Associate Principal Cyber Security Architect (Data)
Singapore · Full Time
Be the first to apply
- Experience
- Any
- Salary
- —
- Openings
- 1
- Posted
- 4 days ago
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About Dyson and the Role
Dyson is pioneering advancements not only in innovative technology-enabled products but also in cybersecurity, addressing the dynamic challenges posed by an increasingly interconnected product ecosystem. Our proactive cybersecurity strategy leverages cutting-edge technologies such as artificial intelligence and machine learning to safeguard products and customers against evolving threats.
As an Associate Principal Cybersecurity Architect focusing on Data, you will spearhead Dyson's data security architecture, concentrating on Data Loss Prevention (DLP), data discovery, classification, and protection across various environments including endpoints, collaboration tools, cloud platforms, and databases. You will transform business, legal, privacy, and security mandates into a comprehensive architecture that ensures sensitive data remains secure throughout its lifecycle while maintaining practical usability for employees and engineers.
Key Responsibilities
- Establish and steer the strategic direction, principles, and multi-year roadmap for data classification, DLP, and protective measures at enterprise scale.
- Define enterprise-wide data classification and handling frameworks covering classification levels, labeling, metadata management, ownership responsibilities, approved usage policies, retention criteria, and integration with enforcement technologies.
- Architect solutions for discovering and classifying structured and unstructured data across endpoints, file systems, collaboration platforms, email, SaaS, cloud storage, databases, and data platforms.
- Design risk-based DLP controls spanning endpoints, email, web, cloud, and collaboration channels with features including detection parameters, contextual policies, user interaction prompts, blocking, quarantine, encryption, alerts, and exception protocols.
- Implement controls for data at rest, in use, and in motion, addressing authorized sharing methods, downloads, printing, clipboard actions, removable media usage, browser uploads, application transfers, and external collaboration.
- Create guidelines for encryption, key management, tokenization, masking, rights management, access controls, and secure data sharing aligned with data sensitivity and business context.
- Lead security architecture assessments and risk evaluations for initiatives involving sensitive data, ensuring thorough documentation of decisions, control mandates, exceptions, and residual risks aligned to audit standards.
- Collaborate with stakeholders in data ownership, governance, privacy, legal, HR, insider risk, cyber operations, and technology to define clear roles and proportionate enforcement procedures.
- Develop integration strategies for DLP and classification telemetry within monitoring, investigation, and incident response workflows, ensuring proper context, evidence handling, access controls, and escalation mechanisms.
- Produce and govern reusable security patterns for Microsoft 365, endpoints, SaaS, cloud infrastructure, data lakes, analytics, databases, and AI applications.
- Define requirements for Data Security Posture Management and enhance data visibility including discovery of sensitive stores, exposure assessments, access reviews, risky sharing detection, and enforcement gap analysis.
- Manage policy lifecycle governance encompassing design, simulation, testing, deployment, tuning, false positive management, change controls, exceptions, periodic evaluation, and retirement criteria.
- Guide technical teams and vendors through design, implementation, and operational transitions to ensure scalability, maintainability, privacy compliance, and conformity to architecture standards.
- Develop metrics and evidence to measure data discovery coverage, classification adoption, DLP effectiveness, policy accuracy, alert management, exception aging, remediation efforts, and overall reduction of data-related risks.
- Enhance organizational capabilities by authoring standards, reference architectures, playbooks, role-based guidance, and mentoring architects, engineers, data owners, and operational staff.
Candidate Profile
- Proven track record in security architecture or information protection with experience delivering at a complex enterprise scale.
- Expertise in Data Loss Prevention architecture encompassing endpoint, email, web, cloud, and collaboration, including policy lifecycle from design to operational integration.
- Comprehensive knowledge of data discovery, classification, and labeling techniques for both structured and unstructured data using metadata management, exact data matching, document fingerprinting, classifiers, and contextual analysis.
- Proficiency in translating complex legal, regulatory, privacy, and business requirements into actionable data classification taxonomies and technical controls.
- In-depth understanding of comprehensive data lifecycle risks covering creation, collection, storage, processing, analytics, sharing, archival, and secure disposal.
- Experience designing and implementing data protection techniques including encryption, rights management, key management, tokenization, masking, access control, and secure collaboration.
- Skilled in analyzing data flows, trust boundaries, identities, entitlements, storage locations, third-party relationships, and cross-border data transfers to inform architectural decisions.
- Familiarity with cloud, SaaS, endpoint, and collaboration platforms ensuring consistent control application across hybrid and multi-platform systems.
- Knowledge of Data Security Posture Management, data inventories, exposure points, over-permissioning, and sensitive-data exposure paths.
- Ability to integrate data security controls with SIEM, case management, incident response, and insider risk workflows, while maintaining privacy and segregation of duties.
- Strong experience developing reference architectures, standards, design patterns, technical specifications, and risk documentation for varied audiences.
- Competence in evaluating security tools and vendors based on requirements, proofs-of-value, architecture fit, integration, operational sustainability, and quantifiable outcomes.
- Exceptional communication, facilitation, and influence skills to align security, data, legal, privacy, HR, and technology stakeholders around effective decisions.
- Capacity to lead by influence, mentor colleagues, and coordinate virtual teams and external partners independently.
- Hands-on experience with enterprise information protection and DLP platforms such as Microsoft Purview, FortiDLP, Netskope, or similar technologies.
- Experience in securing critical intellectual property, engineering assets, customer and employee data, and regulated datasets.
- Knowledge of database and data platform protections including monitoring, fine-grained access, masking, tokenization, and sensitive data discovery.
- Understanding of privacy engineering, record management, data retention, eDiscovery, and insider risk and how these intersect with security architecture.
- Expertise designing data controls for analytics, machine learning, and generative AI, including management of training data, prompts, outputs, retrieval, and model access boundaries.
- Certifications such as CISSP, ISSAP, CCSP, CISM, Microsoft security credentials, or privacy and data governance certifications are helpful though proven practical skill remains paramount.
Equality and Inclusion
Dyson is committed to equal employment opportunities, embracing diversity across all dimensions including race, color, religion, nationality, gender, sexual orientation, age, disability, veteran status, and more.