Security Consultant - Government

Unison GroupSingaporeOn-siteContractStaff, 8–12 yearsListed 8 hours ago

Apply now

About this role

We are seeking an experienced Security Consultant to join our Security Architecture and Consultancy team. In this role, you will serve as a trusted advisor to project teams across the organisation, guiding them in designing secure systems and making sound security decisions throughout the project lifecycle.

You will bring deep technical expertise and a consultative approach to help teams navigate complex security challenges — from early solutioning and architecture design through to risk assessment, threat modelling, and architecture review. Beyond individual engagements, you will also contribute to building the team's capabilities by developing enterprise security standards, AI-powered tools, and reusable frameworks that raise the security bar across the organisation.

Key Responsibilities

• Engage project teams as a trusted security advisor, supporting them in solutioning and secure system design across cloud, on-premises, and hybrid environments, from early concept through to deployment

• Conduct in-depth security architecture reviews for new and existing systems, identifying design-level vulnerabilities, misconfigurations, and control gaps, and providing prioritised and actionable remediation recommendations

• Advise project teams on the application of security design patterns and best practices across key domains including cloud security, application security, identity and access management, and data protection

• Perform structured threat modelling on systems and applications, identifying potential threats and attack vectors, and recommending proportionate mitigation controls aligned to the risk profile of the system

• Conduct risk assessments to identify, evaluate, and prioritise security risks, translating technical findings into clear business impact to support informed decision-making by project teams and senior stakeholders

• Develop and maintain security design patterns covering key domains including cloud security, application security, identity and access management, data protection, and AI system deployments.

• Develop and maintain enterprise security standards and baselines across key domains including endpoint security, network security, cryptography, and AI system deployments, ensuring they remain aligned with government security policies, the evolving threat landscape, and organisational needs

• Assess the security posture of AI and machine learning systems, identifying risks across the model lifecycle including development, training, deployment, and ongoing operations, and recommending appropriate controls to address identified risks

• Advise on the secure and responsible deployment of AI systems, including defining guardrails, human oversight mechanisms, and incident response considerations specific to AI-related security events

• Evaluate and advise on the use of third-party AI services and large language model integrations, assessing risks related to data residency, vendor access, model behaviour, and supply chain exposure

• Develop and iterate on AI-powered tools and workflows to enhance the efficiency and quality of security consultancy activities, such as threat modelling, risk assessment, and architecture review

• Collaborate with project teams and peers to identify repetitive or time-intensive security tasks that could benefit from AI-assisted automation, and prototype practical solutions to address these

Requirements

Qualification

• Bachelor’s degree in Computer Science, Information Security, or related field

• Minimum 9 years of relevant experience in cybersecurity, with a strong focus on security architecture, risk assessment, and security consultancy across cloud, on-premises, and hybrid environments

• Deep knowledge of security architecture principles and practices across key domains including cloud security, application security, identity and access management, and data protection

• Strong understanding of risk management methodologies, threat modelling techniques, and security compliance frameworks

• Working knowledge of Singapore Government security policies and frameworks, including IM8 and CCoP, with experience working in or with Singapore Government agencies being highly advantageous

• Familiarity with AI security concepts and the security implications of AI and machine learning system deployments

• Excellent communication and stakeholder engagement skills, with the ability to present complex security concepts clearly to both technical and non-technical audiences

• Ability to work independently, manage multiple concurrent engagements, and deliver quality outcomes with minimal supervision

• Professional certifications such as CISM, CRISC, CISSP, or equivalent are preferred

• Relevant certifications such as AWS Certified Security - Specialty or Certified Cloud Security Professional (CCSP) are a plus