VP - Security by Design Architect, Technology Risk
Responsible for incorporating security measures into the architecture of the client’s systems and applications from the initial design phase. This role involves ensuring that security is a foundational element, rather than an afterthought, in the development and implementation of IT systems.
Responsibilities:
Threat Modelling:
- Identifying potential security threats and vulnerabilities early in the design process.
- Evaluate existing system security postures and recommend enhancements
Security Requirements:
- Defining and integrating security requirements into the system's architecture.
- End-to-end accountability of the overall security design of financial services projects.
- Collaborate with project teams to ensure that security requirements are considered and assessed.
Best Practices:
- Ensuring adherence to security best practices and standards throughout the development lifecycle.
- Test and verify that the security requirements are properly implemented.
- Provide expert guidance and support to development teams on secure coding practices, security testing, and vulnerability management.
Risk Management:
- Assessing and mitigating risks associated with the system's design.
Collaboration:
- Working with development, operations, and other teams to ensure security is integrated across all stages.
Compliance:
- Ensuring that the system complies with relevant regulations and industry standards.
By focusing on security from the beginning, the Security by Design Architect helps create systems that are inherently more secure and resilient against potential threats.
Requirements:
- Degree in Computer Science, Computer Engineering or Information Security related fields.
- 5+ years’ experience in security engineering, with deep expertise in one or more security domains.
- Broad appreciation of overall security architecture and how various security technologies interact to achieve overall security defence.
- Familiarity with security engineering and design principles across applications, databases, infrastructure and network
- At least 3 years’ experience in Application Security.
- CISSP, CISM, CCSP, CISA, or AWS Certified Security
- Experience in Cloud Security is a must.
- Familiarity with MAS TRM, PCI DSS and PCI PTS is a must.
- Familiarity with DevSecOps and Shift-Left security principles.
- On top of developments in cyber threats and advances in security protection
Compensation:
- Competitive salary
- Excellent benefits
Apply now to be considered for this excellent opportunity.
SLOANE SHOREY
Compliance | Risk | Resilience
Sloane Shorey Consulting is a recruitment firm specialising in compliance, risk, and resilience across Asia and the Middle East. Since 2017, we have partnered with banking and financial services companies, multinational and local corporations, and consulting firms on hiring.
Sloane Shorey is a Ministry of Manpower Licensed Employment Agency: EA License 20S0307