Singlife is a leading homegrown financial services company, offering consumers a better way to financial freedom. Through innovative, technology-enabled solutions and a wide range of products and services, Singlife provides consumers coantrol over their financial wellbeing at every stage of their lives.
In addition to a comprehensive suite of insurance plans, employee benefits, partnerships with financial adviser channels and bancassurance, Singlife offers investment and advisory solutions through its GROW with Singlife platform. It also offers the Singlife Account, a mobile-first insurance savings plan.
Singlife is the exclusive insurance provider for the Ministry of Defence, Ministry of Home Affairs and Public Officers Group Insurance Scheme. Singlife is also an official signatory of the United Nations Principles for Sustainable Insurance and the United Nations-supported Principles for Responsible Investment, affirming its commitment to finding a better way to sustainability.
The merger of Aviva Singapore and Singlife was announced in September 2020 and created one of the largest homegrown financial services companies in Singapore in a deal valued at S$3.2 billion. It was the largest insurance deal in Singapore at the time. Singlife was subsequently acquired by Sumitomo Life in March 2024, one of Japan’s leading life insurers, which valued Singlife at S$4.6 billion, making the transaction one of the largest insurance deals in Southeast Asia.
Key Responsibilities
Data Security
- Design and oversee data security controls including encryption, key management, data loss prevention (DLP), data classification, and access governance to protect sensitive and customer data across on-premises and cloud environments.
- Conduct meticulous and comprehensive technical assessments of data security controls, leaving no stone unturned in identifying critical gaps and providing strategic, risk-based remediation recommendations.
- Identify and report significant data security issues and gaps, providing technical-level recommendations for risk mitigation aligned to regulatory expectations such as MAS TRM and PDPA.
Application Security
- Act as the subject matter expert across the application development lifecycle, performing technical information security risk assessments on business applications throughout SDLC, Agile, and DevSecOps methodologies.
- Provide expert advice in assessing security requirements and controls—including secure coding, API security, and vulnerability management—and drive strategic planning and implementation of controls to strengthen application development lifecycle security.
Security Architecture
- Develop and maintain security reference architectures and design patterns—informed by industry frameworks such as SABSA and TOGAF—for data, application, network, and cloud domains, driving consistent adoption as enterprise standards and reusable building blocks.
- Conduct security architecture reviews across enterprise-wide projects, identifying design gaps and driving recommendations to close them, while advocating for security best practices in alignment with relevant regulations and frameworks (e.g., MAS TRM, ISO 27001, NIST CSF).
- Provide independent, expert assessment and advisory on all data security, application security, and security architecture matters—serving as the trusted technical reference point for these domains within the organisation.
Strategic Stakeholder Engagement and Collaboration
- Collaborate with domain architects, project managers, and IT subject matter experts to foster a collective security culture.
- Raise awareness of the organization's information security policies, standards, and best practices among stakeholders.
- Interface with Risk, Internal Audit, External Audit, and regulatory bodies during audits to provide support and facilitate smooth audit processes.
- Ensure stakeholders understand their strategic roles and responsibilities concerning information security, fostering a culture of accountability.
Experience
- Minimum of 6 years of progressive experience in Information Security, with a strong focus on data security, application security, and security architecture. Experience in financial services or similarly regulated industries is preferred.
- Strong command of data and application security controls—encryption, key management, DLP, access management, and vulnerability management (OWASP, SANS).
- Hands-on experience embedding security into SDLC, Agile, and DevSecOps pipelines, with expertise in API and cloud security (AWS/Azure).
- Working knowledge of security architecture and regulatory frameworks—SABSA, TOGAF, ISO 27001, NIST CSF, MITRE ATT&CK, MAS TRM, and PDPA.
- Strong communication and stakeholder influence skills, with a track record of driving initiatives independently as a senior SME.
Education
- University degree in Information Security, Computer Science, Engineering, or a related field. Advanced degrees and relevant certifications are preferred.
- Certification
- Relevant Information Security Industry qualifications / certifications such as CISSP, CISM, CISA, relevant SANS certifications, Cloud certifications (AWS/Azure), or equivalent industry-recognized qualifications are mandatory.