience
Experienced
About the role
You will lead technical design and execution for the TradeNet CII modernization, driving architectural security, secure coding, DevSecOps practices, and platform reliability. The role sits within GovTech's cybersecurity function, working closely with product and engineering teams as well as the Customs ACISO. It suits a hands-on security engineer who writes code and takes ownership of technical decisions from design through to production.
What you'll do
Own the reference security architecture for the TradeNet CII, covering trust boundaries, identity architecture, segmentation and trust-zone strategy, east-west controls, encryption and key management, and blast-radius containment.
Senior/ Lead Cybersecurity Engineer, TradeNet job at GovTech Singapore, Singapore | WorkJio
Embed secure-by-design controls by working inside product and engineering teams through the delivery lifecycle at design, solutioning and implementation time.
Maintain a living threat model per system and trust boundary, referenced to MITRE ATT&CK and relevant adversary classes, and use it to drive architecture and segmentation decisions.
Engineer the platform's recoverability and graceful degradation, including degraded-mode operation, recovery objectives, and containment design that preserves trade continuity under attack.
Map and treat dependency and concentration risk across the TradeNet ecosystem, including third-party and supply-chain integration risk.
Design for and participate in CSA-mandated cyber resilience exercising for the CII, feeding findings back into the architecture.
Partner the Customs ACISO as technical design authority, designing the Customs digital terrain and CII boundary with multi-layered defence and translating regulatory obligation into architecture.
Co-develop the defensible architecture and resilience narrative the ACISO relies on for CSA engagement, audits, and CII regulatory submissions.
Determine and document what the CII inherits from the GovTech security tech stack versus what the TradeNet product team must build and own, maintaining shared-responsibility delineation as an architectural artefact.
Express security control intent as code, including pipeline guardrails, policy-as-code, and continuous control monitoring, and champion secure SDLC and agile security practice within the delivery cadence.
Provide advisory and incident-response engineering support in coordination with SIRO, ACISO, and GCSOC.
Provide scoping and engineering guidance for external VAPT and vulnerability assessment, with closure validation performed independently.
Good to know
Operational validation sits with an independent assurance line to preserve control independence; the Lead Cybersecurity Engineer provides engineering guidance rather than self-validation.
The role involves writing code, implementing CI/CD security controls, embedding protective mechanisms into system blueprints, and delineating core infrastructure requirements.
Requirements
At least 10 years of engineering experience in software security, not purely advisory, compliance, or incident response.
Hands-on practitioner who builds and writes code directly.
Implements DevSecOps automation and pipeline security.
Mentors developers on secure coding and defensive programming.
Evaluates technical tooling.
Proven track record building defensive controls into critical or government-scale platforms.
Benefits
Purposeful career making lives better.
Robust learning and development opportunities all year round.
High autonomy with ownership of technical decisions.
Apply on the company website
You will leave WorkJio. Never pay a fee or share your Singpass password, OTP or bank log-ins to apply.