Job Description
Senior Specialist, Cybersecurity (2 Years Contract)
Req ID:  1146
Posting Start Date:  08/09/2026

About Us

NTUC Health Co-operative Limited (NTUC Health) is an NTUC enterprise that provides a comprehensive and integrated suite of quality and accessible health and eldercare services to meet the growing needs of families and their dependents. Building on close to three decades of experience and expertise, NTUC Health is among the largest providers of active ageing, senior day care, nursing home, and home personal care services in Singapore. We also serve vulnerable seniors in selected areas in Singapore through Community Case Management Services (CCMS), CREST mental health support, and a sheltered senior group home. In addition, we run a family medicine clinic.

Our purpose is to achieve ‘health for life’; enabling healthy and fulfilling years by being a trusted partner of seniors and their families in our community.

For more information, please visit ntuchealth.sg or follow us on Facebook, Instagram, and LinkedIn.

Services:  Senior Day Care | Home Care | Nursing Home | Active Ageing and Senior Fitness | Rehabilitation and Physiotherapy | Family Medicine

Community Support: CCMS (Community Case Management Services) | CREST (Community Resource, Engagement and Support Team) | Henderson Home

Job Description

NTUC Health operates a growing digital environment supporting healthcare, eldercare, and community services across Singapore. 

As a Senior Specialist, Cybersecurity, you will help protect our systems, applications, endpoints, AI-enabled technologies and data by turning cybersecurity risks into practical risk-based recommendations, strengthening security controls, and working with technology teams and vendors to improve our overall security posture.

This is a hands-on role for someone who can operate across cybersecurity technology, cyber risk management, governance, and stakeholder engagement. You will work closely with Infrastructure, End User Support, Application teams, vendors and management to identify risks, drive remediation and ensure security is built into the way we operate.

What Success Looks like

  • Key cybersecurity risks are identified, prioritised, and driven to appropriate remediation.

  • Security testing findings are effectively managed with application and technology teams.

  • Key security controls and vendor services are operating effectively and delivering expected security outcomes.

  • Cybersecurity risk, third-party risk and audit issues are clearly reported and actively managed.

  • Security requirements are embedded into technology projects and operational processes.

 

What You Will Do

  • Act as the primary technical interface for external Managed Security Service Providers (MSSPs), and security service providers.

  • Evaluate vulnerability assessments and penetration testing reports, translating technical findings into prioritized remediation plans for internal teams.

  • Design, implement, and maintain security baselines across enterprise AWS and Google Cloud Platform (GCP) environments. 

  • Conduct cybersecurity risk assessments and recommend risk treatment plans.

  • Review vulnerability assessments, penetration tests and secure code reviews and drive remediation.

  • Manage cybersecurity vendors and support the implementation and operation of enterprise security controls, including PAM onboarding, WAF/CDN, firewall rules review, EDR and SASE.

  • Work with Infrastructure, End User Support and Application teams to address security gaps.

  • Support third-party risk assessments and vendor due diligence.

  • Coordinate cybersecurity awareness programmes, including newsletters, training and phishing campaigns, to improve security awareness and behavior.

  • Support management reporting, Cybersecurity Subcommittee meetings and internet/external audits.

Qualification

Must-Haves

  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity or a related discipline.

  • 5+ years of relevant cybersecurity experience, with practical exposure to cybersecurity operations, technology risk management, security engineering or governance.

  • Strong working knowledge of enterprise security technologies, such as NGFW/IDS/IPS, EDR/XDR, PAM, WAF, SIEM/SOAR, vulnerability management, SASE/ZTNA, DLP, and cloud computing controls.

  • Experience assessing and managing cybersecurity risks, including vulnerability assessments, penetration testing findings and remediation activities. 

  • Strong vendor and project management skills, with the ability to work effectively with technology teams and external service providers.

  • Strong communication and stakeholder management skills, with the ability to explain cybersecurity risks and recommendations clearly to both technical and non-technical stakeholders.

  • Familiar with regulatory instruments specifically MOH Cybersecurity and Data Security (CS/DS) Essentials, PDPC frameworks, and CSA advisories and guidelines.

 

Nice-to-Haves

  • Professional certifications such as CISSP, CISM, CISA or equivalent.

  • Knowledge of AI security frameworks and standards such as OWASP Top 10 for LLM and GenAI, guidelines from MOH and CSA.

  • Strong analytical, problem-solving, and stakeholder management skills.

  • Detail-oriented, proactive and willing to learn in a rapidly evolving cybersecurity environment.

Other Information