About the job
Assurity Trusted Solutions (ATS), a proud subsidiary of the Government Technology Agency (GovTech), stands as a beacon of trust in the digital sphere. For over a decade, ATS has provided a robust array of products and services, including infrastructure and operational services, authentication solutions, governance, assurance services, and managed processes. In an ever-evolving digital and cyber landscape, where trust and collaboration are paramount, ATS strives to foster beneficial outcomes through its partnership with GovTech, government agencies, and commercial partners, effectively mitigating cyber risks and enhancing security measures.
Key Responsibilities:
Audit Planning & Program Development
- Design tailored audit programs and security checklists to evaluate internal controls for IT risks, focusing on data privacy, IM8 compliance, and cutting-edge technologies such as cloud services and AI.
- Plan comprehensive annual audits and technical assessments of critical systems and infrastructure, employing risk-based methodologies and continuous monitoring techniques.
- Supervise outsourced audit resources and specialist expertise to ensure high-quality audit deliverables.
Audit Execution & Fieldwork
- Conduct extensive ICT&SS audits for agencies designated by the Central Digital Assurance (CDA), emphasizing data security and privacy controls, security frameworks, and hybrid cloud environments.
- Perform detailed audits of government systems classified up to Secret, assessing the handling of sensitive personal data, AI governance, and the application of zero trust architecture.
- Manage relationships with agencies throughout the audit lifecycle, from initial briefings to fieldwork execution, ensuring timely delivery through effective stakeholder engagement.
Risk Assessment & Strategic Analysis
- Assess the maturity of agencies' ICT governance and risk posture, particularly in relation to data privacy compliance, security controls, third-party risks, and cyber resilience against emerging threats including AI governance.
- Develop strategic mitigation plans to enhance ICT governance, data privacy frameworks, and the implementation of privacy-by-design across government systems.
Follow-up & Continuous Monitoring
- Conduct follow-up audits and validate remediation efforts to guarantee effective control implementation and root cause resolution.
- Maintain a central repository for audit findings and monitor remediation progress through analytics to support continuous improvement initiatives.

