Cybersecurity Engineer (Solutioning and Architecture) - Multiple Headcounts
- Employment
- Contract
- Posted
- 11d ago
Assurity Trusted Solutions (ATS) is a wholly owned subsidiary of the Government Technology Agency (GovTech). As a Trusted Partner over the last decade, ATS offers a comprehensive suite of products and services ranging from infrastructure and operational services, authentication services, governance and assurance services as well as managed processes. In a dynamic digital and cyber landscape, where trust & collaboration are key, ATS continues to drive mutually beneficial business outcomes through collaboration with GovTech, government agencies and commercial partners to mitigate cyber risks and bolster security postures. We are looking for individuals to join us as Cybersecurity Engineer (Architecture & Solutioning). This person should be familiar with the cybersecurity domains, including Network Security or Device/Endpoint Management. This will be offered as a contract employment till 30 November 2028. Senior role may be offered, subjected to the interview outcomes. Responsibilities: Conduct cybersecurity architecture reviews, security design reviews, and Threat Risk Assessments (TRAs) for new products, features, technology adoption, and significant system changes. Assess risks, recommend treatments, and document residual risks for management decision-making. Perform threat modelling using structured methodologies (e.g. STRIDE) and industry frameworks such as MITRE ATT&CK to identify threats, attack paths, adversary techniques, and required security controls. Serve as the cybersecurity subject matter expert (SME) for assigned products and services, providing guidance on cybersecurity risks, security architecture, and control implementation throughout the system lifecycle. Define security requirements and develop technical security specifications and tender clauses to support procurement, implementation, and deployment activities. Drive security-by-design practices across the software and infrastructure lifecycle by defining security patterns, guardrails, reference architectures, and control requirements that enable secure and scalable product delivery. Lead and influence product, engineering, and infrastructure teams in implementing cybersecurity controls across cloud, on-premises, application, container, microservices, database, and network environments. Define, review, and govern security assessments, including vulnerability assessments, penetration testing, source code reviews, hardening reviews, and compliance assessments. Validate remediation plans, control effectiveness, and residual risks. Assess deployment readiness from a cybersecurity perspective and ensure appropriate security controls are implemented prior to production rollout. Conduct continual compliance and security posture reviews to identify security gaps, emerging risks, and improvement opportunities across systems, cloud services, and platform environments. Evaluate new technologies, platforms, and services through cybersecurity reviews, proof-of-concept (PoC) exercises, lab testing, and cybersecurity due diligence activities to determine suitability for adoption. Collaborate with government agencies, product teams, vendors, and industry partners to define security requirements, implement security controls, drive remediation of identified risks and findings, and provide risk-informed cybersecurity and architecture recommendations to support decision-making. Develop and implement automation, reusable security controls, workflows, and engineering solutions to improve the effectiveness, consistency, and scalability of cybersecurity assurance and risk management activities. Contribute to the continuous improvement of cybersecurity processes, standards, templates, playbooks, and automation initiatives to improve security assurance effectiveness and efficiency. Requirements At least 5 years of experience in the cybersecurity domain, with hands-on experience in cybersecurity architecture, security engineering, security assessments, or risk management activities. Experience in conducting Threat Risk Assessments (TRAs), threat modelling, vulnerability assessments (VA), penetration testing (PT), and security architecture or design reviews for enterprise systems, applications, cloud platforms, or infrastructure environments. Experience in the deployment, management, or maintenance of security technologies and infrastructure, and working with cross-functional teams, vendors, and contractors to implement cybersecurity controls and drive remediation activities. Strong understanding of cybersecurity principles and frameworks, including secure system design, cloud security, Zero Trust architecture, OWASP, MITRE ATT&CK, and risk management methodologies. Familiarity with modern engineering practices and technologies, including DevOps, DevSecOps, Infrastructure as Code (IaC), container platforms, microservices, software-defined networking, and public cloud services. Strong analytical, problem-solving, communication, stakeholder engagement, and report-writing skills, with the ability to assess and prioritise cybersecurity risks, influence security and architecture decisions, and translate complex technical issues into practical and actionable recommendations for both technical and non-technical stakeholders. Self-motivated and self-directed, with clear and logical thinking, a strong technical foundation, and willingness to learn new technologies, cybersecurity approaches, and emerging threats. Professional certifications such as CISSP, CCSP, OSCP, AWS Security Specialty, Azure Security Engineer, or equivalent cybersecurity and cloud security certifications will be advantageous. Knowledge of secure software development lifecycle (SSDLC), applied cryptography, public key infrastructure (PKI), key management, hardware security modules (HSMs), and network security protocols such as TLS and IPSec will be advantageous. Join us and discover a meaningful and exciting career with Assurity Trusted Solutions! The remuneration package will commensu