Job Description
Job Title:  Chief Information Security Officer (CISO)
Requisition ID:  3361
Posting Start Date:  05/10/2026

Job Summary

The Chief Information Security Officer (CISO) is responsible for providing strategic leadership, governance, and oversight of A*STAR's cybersecurity programme to safeguard its information assets, systems, and services. The CISO shall collaborate closely with the Chief Information Officer (CIO), A*STAR, to ensure that day-to-day ICT security operations, initiatives, and projects are aligned, non-duplicative, and compliant with prevailing cybersecurity policies, standards, and regulatory requirements.

Key Responsibilities

  1. Cybersecurity Strategy
    • Formulate and maintain A*STAR's cybersecurity strategy, roadmap, and work plan.
    • Ensure alignment of A*STAR's cybersecurity objectives with the Ministry of Trade and Industry (MTI) Family cybersecurity strategy and the directions of the Information and Digital Security Committee (IDSC).
    • Lead cybersecurity planning and prioritisation to support A*STAR's organisational goals and risk management objectives.
    • Ensure adequate cybersecurity resources, capabilities, and competencies are in place to meet strategic and operational requirements.
  2. Cybersecurity Maturity and Gap Analysis
    • Conduct periodic cybersecurity maturity and gap assessments across A*STAR.
    • Evaluate cybersecurity posture against the MTI Family Cybersecurity Maturity Model (CMM) and other relevant industry maturity frameworks.
    • Identify areas for improvement and drive remediation plans to enhance organisational cybersecurity resilience.
  3. Security Governance
    • Establish and maintain effective cybersecurity governance across A*STAR, including oversight of all A*STAR Research Institutes (RIs).
    • Ensure compliance with MTI Family cybersecurity requirements, A*STAR policies, and applicable regulatory obligations.
    • Develop, monitor, and report cybersecurity metrics and key performance indicators to MTI, A*STAR Senior Management, and the IDSC.
    • Implement and oversee cybersecurity risk and control programmes to maintain and improve A*STAR's security posture.
    • Oversee cybersecurity audits, assessments, reviews, and compliance activities across A*STAR's ICT systems.

 

    • Maintain enterprise-wide visibility and oversight of cybersecurity matters relating to ICT systems, applications, products, and services across intranet, internet, and extranet environments.
  1. Policy, Standards and Compliance
    • Develop, implement, and maintain A*STAR's cybersecurity policies, standards, and guidelines.
    • Ensure alignment with MTI's ICT Security Policy Baseline and relevant industry standards, frameworks, and best practices.
    • Drive organisation-wide awareness, adoption, and compliance with cybersecurity policies and standards.
  2. Cybersecurity Risk Management
    • Establish policies, standards, and processes governing cybersecurity risk assessments for all A*STAR ICT systems and projects.
    • Maintain and oversee the Security Risk Register, including approved waivers, risk acceptances, exceptions, and corrective action plans.
    • Ensure cybersecurity risks are appropriately assessed, mitigated, monitored, and reported.
    • Facilitate risk acceptance decisions by business stakeholders and the IDSC in accordance with MTI and A*STAR's risk appetite and tolerance levels.
    • Provide regular reporting and recommendations to senior management on cybersecurity risks and emerging threats.

 

Requirements

  • Degree in Information Security, Cybersecurity, Computer Science, Information Systems, or a related discipline.
  • At least 15-20 years of experience in information security, cybersecurity, risk management, or ICT governance, including leadership roles.
  • Strong knowledge of cybersecurity governance, risk management, security operations, audit, compliance, and industry frameworks.
  • Proven ability to engage senior stakeholders and lead enterprise-wide cybersecurity initiatives.

 

All new hires are appointed on a 3-year renewable contract in the first instance. 

 

The above eligibility criteria are not exhaustive. A*STAR may include additional selection criteria based on its prevailing recruitment policies. These policies may be amended from time to time without notice. We regret that only shortlisted candidates will be notified.