Back to board
Early applicant
Singapore Public Service (PSD)·Other·1 day ago

Senior Manager / Executive Manager (Inspection), Risk Assurance Division

IMDSenior · 8-12 yearsH1B likely

About this role

[What the role is]

You will be part of the Risk Assurance Division within IMDA’s Resilience and Cybersecurity Group. The Holistic Assessment team in this Division assesses the overall cybersecurity risk posture of critical digital networks and systems and the cyber capabilities of organisations operating these networks.

This includes integrating diverse sources of information, across the organisation’s external environment, its internal capabilities and the performance of its networks and systems. The team adopts an evidence-based approach to develop an objective assessment of the organisation and network’s key strengths and vulnerabilities. It also recommends key areas that senior management should track to uplift its cybersecurity risk posture.

The Holistic Assessment team works with teams across IMDA’s Resilience and Cybersecurity Group, and in partnership with industry stakeholders. It regularly engages senior management in both IMDA and the industry, to review its findings and recommendations. Through these, the Holistic Assessment team plays a critical role in ensuring that the critical digital networks and systems which underpin Singapore’s Digital Economy remain secure and resilient.

[What you will be working on]

  • Conduct research and sense making of the evolving cybersecurity landscape in relation to Singapore’s digital infrastructure. This includes integrating threat intelligence information as well as international industry best practices for defending against current and emerging cyber threats.
  • Review and assess key priorities that inspections should focus on, based on the current and emerging threat landscape, as well as potential vulnerabilities surfaced in cyber audit reports and remediations implemented.
  • Design technical tests to validate the effectiveness of cybersecurity measures within these priority areas. This requires a deep understanding of the network design, what the cybersecurity measures are intended to protect against, as well as how they contribute to the overall cybersecurity of the digital network and systems as a whole.
  • Conduct the technical validation tests.
  • Synthesise key findings from the inspections, on the strengths and vulnerabilities of the network. Recommend remediations that should be implemented to improve the overall cybersecurity of the digital network and systems inspected.

[What we are looking for]

  • Background in Information Security, Engineering, Computer Science or equivalent with 8 years of experience in relevant fields or capacity.
  • Possess relevant OSCP, CREST or GIAC certification in offensive operations or equivalent.
  • Good understanding of the digital landscape and appreciation of how the different facets of cyber threats and defence interact and impact the cybersecurity of digital networks and systems.
  • Possess strong analytical skills and an attention to detail.
  • Have an inquisitive mind to explore and evaluate novel methods of testing.
  • Excellent writing and communication skills. This includes translating technical findings to their strategic and business impact.
  • Enjoy working in a fast-paced and dynamic environment.
  • Able to work independently as well as in a team/cross-team setting.

The position offered will be commensurate with experience.

Only shortlisted candidates will be notified.