Free with a WorkJio account: we compare your profile with this job and show what you already meet.
Share with a friend
Start
Not stated
Work mode
On-site
Experience
Experienced
About the role
This role owns the cybersecurity architecture for a platform and managed service portfolio, aligning it with the product and technology roadmap. You will work with product owners, engineering, SOC, operations and other architects to design secure, reusable managed security offerings. It suits an experienced architect who can translate security policy into practical designs and guide teams across multiple concurrent initiatives.
What you'll do
Own and maintain current-state, transition-state and target-state cybersecurity architecture for the platform and managed services.
Design reusable, productised managed security offerings such as centrally managed firewall services, covering multi-tenancy, tenant segregation, policy and change lifecycle, high availability, disaster recovery, secure onboarding, telemetry, auditability and customer reporting.
Platform Cybersecurity Enterprise Architect job at StarHub, Singapore | WorkJio
Ensure managed Wi-Fi, LAN, SD-WAN, cloud, infrastructure and related services are designed with security by default and consistent controls.
Define and maintain platform guardrails, reference architectures, approved design patterns, technical standards and control baselines across network, identity, cloud, application and API, data, encryption, key and secrets management, endpoint and platform engineering.
Partner with the CISO and cybersecurity governance teams to turn policies, regulatory obligations and risk requirements into implementable architecture and control requirements, and provide technical impact assessments and remediation options.
Lead architecture review, design assurance and threat-modelling activities across the platform lifecycle from concept and build through release, customer onboarding, operation and technology refresh.
Work with product owners, the platform architect, engineering, SOC, operations, service delivery, ITSM and other domain architects to prioritise security capabilities and keep implementation aligned with approved architecture.
Define non-functional requirements and acceptance criteria covering security, availability, scalability, performance, resilience, recoverability, maintainability, observability, supportability and cost efficiency.
Architect secure automation and orchestration capabilities including infrastructure as code, CI/CD, configuration and policy as code, automated compliance checks, standardised service provisioning and controlled customer changes.
Ensure platform and service telemetry supports operations and security monitoring, including logging of permitted, blocked, failed, administrative and policy-change activities, with integration into observability, SIEM/SOC, ITSM/CMDB and customer reporting.
Evaluate technologies, products, vendors and cloud services; lead technical assessments and proof-of-concept activities; and maintain technology standards, lifecycle roadmaps, end-of-life plans and technical debt priorities.
Govern standard platform boundaries and assess customer-specific deviations for feasibility, security impact
Requirements
Degree in Information Technology, Computer Science, Engineering, Cybersecurity or a related field
At least 10 years of relevant experience, including significant enterprise, security or platform architecture experience
Proven experience designing multi-tenant, centrally managed platforms or managed security services at scale
Strong end-to-end technical and architectural knowledge across networking, cybersecurity, cloud, platform engineering, service management and observability
Familiarity with firewalls, IPS/IDS, SASE/ZTNA, SD-WAN, NAC, wireless security, WAF, DDoS protection, NDR, EDR/XDR/MDR, SIEM, SOAR, IAM/PAM, PKI, key and secrets management, public and private cloud, and container platforms
Strong understanding of Zero Trust, defence in depth, tenant isolation, secure APIs, encryption, threat modelling, vulnerability and configuration management, secure software development and security-by-design principles
Apply on the company website
You will leave WorkJio. Never pay a fee or share your Singpass password, OTP or bank log-ins to apply.