Lead/Senior Cybersecurity Operations Specialist (Security Services)
Lead/Senior Cybersecurity Operations Specialist (Security Services)

Lead/Senior Cybersecurity Operations Specialist (Security Services)

Full-Time 48000 - 84000 £ / year (est.) Home office (partial)
J

At a Glance

  • Tasks: Lead cybersecurity initiatives and enhance security testing across the organisation.
  • Company: Join a leading agency transforming public sector digital security.
  • Benefits: Enjoy competitive perks, generous leave, and flexible work options.
  • Why this job: Make a real impact in cybersecurity while developing your skills.
  • Qualifications: 8-10 years in cybersecurity with expertise in offensive and application security.
  • Other info: Collaborative environment focused on continuous learning and innovation.

The predicted salary is between 48000 - 84000 £ per year.

The client is a leading agency driving their clients' initiatives and public sector digital transformation. As the Centre of Excellence for Infocomm Technology and Smart Systems (ICT & SS), the client develops capabilities in Data Science & Artificial Intelligence, Application Development, Smart City Technology, Digital Infrastructure, and Cybersecurity.

The Cyber Security Group is the cybersecurity arm of our client, committed to creating a digital government that is safe and secure. CSG delivers technical and operational capabilities to counteract cyber threats, provides thought leadership on transformative cybersecurity governance and policies, and strengthens the cybersecurity posture of government agencies sustainably and effectively.

As the Security Services Specialist within the firm, you will be the domain expert responsible for elevating the security testing and "Secure-by-Design" capabilities across the entire firm. You will bridge the gap between high-level governance and technical implementation, ensuring that all agencies under the firm’s purview adopt consistent, high-quality security practices. Your role is pivotal in shifting the firm from a reactive security posture to a proactive, resilient one.

Key Responsibilities
  • Security Testing Governance & Standardisation
    • Establish Standards: Define and maintain the Ministry-wide framework for security testing (Vulnerability Assessment and Penetration Testing - VAPT).
    • SOP Development: Create and roll out Standard Operating Procedures (SOPs) to guide Agency project teams on engaging external security vendors and managing internal testing cycles.
    • Quality Assurance: Develop "Quality Rubrics" to help agencies evaluate the performance of pen-testers.
  • Advanced Technical Operations
    • Red Teaming & Critical Testing: Lead and execute complex Red Teaming exercises and deep-dive penetration tests on the client’s high-impact systems.
    • Adversary Simulation: Utilise knowledge of the latest Adversary Tactics, Techniques, and Procedures (TTPs) to simulate real-world attacks, helping agencies identify blind spots in their prevention, detection, and response capabilities.
    • Environmental Scanning: Proactively monitor the global threat landscape to identify emerging threats and evolving actor TTPs.
  • Secure-by-Design & Source Code Excellence
    • Secure Coding Standards: Establish Ministry-wide secure coding guidelines (e.g., based on OWASP, SANS) to ensure developers build security into the application layer from day one.
    • Source Code Analysis: Lead the strategy for Static Application Security Testing (SAST) and Software Composition Analysis (SCA).
    • CI/CD Integration: Evaluate, recommend, and provide guidance on integrating security tools into the agencies' DevOps pipelines (DevSecOps).
    • Code Quality Oversight: Review and recommend systems that help to boost code quality, ensuring that security is treated as a core component of "clean code."
    • Technology Foresight: Stay abreast of technology changes (e.g., Cloud-native security, AI-driven development) and recommend systems/technologies that enhance code quality and resilience.
  • Stakeholder Engagement & Advocacy
    • Consultative Leadership: Act as a trusted advisor to Agency CIOs, ACISOs, and Project Owners to educate them and inculcate a culture of secure-by-design.
    • Community of Practice: Establish a platform for knowledge sharing among security practitioners within the firm to harmonise security testing efforts.
Experience
  • Years of Experience: 8 to 10 years of deep technical experience in Cybersecurity, with a strong focus on offensive security and application security.
  • Domain Expertise: Proven track record in conducting penetration tests for Web Applications, IT Systems (on-premises and cloud environments), and complex Network architectures.
  • Code Review Mastery: Experience in performing manual and automated source code reviews to identify logic flaws, injection vulnerabilities, and cryptographic weaknesses.
Technical Skills
  • Secure Development: Deep understanding of secure software development lifecycles (SSDLC) and the ability to read/analyse common programming languages (e.g., Java, Python, .NET, JavaScript).
  • Source Code Analysis Tools: Proficiency with enterprise-grade SAST, DAST, SCA, and VAPT tools (e.g., Checkmarx, Fortify, SonarQube, Snyk, Burp Suite).
  • Offensive Security: Proficiency in manual and automated testing tools; deep understanding of the MITRE ATT&CK framework and common TTPs.
  • Cloud & DevOps: Experience with Government Commercial Cloud (GCC) environments and practical knowledge of Jenkins, GitLab CI, or GitHub Actions.
  • Certifications: Professional certifications such as OSCP, OSWE (Offensive Security Web Expert), CASE (Certified Application Security Engineer), or GWEB are highly desirable.
Soft Skills
  • Influence & Diplomacy: Ability to communicate complex technical risks to non-technical stakeholders (CIOs/Project Owners) and influence change without direct reporting lines.
  • Analytical Mindset: Ability to spot patterns in "bad" testing jobs or recurring code vulnerabilities and provide constructive feedback to improve agency-level performance.
  • Intellectual Curiosity: A strong commitment to continuous learning and keeping pace with the rapidly evolving cyber threat landscape.
Other Requirements
  • This role is open to Singaporeans Only.
  • We are an equal opportunity employer and value diversity at our company as we believe that diversity is meaningful to innovation.
  • Our employee benefits are based on a total rewards approach, offering a holistic and market-competitive suite of perks, including generous leave benefits to meet your work-life needs.

