Principal Cyber Security Architect - Application Security
Singapore · Full Time
Be the first to apply
- Experience
- Any
- Salary
- —
- Openings
- 1
- Posted
- 6 days ago
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About Dyson and the Role
Dyson is pioneering advanced technology-driven products with a strong focus on cybersecurity. With increasingly sophisticated and interconnected products, Dyson anticipates emerging cyber threats and combats them through innovative security solutions. Joining Dyson’s cybersecurity team offers the chance to work with cutting-edge technologies like artificial intelligence and machine learning to safeguard products and users.
As the Principal Cybersecurity Architect focused on Application Security and DevSecOps, you will shape the security architecture across Dyson’s digital applications including eCommerce, mobile apps, APIs, and cloud-native services. Your role involves defining reusable security frameworks, building scalable DevSecOps capabilities, and collaborating with engineering teams to embed consistent security measures in software development. This leadership position ensures security controls are practical, effective, and aligned with risk governance.
Key Responsibilities
- Define strategic security architecture for applications and DevSecOps, converting company risk policies into tangible standards, patterns, and controls.
- Advise on security for web, mobile, API, microservices, serverless, and cloud-native systems balancing security with usability and delivery speed.
- Lead comprehensive security architecture reviews and risk assessments during all development phases, documenting decisions and residual risks for audit compliance.
- Conduct threat modelling using methodologies like STRIDE, attack trees, and data flow analysis, ensuring mitigation measures become actionable engineering tasks.
- Develop and maintain reusable security patterns covering identity, access, session management, encryption, logging, and other key controls.
- Establish a DevSecOps framework with policy-as-code, quality gates in CI/CD pipelines, risk thresholds, and evidence tracking.
- Oversee integration of security testing tools including SAST, DAST, composition analysis, secrets & infrastructure scanning, container/image scanning, API and mobile security tests, and penetration testing.
- Enhance software supply chain security focusing on dependency governance, software bills of materials, artifact signing, and trusted build environments.
- Partner with platform teams to build secure-by-default templates and controls that facilitate secure development workflows.
- Create vulnerability triage and remediation processes prioritizing severity, exploitability, business impact, and ownership with clear SLAs.
- Develop metrics for application security effectiveness, adoption levels, remediation speed, and recurring issues to guide improvements.
- Build security capability via champions, training, coaching, communities of practice, and guidance for architects, developers, testers, and product teams.
- Work closely with Cyber Security, Risk, Digital, Engineering and Technology teams offering technical leadership and ensuring quality delivery and operational transition.
- Support resolution of major security incidents and continuously improve security practices based on lessons learned.
Candidate Profile
- Proven, extensive experience in application security architecture or secure software engineering managing complex enterprise-scale projects.
- Strong understanding of secure design and software development lifecycles for web, mobile, API, microservices, and cloud-native services.
- Practical knowledge in designing or advancing DevSecOps capabilities embedded in modern CI/CD and developer tools.
- Deep familiarity with common application and API vulnerabilities including OWASP Top 10 and ability to map threats to engineering solutions.
- Experienced in security testing technologies such as SAST, DAST, software composition analysis, secrets scanning, infrastructure-as-code and container scanning with quality gate expertise.
- Skilled in threat modelling and risk assessment, including trust boundaries, dataflows, abuse cases and compensating controls.
- Expertise with identity protocols (OAuth 2.0, OpenID Connect, SAML) and security controls like session management and cryptographic key handling.
- Knowledgeable in cloud and container security across major platforms, including Kubernetes, serverless, API gateways, service mesh, and infrastructure as code security.
- Understanding of software supply-chain security aspects such as dependency governance, SBOMs, artifact signing, provenance, build pipeline security and third-party risk.
- Ability to review and challenge code, pipeline definitions and configuration; proficient in at least one programming language such as Python, Java, JavaScript/TypeScript, C# or Go and familiar with REST or GraphQL, JSON and YAML scripting for automation.
- Experienced in producing clear security architecture documentation, requirements, standards, risk decisions understandable by engineers and governance bodies.
- Strong communication and influencing skills capable of explaining security risk, trade-offs and rationale to both technical teams and senior leadership.
- Self-driven with leadership skills to influence teams and manage multidisciplinary internal and external collaboration.
- Experience in establishing security champions, developer training programs and product security communities of practice.
- Working knowledge of web application and API protection technologies such as WAFs, bot management, rate limiting and virtual patching aligned with remediation focus.
- Capability in defining control evidences and metrics required for regulated or audit-sensitive environments.
- Understanding of mobile application security testing and secure mobile design guided by OWASP mobile standards.
- Professional certifications (e.g. ISC2 CSSLP, CISSP, GIAC secure software, cloud security) are advantageous but not mandatory.
Equal Opportunity Employer
Dyson values diversity and welcomes applications from candidates of all backgrounds. Hiring decisions are made without discrimination based on race, color, religion, nationality, gender identity, age, disability, or any other diversity factor.