Senior Specialist, Cybersecurity (2 Years Contract)
ntuc health co-operative limited- Posted 3 days ago
- Be among the first 10 applicants
Job Description
NTUC Health operates a growing digital environment supporting healthcare, eldercare, and community services across Singapore.
As a Senior Specialist, Cybersecurity, you will help protect our systems, applications, endpoints, AI-enabled technologies and data by turning cybersecurity risks into practical risk-based recommendations, strengthening security controls, and working with technology teams and vendors to improve our overall security posture.
This is a hands-on role for someone who can operate across cybersecurity technology, cyber risk management, governance, and stakeholder engagement. You will work closely with Infrastructure, End User Support, Application teams, vendors and management to identify risks, drive remediation and ensure security is built into the way we operate.
What Success Looks like
- Key cybersecurity risks are identified, prioritised, and driven to appropriate remediation.
- Security testing findings are effectively managed with application and technology teams.
- Key security controls and vendor services are operating effectively and delivering expected security outcomes.
- Cybersecurity risk, third-party risk and audit issues are clearly reported and actively managed.
- Security requirements are embedded into technology projects and operational processes.
What You Will Do
- Act as the primary technical interface for external Managed Security Service Providers (MSSPs), and security service providers.
- Evaluate vulnerability assessments and penetration testing reports, translating technical findings into prioritized remediation plans for internal teams.
- Design, implement, and maintain security baselines across enterprise AWS and Google Cloud Platform (GCP) environments.
- Conduct cybersecurity risk assessments and recommend risk treatment plans.
- Review vulnerability assessments, penetration tests and secure code reviews and drive remediation.
- Manage cybersecurity vendors and support the implementation and operation of enterprise security controls, including PAM onboarding, WAF/CDN, firewall rules review, EDR and SASE.
- Work with Infrastructure, End User Support and Application teams to address security gaps.
- Support third-party risk assessments and vendor due diligence.
- Coordinate cybersecurity awareness programmes, including newsletters, training and phishing campaigns, to improve security awareness and behavior.
- Support management reporting, Cybersecurity Subcommittee meetings and internet/external audits.
Qualification
Must-Haves
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity or a related discipline.
- 5+ years of relevant cybersecurity experience, with practical exposure to cybersecurity operations, technology risk management, security engineering or governance.
- Strong working knowledge of enterprise security technologies, such as NGFW/IDS/IPS, EDR/XDR, PAM, WAF, SIEM/SOAR, vulnerability management, SASE/ZTNA, DLP, and cloud computing controls.
- Experience assessing and managing cybersecurity risks, including vulnerability assessments, penetration testing findings and remediation activities.
- Strong vendor and project management skills, with the ability to work effectively with technology teams and external service providers.
- Strong communication and stakeholder management skills, with the ability to explain cybersecurity risks and recommendations clearly to both technical and non-technical stakeholders.
- Familiar with regulatory instruments specifically MOH Cybersecurity and Data Security (CS/DS) Essentials, PDPC frameworks, and CSA advisories and guidelines.
Nice-to-Haves
- Professional certifications such as CISSP, CISM, CISA or equivalent.
- Knowledge of AI security frameworks and standards such as OWASP Top 10 for LLM and GenAI, guidelines from MOH and CSA.
- Strong analytical, problem-solving, and stakeholder management skills.
- Detail-oriented, proactive and willing to learn in a rapidly evolving cybersecurity environment.
This is in partnership with the Employment and Employability Institute Pte Ltd (e2i). e2i is the empowering network for workers and employers seeking employment and employability solutions. e2i serves as a bridge between workers and employers, connecting with workers to offer job security through job-matching, career guidance and skills upgrading services, and partnering employers to address their manpower needs through recruitment, training, and job redesign solutions. e2i is a tripartite initiative of the National Trades Union Congress set up to support nation-wide manpower and skills upgrading initiatives.
By applying for this role, you consent to NTUC Health's PDPA and e2i's PDPA.




