GovTech supports various Government Agencies in carrying out ICT delivery services. The appointment of the Agency Chief Security Information Officers (ACISO) who have familiarity with Cybersecurity Governance, Operations, Engineering and Testing in on-premises and major cloud platforms (e.g., AWS, Azure, and GCP) and their security features, will ensure security is well-considered and uplifted in Agency’s ICT and digitalisation transformation matters.
The ACISO will lead all aspects of the agency’s infocomm security management by planning, refining, recommending and implementing strategies, policies, and globally accepted practices aligned with the regulatory requirements. Are you looking for a leadership role in your next cybersecurity career? If so, then this role provides the driver's seat and a highly visible exposure in cybersecurity management.
[What you will be working on]
Emplaced in public agencies and reporting to the agency’s Chief Information Officer (CIO), you will collaborate with various stakeholders (including Ministry Family CISO (MCISO), GovTech HQ teams, Agency management teams, Agency project teams, and outsourced vendors) and will be responsible to:
- Lead the formulation of cyber security strategies and work plan, policies, standards and guidelines, supporting agency's digitalisation planning and aligning with Ministry Family (MF) strategic goals and policy baselines.
- Ensure the formulated Agency ICT security policies remain aligned with Ministry Family’s (MF’s) ICT security strategy goals with regular Gap analysis performed.
- Assist Agency management in overseeing ICT security matters, such as approving and tracking ICT security work plan and resourcing, monitoring performance in security indicators and risk acceptance decisions.
- Govern the security posture of the Agency by maintaining a full visibility of all ICT systems (Assets) across different operating environments, the systems’ security design, implementation and operations through regular reviews.
- Implement Cybersecurity risk assessment and acceptance processes at the management level. Review, provide consultation and endorse risk management and mitigation plans from agency’s project teams.
- Provide advisory and consultancy on the appropriate cyber security solutions and technologies to be deployed suitable to agency’s business operations and aligned with WOG-wide advisories and practices.
- Ensure the Agencies’ secure ICT development life cycle is complying to the security policies, and the security controls implementations are complying to the defined security policies, standards and guidelines.
- Design and implement end user security awareness programmes and establish defined processes for Threat and Incident Management.
- Plan, design and conduct security incident response workshops and exercises (table-top exercises, simulation and drills) and lead the investigation and management of ICT security incidents.