Job Description
Job Title:
Chief Information Security Officer (CISO)
Requisition ID:
3361
Posting Start Date:
05/10/2026
Job Summary
The Chief Information Security Officer (CISO) is responsible for providing strategic leadership, governance, and oversight of A*STAR's cybersecurity programme to safeguard its information assets, systems, and services. The CISO shall collaborate closely with the Chief Information Officer (CIO), A*STAR, to ensure that day-to-day ICT security operations, initiatives, and projects are aligned, non-duplicative, and compliant with prevailing cybersecurity policies, standards, and regulatory requirements.
Key Responsibilities
- Cybersecurity Strategy
- Formulate and maintain A*STAR's cybersecurity strategy, roadmap, and work plan.
- Ensure alignment of A*STAR's cybersecurity objectives with the Ministry of Trade and Industry (MTI) Family cybersecurity strategy and the directions of the Information and Digital Security Committee (IDSC).
- Lead cybersecurity planning and prioritisation to support A*STAR's organisational goals and risk management objectives.
- Ensure adequate cybersecurity resources, capabilities, and competencies are in place to meet strategic and operational requirements.
- Cybersecurity Maturity and Gap Analysis
- Conduct periodic cybersecurity maturity and gap assessments across A*STAR.
- Evaluate cybersecurity posture against the MTI Family Cybersecurity Maturity Model (CMM) and other relevant industry maturity frameworks.
- Identify areas for improvement and drive remediation plans to enhance organisational cybersecurity resilience.
- Security Governance
- Establish and maintain effective cybersecurity governance across A*STAR, including oversight of all A*STAR Research Institutes (RIs).
- Ensure compliance with MTI Family cybersecurity requirements, A*STAR policies, and applicable regulatory obligations.
- Develop, monitor, and report cybersecurity metrics and key performance indicators to MTI, A*STAR Senior Management, and the IDSC.
- Implement and oversee cybersecurity risk and control programmes to maintain and improve A*STAR's security posture.
- Oversee cybersecurity audits, assessments, reviews, and compliance activities across A*STAR's ICT systems.
-
- Maintain enterprise-wide visibility and oversight of cybersecurity matters relating to ICT systems, applications, products, and services across intranet, internet, and extranet environments.
- Policy, Standards and Compliance
- Develop, implement, and maintain A*STAR's cybersecurity policies, standards, and guidelines.
- Ensure alignment with MTI's ICT Security Policy Baseline and relevant industry standards, frameworks, and best practices.
- Drive organisation-wide awareness, adoption, and compliance with cybersecurity policies and standards.
- Cybersecurity Risk Management
- Establish policies, standards, and processes governing cybersecurity risk assessments for all A*STAR ICT systems and projects.
- Maintain and oversee the Security Risk Register, including approved waivers, risk acceptances, exceptions, and corrective action plans.
- Ensure cybersecurity risks are appropriately assessed, mitigated, monitored, and reported.
- Facilitate risk acceptance decisions by business stakeholders and the IDSC in accordance with MTI and A*STAR's risk appetite and tolerance levels.
- Provide regular reporting and recommendations to senior management on cybersecurity risks and emerging threats.
Requirements
- Degree in Information Security, Cybersecurity, Computer Science, Information Systems, or a related discipline.
- At least 15-20 years of experience in information security, cybersecurity, risk management, or ICT governance, including leadership roles.
- Strong knowledge of cybersecurity governance, risk management, security operations, audit, compliance, and industry frameworks.
- Proven ability to engage senior stakeholders and lead enterprise-wide cybersecurity initiatives.
All new hires are appointed on a 3-year renewable contract in the first instance.