- Location
- Singapore
- Type
- Full-time
- Department
- Engineering
- Seniority
- Lead
- Closing date
- Today
- Source
- CareersPage
Description
Responsibilities
- Own and evolve the security architecture for the TradeNet Critical Information Infrastructure (CII), covering trust boundaries, identity, segmentation, encryption, key management, Zero Trust principles, and blast-radius containment.
- Embed secure-by-design and resilient-by-design controls throughout architecture, solution design, development, and implementation.
- Work hands-on with engineering teams to implement security controls and improve secure coding practices.
- Maintain threat models using frameworks such as MITRE ATT&CK, covering supply-chain, advanced persistent, and nation-state threats.
- Design for high availability, recoverability, graceful degradation, disaster recovery, and containment to maintain national trade continuity during cyber incidents.
- Identify and address dependency, concentration, third-party, and supply-chain risks across the TradeNet ecosystem.
- Partner with the Singapore Customs ACISO to design the CII security boundary and multi-layered defensive architecture.
- Translate CSA CCoP v2 and WOG IM8 requirements into practical architecture and engineering controls.
- Determine which security controls can be inherited from the GovTech security technology stack and which must be built and owned by the TradeNet product team.
- Maintain clear documentation of security control ownership and the shared-responsibility model.
- Implement security controls as code, including policy-as-code, CI/CD security guardrails, automated security checks, and continuous control monitoring.
- Champion Secure SDLC and DevSecOps practices across engineering teams.
- Evaluate and recommend appropriate cybersecurity tools, technologies, and security architecture patterns.
- Participate in cybersecurity resilience exercises and incorporate findings into platform architecture and engineering improvements.
- Provide technical guidance for incident response, vulnerability assessments, and penetration testing where required.
- Mentor and coach engineers on secure coding, security architecture, threat modelling, and cybersecurity best practices.
Requirements
- 10+ years of cybersecurity experience, with strong hands-on experience in software engineering, security engineering, or security architecture.
- Must be technically hands-on and capable of designing secure systems, reviewing or writing code, and coaching engineering teams on secure development.
- Demonstrated experience designing and implementing security architecture for regulated, critical, large-scale, or enterprise platforms.
- Working knowledge of Singapore cybersecurity regulatory frameworks, particularly CSA CCoP v2 and WOG IM8
- Familiarity with security frameworks including MITRE ATT&CK, NIST, ISO 27001, and CIS Benchmarks.
- Strong understanding of system boundaries, dependencies, failure modes, recoverability, and security risks across complex platforms.
- Proficiency in at least one scripting or automation language such as Python, TypeScript, Shell/Bash, or equivalent.
- Preferably proficient in Kotlin/JVM and TypeScript.
- Experience with government, CII, financial services, national infrastructure, or other mission-critical environments is advantageous.
- Cybersecurity architecture certifications such as CISSP / CISSP-ISSAP, SABSA, or cloud security certifications are advantageous.
- Must be eligible for the required personnel security clearance / CII vetting.
- Onsite presence during fixed hours may be required due to the critical nature of the role.
Strong knowledge of:
- Cloud security across IaaS, PaaS, and SaaS
- Identity and access management
- Encryption and key management
- Network segmentation and Zero Trust
- Secure SDLC and DevSecOps
- Policy-as-code and security automation
- Resilience, disaster recovery, and business continuity
Skills
PythonTypeScriptKotlinCI/CDCybersecurityPenetration TestingISO 27001CISSP