About Us
NTUC Health Co-operative Limited (NTUC Health) is an NTUC enterprise that provides a comprehensive and integrated suite of quality and accessible health and eldercare services to meet the growing needs of families and their dependents. Building on close to three decades of experience and expertise, NTUC Health is among the largest providers of active ageing, senior day care, nursing home, and home personal care services in Singapore. We also serve vulnerable seniors in selected areas in Singapore through Community Case Management Services (CCMS), CREST mental health support, and a sheltered senior group home. In addition, we run a family medicine clinic.
Our purpose is to achieve ‘health for life’; enabling healthy and fulfilling years by being a trusted partner of seniors and their families in our community.
For more information, please visit ntuchealth.sg or follow us on Facebook, Instagram, and LinkedIn.
Services: Senior Day Care | Home Care | Nursing Home | Active Ageing and Senior Fitness | Rehabilitation and Physiotherapy | Family Medicine
Community Support: CCMS (Community Case Management Services) | CREST (Community Resource, Engagement and Support Team) | Henderson Home
Job Description
NTUC Health operates a growing digital environment supporting healthcare, eldercare, and community services across Singapore.
As a Senior Specialist, Cybersecurity, you will help protect our systems, applications, endpoints and data by turning cybersecurity risks into a practical recommendation, strengthening security controls, and working with technology teams and vendors to improve our overall security posture.
This is a hands-on role for someone who can operate across cybersecurity technology, cyber risk management, governance and stakeholder engagement. You will work closely with Infrastructure, End User Support, Application teams, vendors and management to identify risks, drive remediation and ensure security is built into the way we operate.
What Success Looks like
- Key cybersecurity risks are identified, prioritised, and driven to appropriate remediation.
- Security testing findings are effectively managed with application and technology teams.
- Key security controls and vendor services are operating effectively and delivering expected security outcomes.
- Cybersecurity risk, third-party risk and audit issues are clearly reported and actively managed.
- Security requirements are embedded into technology projects and operational processes.
What You Will Do
- Conduct cybersecurity risk assessments and recommend risk treatment plans.
- Review vulnerability assessments, penetration tests and secure code reviews and drive remediation.
- Manage cybersecurity vendors and support the implementation and operation of enterprise security controls, including PAM onboarding, WAF/CDN, firewall rules review, EDR and SASE.
- Work with Infrastructure, End User Support and Application teams to address security gaps.
- Support third-party risk assessments and vendor due diligence.
- Coordinate cybersecurity awareness programmes, including newsletters, training and phishing campaigns, to improve security awareness and behavior.
- Support management reporting, Cybersecurity Subcommittee meetings and internet/external audits.
Assess emerging risks, including Al-related threats and governance requirements.
Qualification
Must-Haves
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity or a related discipline.
- 5+ years of relevant cybersecurity experience, with practical exposure to cybersecurity operations, technology risk management, security engineering or governance.
- Strong working knowledge of enterprise security technologies, such as NGFW/IDS/IPS, EDR/XDR, PAM, WAF, SIEM/SOAR, vulnerability management, SASE/ZTNA, DLP, and cloud computing controls.
- Experience assessing and managing cybersecurity risks, including vulnerability assessments, penetration testing findings and remediation activities.
- Strong vendor and project management skills, with the ability to work effectively with technology teams and external service providers.
- Strong communication and stakeholder management skills, with the ability to explain cybersecurity risks and recommendations clearly to both technical and non-technical stakeholders.
- Knowledge of AI security risks, AI governance and emerging technology risks.
- Experience with cybersecurity governance, regulatory requirements and vendor due diligence.
Nice-to-Haves
- Professional certifications such as CISSP, CISM, CISA or equivalent.
- Strong analytical, problem-solving, and stakeholder management skills.
- Detail-oriented, proactive and willing to learn in a rapidly evolving cybersecurity environment.