
Senior Security Architect
- Kuala Lumpur
- Permanent
- Full-time
- Design and implement secure architectures and control across networks, applications, cloud environments, and data systems.
- Develop security blueprints, reference architectures, and design patterns aligned with industry standards
- Define and apply security requirements and controls across different security domains, especially Cloud and AI Security during the Application blueprinting and design review.
- Act as the subject matter expert for security architecture and provide technical guidance to project teams, solution architects, developers and business users.
- Research and evaluate security tools, technologies, and frameworks to enhance the organization’s security posture.
- Perform security risk assessment on emerging technologies and provide recommendations.
- Liaise with internal and external auditors and regulators to support Prudential businesses.
- Understand business requirement and security risk to business during the security assessment and consultation.
- Understand the company and business direction from products/solutions/market/technology in the Cloud domain
- Participate in POV/POC of selected security solutions and provide insights on suitability.
- Bachelor’s degree in Information Security/ Information Technology/ Computer Science or equivalent work experience.
- At least 12 years of experience in large organization with a focus on IT security and adoption of cloud technologies.
- Experience with architecture and security reviews, threat modeling applications and identifying areas of risk.
- Demonstrated experience in applying security and risk frameworks such as: NIST, Mitre ATT&CK, Mitre DEFEND, ISO27K
- Demonstrated experience in applying technical solutions to meet regulatory requirements stipulated by regional authorities (MAS, HKMA, BNM…)
- Ability to articulate cyber risks to senior leadership within the context of corporate strategy and threat environment
- Familiarity with secure development practices (DevSecOps) related toolset and automation CI/CID tools.
- Hands-on experience on conducting evaluation, design, implementation and optimization of a comprehensive and broad set of security technologies and processes. (Application Security, data protection, key management, identity, and access management (IAM), network security and security monitoring).
- Proficient in coding/scripting languages such as Python, Bash or Powershell.
- Possess in-depth technical knowledge in containerization technologies and cloud native applications.
- Pro-active with multitasking capabilities, comfortable to work in both hands-on and leadership role.
- High level of personal integrity, as well as the ability to professionally handle confidential matters.
- Cloud native certification such as CKA, CKS
- ISSP, CCSP or equivalent certification preferred.
- OSCP, OSWE, GIAC GWAPT, GPEN certification is highly desirable.