Cybersecurity Engineer (GRC Manager)
Core
Lead Governance, Risk, and Compliance (GRC) operations as the 2nd line of defence, shaping risk governance, automating security plan audits, and managing ICT audit workflows for GovTech's digital products.
Role type
Senior GRC Manager (2nd line of defence)
Builds
Automated security assurance workflows, standardized security plans, and policy frameworks for GovTech's CIOO and product teams.
Domain
Public sector cybersecurity, ICT governance, and regulatory compliance.
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
ICT governance and security controls, SDLC and agile delivery integration, enterprise issue-tracking and collaboration platforms, security policy drafting and lifecycle management, security awareness training design, stakeholder influence and negotiation, automation of audit processes.
Preferred skills
Phishing simulation design, AI-enabled tool usage for GRC, change management leadership.
Responsibilities
Act as de facto GRC lead and 2nd line of defence for ICT risk; own governance and automation of Security Plan submissions; design and execute ICT audit workflows; author and manage GovTech-wide security policies; lead Security Education, Training, and Awareness (SeTA) campaigns; champion new audit practices through stakeholder engagement.
Seniority
Senior, hands-on IC with leadership responsibilities
