Lead Software Engineer (Cybersecurity Specialist)
Capgemini · Singapore, Singapore
IT Services and IT Consulting · 10,001+ employees
About the role
The Lead Software Engineer will own the reference security architecture, including trust boundaries, identity, and encryption strategies. They will also embed secure-by-design controls within engineering teams and ensure platform resilience and business continuity.
What they look for
Requirements
Candidates must have over 10 years of hands-on experience in cybersecurity software engineering with a strong command of regulated systems and security frameworks. Proficiency in scripting languages like Python or TypeScript and experience with cloud and platform security architecture are essential.
Benefits
Full description
About Capgemini Capgemini is a global business and technology transformation partner, helping organizations to accelerate their dual transition to a digital and sustainable world, while creating tangible impact for enterprises and society. It is a responsible and diverse group of 340,000 team members in more than 50 countries. With its strong over 55-year heritage, Capgemini is trusted by its clients to unlock the value of technology to address the entire breadth of their business needs. It delivers end-to-end services and solutions leveraging strengths from strategy and design to engineering, all fueled by its market leading capabilities in AI, generative AI, cloud and data, combined with its deep industry expertise and partner ecosystem. The Group reported 2024 global revenues of €22.1 billion.
Responsibilities
Secure and Resilient Architecture (Core Mandate)
- Own the reference security architecture: trust boundaries, identity architecture, segmentation and trust-zone strategy, east-west controls, encryption and key management, and blast-radius containment.
- Embed secure-by-design controls by working inside product and engineering teams throughout the delivery lifecycle, at design, solutioning, and implementation stages rather than as post-build validation.
- Maintain a living threat model for systems and trust boundaries, referenced to MITRE ATT&CK and relevant adversary classes (including supply-chain threats), and use it to drive architecture and segmentation decisions rather than solely remediation prioritization.
Resilience and Business Continuity
- Engineer platform recoverability and graceful degradation, including degraded-mode operation, recovery objectives, and containment designs that preserve critical business operations during cyber incidents.
- Map and manage dependency and concentration risk across the ecosystem, including customers, partners, third-party providers, and supply-chain integrations.
- Design for and participate in cyber resilience exercises, incorporating lessons learned into the architecture.
Defensive Terrain
- Partner with security leadership as the technical design authority to define digital architecture and security boundaries using multi-layered defence, translating security and regulatory requirements into practical architecture decisions.
- Co-develop defensible architecture and resilience strategies to support stakeholder, audit, and regulatory engagements.
Platform Leverage and Control Inheritance
- Determine and document which security controls are inherited from enterprise platforms and shared services (e.g., cloud platforms, centralized monitoring, CI/CD guardrails, baseline security controls) versus those that application teams must build and maintain.
- Maintain shared responsibility models as architectural artefacts to clearly define ownership and audit boundaries.
Continuous Assurance and Secure Delivery
- Express security control intent as code through pipeline guardrails, policy-as-code, and continuous control monitoring so conformance can be observed continuously.
- Champion secure SDLC and agile security practices within engineering teams, enabling teams rather than creating delivery bottlenecks.
Transitional / Day-2 Scope (Explicitly Secondary)
The following are transitional and not the primary remit. Operational validation of architecture designs should be performed by an independent assurance function to preserve control independence. The role provides engineering guidance rather than self-validation:
- Advisory and incident response engineering support in coordination with security and operational stakeholders.
- Scoping and engineering guidance for external security assessments and penetration testing, with validation of remediation performed independently.
Requirements
- 10+ years in Cybersecurity as a Software Engineer and not just in the capacity of auditing, pen-testing, operational triage, etc.
- We need someone that is hands on where the ideal candidate is someone that can design systems to be secure and can sit down to write code if they need to, someone that can coach our engineering teams on how to write better and more secure code, and someone that understands the cybersecurity tooling landscape to help us choose the right tools, we are not looking for a high level theorist / academic.
- Demonstrated experience with designing security architecture into regulated / critical systems and platforms at the national or whole enterprise level, not just providing testing and assurance but actually designing and implementing.
- Working command of Singapore regulatory frameworks for critical systems: e.g. WOG IM8 (Reform), with the ability to translate obligation into architecture and to delineate control inheritance for audit scoping.
- Strong systems thinking: able to reason about a national platform as an interdependent whole — boundaries, failure modes, recoverability, and concentration risk — not as a checklist of controls.
- Depth across cloud and platform security architecture (IaaS/PaaS/SaaS), identity, encryption and key management, segmentation and zero-trust patterns, and secure SDLC / policy-as-code.
- Fluency with architectural and adversary frameworks (MITRE ATT&CK, NIST, ISO 27001, CIS benchmarks) used to drive design decisions.
- Ability to operate as a technical design authority alongside a CISO, clearly within the first line, and to produce architecture that withstands regulatory and audit scrutiny.
- Proficiency in at least one scripting/automation language (e.g. Python, TypeScript, Shell/Bash, et) for policy-as-code and tooling.
- Preferably proficient in both Kotlin/JVM stack and TypeScript.
- Architecture-leaning certifications are advantageous (e.g. CISSP / CISSP-ISSAP, SABSA, cloud security architecture). Incident-response and offensive certifications are useful but not the primary signal for this role.
- Subject to the nature of the role, onsite presence during fixed hours may be required.
Let's talk about what's in it for you!
Passionate people are Capgemini's Ace of Spades - join us to discover a career that will challenge, support and inspire you. Working at Capgemini you'll find the rewards are more than just financial. You will work alongside some very smart and inspiring people on exciting projects and you will also enjoy incredible benefits. We offer flexible work practices and 40 hours of self-development every year with a huge selection of learning opportunities to choose from.
As "Architects of Positive Futures", Capgemini actively supports the community in 3 ways:
Diversity and Inclusion - we believe diversity of thought fuels excellence and innovation, which is why we positively encourage applications from suitably qualified candidates regardless of their gender identity, ethnicity, sexual orientation, religion, ability, intersex status or age. To support our commitment to diversity and inclusion, we celebrate special events and days of significance that are important to our employees such as Diwali, Bastille Day, Pride, IDAHOBIT, IWD and International day of people with Disabilities. Our Employee Resource Groups Women@Capgemini and OutFront support the grassroots passion of employees to drive our diversity agenda and effect change.
Digital inclusion - at Capgemini we are using our skills to drive social impact initiatives focusing on helping society address the impact of the digital and automation revolution. We also provide employees with opportunities to give back to the community through charity projects and volunteer days.
Environmental Sustainability - Capgemini joined the CDP's (Carbon Disclosure Project) prestigious "A list" for its commitment to the Net-Zero economy. We are focusing on helping our clients transform towards more sustainable business models and committing to reduce our own carbon emissions (GHG) by 20% per employee by 2020.
Recognized by Ethisphere as one of the World's Most Ethical Companies for the last 8 years in a row, ethics and values are at the heart of Capgemini's corporate culture and business. Embedded in our DNA, our seven values - Honesty, Boldness, Trust, Team Spirit, Freedom, Fun and Modesty - have remained the same since company inception in 1967. To see how we bring these values to life, click here to listen to some of our employee’s stories.
Come join us, bring your whole self to work, create new possibilities for you, your customers and your community and help us to be Architects of Positive Futures.