Free with a WorkJio account: we compare your profile with this job and show what you already meet.
Share with a friend
Start
Not stated
Work mode
On-site
Experience
Experienced
About the role
This senior architecture role sits within Dyson's cybersecurity team at the Singapore Technology Centre, covering the digital application landscape such as eCommerce, customer experiences, mobile apps, APIs and cloud-native services. You will act as the senior authority for application security and DevSecOps, shaping reusable architectures and guardrails while working closely with engineering and product teams. It suits an experienced application security architect comfortable operating at both strategic and hands-on technical depth.
What you'll do
Set the application security and DevSecOps architecture direction, turning risk appetite and policy into target architectures, principles, standards, patterns and control objectives.
Principal Cyber Security Architect (Application Security) job at Dyson, Singapore | WorkJio
Give authoritative security advice across web, mobile, API, microservices, serverless and cloud-native architectures, balancing security, resilience, customer experience, delivery speed and cost.
Lead security architecture reviews and risk assessments from discovery through design, build, release and operation, recording decisions, risks, controls, exceptions and residual risk in an audit-defensible way.
Facilitate threat modelling using techniques such as STRIDE, attack trees, abuse cases and data-flow analysis, and ensure threats become owned engineering requirements with verified mitigations.
Design and govern reusable security patterns for identity and access, session management, API protection, secrets, encryption, key and certificate use, tenant isolation, input and output handling, logging, monitoring and secure failure modes.
Define the DevSecOps control framework and reference pipeline, including policy-as-code, security quality gates, risk-based thresholds, exception workflows, evidence capture and CI/CD feedback loops.
Guide integration and effective use of security testing capabilities such as SAST, DAST, software composition analysis, secrets scanning, infrastructure-as-code scanning, container and image scanning, API security testing, mobile testing and penetration testing.
Strengthen software supply-chain security by defining expectations for dependency governance, software bills of materials, provenance and integrity, artifact signing, trusted build environments and third-party component risk.
Partner with engineering enablement and platform teams to create secure-by-default paved roads, templates and reusable controls that reduce friction and prevent recurring vulnerabilities.
Establish vulnerability triage and remediation models covering severity, exploitability, business context, ownership, service-level expectations, risk acceptance and verification of closure.
Develop application security metrics and capability measures covering control coverage, effectiveness, engineering adoption, security debt, remediation performance and recurring defect patterns, using evidence to prioritise improvement.
Build capability through security champions, role-based training, coaching, communiti
Requirements
Extensive experience in application security, security architecture or secure software engineering, with ownership of complex enterprise-scale outcomes
Strong knowledge of secure software design and the software development lifecycle across web, mobile, API, microservices and cloud-native services
Practical experience designing or maturing DevSecOps capabilities and integrating security controls into modern CI/CD platforms and developer workflows
Deep understanding of common application and API threats, including the OWASP Top 10 and OWASP API Security Top 10, and ability to translate weaknesses into design and engineering controls
Hands-on understanding of SAST, DAST, software composition analysis, secrets scanning, infrastructure-as-code scanning, container and image scanning and security test automation, including tuning, coverage, false-positive management and quality gates
Strong threat-modelling and security-risk-assessment skills, including modelling trust boundaries, data flows, abuse paths and compensating controls
Benefits
Opportunity to work with innovative technologies such as artificial intelligence and machine learning
Chance to develop skills and knowledge while collaborating with a team of cybersecurity experts
Apply on the company website
You will leave WorkJio. Never pay a fee or share your Singpass password, OTP or bank log-ins to apply.