[What you will be working on]
Some problems are easy to walk past. Others keep nagging at you.
Why are we still doing this manually?
Why does sensible policy become painful when it meets the real world?
Why do we discover risks after the fact when the signals were already there?
How should government govern AI systems that increasingly make decisions and take actions for themselves? And why, when technology can change in minutes, does governance sometimes still move in months?
If questions like these bother you enough that you want to get underneath them, experiment with better answers and solve the real-world problem, we should talk.
We are rethinking what modern governance, risk and assurance could look like across GovTech and, ultimately, the wider Singapore Government.
GovTech is where we can design, build, test and learn. The ambition is bigger.
We are modernising Governance, Risk, and Compliance (GRC) so government can use technology and AI with greater confidence, improve services faster, and keep the essential systems people rely on dependable and resilient.
Ultimately, the test is bigger than GRC: Can government use technology better, serve citizens better, and retain their trust when things go wrong?
That is the problem behind this role. And we do not expect to solve it by designing the perfect framework in a room.
We expect to work on real systems, with real users and real constraints. To experiment. Test assumptions. Prototype, understand behavior and incentives. Learn from what does not work.
And turn what does into something that can work at government scale. One role. Multiple archetypes. This is one modern GRC role, not six separate jobs or six career tracks.
The six archetypes below describe different capabilities a Modern GRC Practitioner can develop and create a problem.
You might begin with strength in one. Over time, you can acquire additional archetypes without giving up the ones you already have. An engineer might combine GRC Platform Engineering with Policy Engineering and AI Governance. An assurance practitioner might bring together Threat-Informed Risk Intelligence, Enterprise Risk Management and Systems Architecture. A policy practitioner might combine Policy Engineering with behavioral insights, systems thinking and platform capability.
Which archetypes you draw on depends on the problem. Some practitioners will build deep expertise in one or two. Others will develop a broader combination across several. Neither is a prescribed progression. The archetypes are not boxes to move between. They are capabilities you can accumulate, combine and apply. The ambition is to build practitioners with an increasingly powerful repertoire for understanding and solving difficult problems. Six capabilities you could build and combine.
Make policy work in the real world
How do we design policy that survives contact with engineers, users and actual organisational behavior?
Bring together domain expertise, behavioral insights, human-centered design and technology to create controls that people can understand, systems can implement and organisations can actually operate.
A technically correct policy that everyone works around is not a successful policy.
Turn uncertainty into decisions
Enterprise Risk Management
How do we help leaders decide which risks matter, what needs intervention and what we can deliberately live with? Connect signals across the organisation, expose dependencies and concentration risks, translate risk appetite into practical choices and bring better analysis to difficult decisions.
The output is not another register. It is a better decision.
Build assurance into the technology
How do we make governance and assurance part of the delivery environment rather than another checkpoint around it? Build Policy-as-Code, automated evidence, continuous control verification and other infrastructure that makes safer behavior easier and assurance more timely.
Sometimes the answer is automation. Sometimes the smarter answer is removing the process first.
Govern systems that increasingly act for themselves
What can an AI agent decide? Where must humans intervene? How should decision boundaries, accountability and assurance work when autonomous systems act at scale?
How do we govern model drift, changing behavior and GRC’s own use of AI? Some answers exist. Many do not. You could help develop them.
Find the signal before it becomes the incident
Threat-Informed Risk Intelligence
How do we understand what is changing now rather than explain months later what went wrong? Connect cyber, data, resilience, platform, supply-chain and operational signals to identify patterns and emerging risks earlier.
Less: “Did the control pass?” More: “Is it working now, what changed, and what does that tell us?”
See the system everyone else sees in pieces
How do policy, risk, controls, evidence, engineering and assurance fit together?
Design the taxonomies, information flows, feedback loops and operating models that allow them to work as one system. Ask some people about one control and they will explain the other three things it affects.