Senior Cybersecurity Engineer (Data Security), Department of Statistics
GovTech · Singapore ·
- Seniority
- Senior
- Category
- Security
A senior data security role within GovTech serving the Department of Statistics: the engineer acts as a Data Security Officer who implements data access controls and data virtualisation (Denodo), runs risk assessments, automates compliance checks, and keeps data handling aligned with IM8 and other Singapore government security regulations.
GovTech supports various Government Agencies in carrying out ICT delivery services and appoints Data Security Officers to oversee data security management within these agencies. The Data Security Officer role requires technical proficiency demonstrated in multiple cybersecurity domains. The role demands knowledge and/or practical experience in most of the domains below:
- Cybersecurity Governance frameworks,
- Security Operations including incident response,
- Architecture design and threat risk assessment,
- Security Testing.
The Data Security Officer will conduct comprehensive analysis of data assets, evaluate existing controls, and assess compliance throughout the data lifecycle, whilst providing actionable implementation recommendations to strengthen Department of Statistic's data security posture.
What you will be working on:
Implementation and Oversight
- Spearhead the deployment of enhanced data access controls and advanced virtualisation strategies
- Manage the seamless integration of automated compliance checks within existing workflows
- Monitor and enhance data protection measures through continuous assessment
Risk Management and Compliance
- Execute regular risk assessments focusing on data assets and access patterns
- Maintain alignment with IM8 requirements, PSDSRC recommendations and relevant regulatory frameworks
- Develop and update comprehensive data security policies and procedures
Data Flow Analysis and Optimisation
- Evaluate organisational data usage patterns and workflows
- Identify and implement data virtualisation opportunities
- Partner with divisions to streamline data access processes
Technology Optimisation
- Leverage Denodo's capabilities to their full potential
- Monitor and evaluate emerging data security technologies for potential implementation
What we are looking for:
- Candidate CRISC certified or experience on ISO27001 certification as lead implementer or auditor will have an advantage
- Experience in setting up policy and operating Denodo or similar tools will be an advantage
- Possess knowledge or experience in Information Systems, Information Technology, Computer Engineering, Risk Analytics or related fields
- Familiarity with data access controls, data lifecycle management, and compliance frameworks will be advantageous
- Proactively monitor control implementation and propose any mitigation measure necessary to maintain risk posture
- Strong problem-solving and analytical skills, with attention to detail
- Good communication skills
- Able to work well both independently and as a member of a team