Public Service Division

[LTA-ITCD] SNR/EXEC CYBERSECURITY ENGINEER, CYBER ARCHITECTURE & DEVT

Public Service Division Singapore

IT Services and IT Consulting · 1,001-5,000 employees

Yesterday
security Mid (2-5 yrs) Full-time Singapore
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

You will lead end-to-end vulnerability assessments and adversarial attack simulations to strengthen digital system resilience. Additionally, you will advise project teams on secure architecture and explore the integration of AI into cybersecurity testing processes.

What they look for

Vulnerability Assessment Penetration Testing Adversarial Attack Simulation Cybersecurity Architecture Cloud Security Network Security Red Teaming Purple Teaming AI Security Risk Assessment Scripting Security Automation Encryption Authentication Protocols MITRE ATT&CK

Requirements

Candidates should have at least 2 years of experience in VAPT or offensive security and possess strong technical foundations in cloud and network security. Professional certifications such as OSCP, CREST, or CISSP are highly preferred for this role.

Benefits

Professional development Knowledge sharing Collaborative environment

Full description

[What the role is]

SENIOR / EXECUTIVE CYBERSECURITY ENGINEER, CYBER ARCHITECTURE & DEVELOPMENT

[What you will be working on]

Join a forward-looking cybersecurity team where your technical expertise will directly strengthen the resilience of critical digital systems. You will work on high-impact Vulnerability Assessment and Penetration Testing (VAPT), build our in-house Adversarial Attack Simulation (AAS) capability, and advise project teams on secure architecture and implementation. You will also have the opportunity to explore and shape the responsible use of Artificial Intelligence (AI) in VAPT, helping us improve testing depth, speed, consistency, and insight. This role offers a distinctive blend of hands-on offensive security, capability development, innovation, and stakeholder engagement, with opportunities to influence how cybersecurity assurance evolves across the organisation. Key responsibilities include:

  • Lead and deliver end-to-end VAPT across applications, infrastructure, networks, and cloud environments by identifying exploitable weaknesses, validating business impact, and helping system owners remediate effectively.
  • Design and execute safe, controlled Adversarial Attack Simulation exercises that emulate realistic threat actors and attack paths, revealing blind spots across preventive, detective, response, and recovery controls.
  • Explore, prototype, and evaluate AI-enabled approaches for VAPT, including test planning, attack-path analysis, vulnerability triage, evidence correlation, report generation, and remediation guidance, with appropriate governance and human oversight.
  • Serve as a trusted cybersecurity advisor to digital projects by conducting risk assessments, reviewing security architecture, and recommending practical, risk-informed security solutions.
  • Partner with architects, developers, project teams, system owners, vendors, and security operations teams to embed secure-by-design practices throughout the system lifecycle.
  • Track emerging vulnerabilities, attacker techniques, AI-enabled threats, and security technologies, translating developments into stronger testing methods, playbooks, and defensive improvements.
  • Analyse and trend cybersecurity findings across VAPT, AAS, and other assurance activities to identify recurring weaknesses, systemic root causes, risk concentrations, and emerging patterns, translating these insights into dashboards, targeted remediation priorities, and improvements to security standards, testing playbooks, and preventive controls.
  • Communicate complex technical findings clearly to both technical and non-technical stakeholders, turning assessment results into prioritised and actionable recommendations.

What you can look forward to: meaningful work that protects critical services; exposure to diverse technology environments; opportunities to build new VAPT, AAS, and AI-assisted testing capabilities; and a collaborative setting that supports experimentation, professional development, and knowledge sharing.

[What we are looking for]

We are looking for a driven, hands-on cybersecurity professional who combines strong technical foundations with sound judgement, collaboration, and a drive to keep learning.

  • Knowledge in Cybersecurity, Computer Science, Information Technology, or a related discipline, or equivalent relevant experience.
  • OSCP, a relevant CREST certification, or an equivalent hands-on offensive security credential is preferred.
  • CISSP (Certified Information Systems Security Professional), CISM (Certified Information Security Manager), CRISC (Certified in Risk and Information Systems Control), and CISA (Certified Information Systems Auditor) certifications are advantageous.
  • At least 2 years of relevant experience in VAPT, offensive security, cybersecurity engineering, or security consultancy; candidates with strong practical capability gained through labs, competitions, research, or substantial independent projects may also be considered.
  • Demonstrated hands-on capability with VAPT methodologies, manual testing techniques, and commonly used security assessment tools.
  • Experience with adversary emulation, red teaming, purple teaming, attack frameworks such as MITRE ATT&CK, or the validation of security monitoring and incident response capabilities is advantageous.
  • Familiarity with AI and machine learning concepts, large language models, AI-assisted security testing tools, scripting, or security automation, together with an understanding of responsible AI use and associated risks, is advantageous.
  • Strong understanding of cloud configuration, network security, encryption, and authentication protocols.
  • Strong analytical and problem-solving skills, with the ability to work independently, collaborate across teams, manage priorities, and explain technical risks clearly in writing and conversation.

Similar roles