Lead/Senior Cybersecurity Operations Specialist (Security Services) employer: JOHN ETHANS INTERNATIONAL PTE. LTD.

As a leading agency in Singapore focused on digital transformation and cybersecurity, we offer our employees a purposeful career that empowers them to master their craft through continuous learning and development opportunities. Our work culture promotes innovation and collaboration, ensuring that every team member plays a vital role in creating a safe and secure digital government. With generous leave benefits and the flexibility to work from home, we prioritise work-life balance while fostering an environment where diverse perspectives drive meaningful change.
J

Contact Detail:

JOHN ETHANS INTERNATIONAL PTE. LTD. Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Lead/Senior Cybersecurity Operations Specialist (Security Services)

✨Tip Number 1

Network like a pro! Get out there and connect with folks in the cybersecurity field. Attend meetups, webinars, or even online forums. You never know who might have the inside scoop on job openings or can put in a good word for you.

✨Tip Number 2

Show off your skills! Create a portfolio showcasing your cybersecurity projects, whether it's vulnerability assessments or secure coding practices. This gives potential employers a taste of what you can bring to the table.

✨Tip Number 3

Prepare for interviews by brushing up on common cybersecurity scenarios. Be ready to discuss how you've tackled security challenges in the past. Practice makes perfect, so consider mock interviews with friends or mentors.

✨Tip Number 4

Don't forget to apply through our website! We’ve got loads of opportunities waiting for talented individuals like you. Plus, it’s a great way to ensure your application gets the attention it deserves.

We think you need these skills to ace Lead/Senior Cybersecurity Operations Specialist (Security Services)

Cybersecurity
Vulnerability Assessment
Penetration Testing
Red Teaming
Adversary Tactics, Techniques, and Procedures (TTPs)
Secure Coding Standards
Static Application Security Testing (SAST)
Software Composition Analysis (SCA)
DevSecOps
Source Code Analysis Tools
Offensive Security
MITRE ATT&CK framework
Cloud Security
Analytical Skills
Influence & Diplomacy

Some tips for your application 🫡

Tailor Your CV: Make sure your CV is tailored to the Lead/Senior Cybersecurity Operations Specialist role. Highlight your relevant experience in cybersecurity, especially in offensive security and application security. We want to see how your skills align with our mission!

Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about cybersecurity and how you can contribute to our goal of creating a safe digital government. Keep it engaging and personal – we love a good story!

Showcase Your Technical Skills: Don’t hold back on showcasing your technical expertise! Mention specific tools and methodologies you’ve used, like SAST, DAST, or VAPT. We’re looking for someone who knows their stuff and can bridge the gap between governance and technical implementation.

Apply Through Our Website: We encourage you to apply through our website for a smoother process. It’s the best way for us to receive your application and ensure it gets the attention it deserves. Plus, you’ll find all the details you need about the role there!

How to prepare for a job interview at JOHN ETHANS INTERNATIONAL PTE. LTD.

✨Know Your Stuff

Make sure you brush up on your technical skills, especially in offensive security and application security. Be ready to discuss your experience with penetration testing, secure coding standards, and the tools you've used like Checkmarx or Burp Suite.

✨Showcase Your Leadership Skills

As a Lead/Senior Cybersecurity Operations Specialist, you'll need to demonstrate consultative leadership. Prepare examples of how you've influenced non-technical stakeholders or led teams in previous roles to foster a culture of security.

✨Stay Current with Trends

The cybersecurity landscape is always changing, so be prepared to talk about the latest threats and technologies. Familiarise yourself with current Adversary Tactics, Techniques, and Procedures (TTPs) and how they impact security practices.

✨Prepare for Scenario Questions

Expect scenario-based questions that test your problem-solving skills. Think about how you would handle specific security challenges, such as conducting a Red Team exercise or implementing secure coding guidelines across multiple agencies.

Lead/Senior Cybersecurity Operations Specialist (Security Services)
JOHN ETHANS INTERNATIONAL PTE. LTD.

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

J
Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>