Deputy Director - IT Risk & Control (CIO)
Date: 2 Oct 2026
Location: SG
Company: Synapxe
Position Overview
The is the first line of defence lead for ICT systems that are managed and operated by one of the healthcare cluster. The role is accountable for translating approved cybersecurity policies and standards into day-to-day operational controls for these systems, including their applications, supporting infrastructure, cloud services, connected devices, interfaces and third-party services.
We are offering a 2 years Direct Contract for this position.
Role & Responsibilities
First-Line Security Planning and Accountability
- Formulate and execute the ICT security work plan for our managed systems in alignment with approved cybersecurity strategy, policies, standards and risk appetite.
- Maintain clear first-line accountability for the security design, implementation and operation of controls within the our managed systems portfolio.
- Translate policy requirements into actionable control plans, operating procedures, technical baselines and delivery priorities for our managed systems.
- Secure and deploy the resources, capabilities and services required to achieve agreed security outcomes for the portfolio.
- Report the portfolio’s operational security performance, material exposures and delivery constraints to management and the second-line cybersecurity risk function.
Operational Cyber Risk and Control Management
- Identify, assess, document and manage cybersecurity risks arising from systems, projects, operations, changes and related third-party services.
- Own and maintain first-line risk and control registers for the portfolio, including emerging risks, control deficiencies, findings and treatment plans.
- Implement and monitor preventive, detective, corrective and recovery controls for systems in accordance with approved requirements.
- Evaluate policy deviations affecting the portfolio, determine residual risk and mitigating measures, and prepare submissions for the appropriate system owner, risk owner and governance forum.
- Drive remediation of vulnerabilities, audit findings, security review findings and control weaknesses within agreed timelines.
- Collate accurate portfolio security metrics and evidence, review control performance regularly, and escalate risks that exceed approved tolerance or cannot be treated within plan.
Security Engineering, Delivery and Control Implementation
- Embed security-by-design and privacy-by-design controls into projects, procurements, changes and technology lifecycles for systems.
- Translate approved security requirements into solution designs, technical controls, configuration standards and operational acceptance criteria for the portfolio.
- Ensure project and operations teams conduct required risk assessments, architecture reviews, vulnerability assessments, penetration tests, configuration reviews and code assurance activities.
- Review and validate that findings are risk-rated, assigned, remediated or mitigated before go-live and throughout each system’s lifecycle.
- Implement and maintain controls for identity and access management, privileged access, encryption, logging, patching, endpoint protection, data loss prevention, backup and secure configuration within the portfolio.
- Maintain implementation evidence and support technical verification by the second-line cybersecurity function.
Requirements
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Engineering or a related discipline.
- At least 10 years of relevant experience in cybersecurity, security engineering, application security, IT operations or technology risk, including leadership of operational security functions in a large and highly regulated environment.
- Demonstrated experience implementing and operating security controls, managing vulnerabilities, leading incident response, conducting cyber risk assessments and driving remediation for an enterprise application portfolio.
- Strong working knowledge of recognised cybersecurity frameworks and practices, including NIST Cybersecurity Framework, ISO/IEC 27001, security-by-design, defence-in-depth and the three lines model.
- Experience securing entity-managed or internally managed enterprise applications, supporting infrastructure, cloud services, interfaces and third-party services will be advantageous.
- Experience in healthcare, public sector or other high-availability environments will be advantageous.
- Proven ability to direct multidisciplinary operational teams, manage vendors and translate policy and risk requirements into effective technical and process controls.
Apply Now
NOTE: It only takes a few minutes to apply for a meaningful career in HealthTech - GO FOR IT!!