Dyson

Principal Cyber Security Architect (Application Security)

Dyson
Apply
1 day ago
Singapore, SingaporeStaff+

Responsibilities

  • Set application security and DevSecOps architecture direction, including target architectures, principles, standards, patterns, and control objectives.
  • Lead security architecture reviews, threat modeling, risk assessments, design decisions, and risk governance across the application lifecycle.
  • Define reusable controls for identity, API protection, secrets, encryption, tenant isolation, logging, monitoring, and secure failure modes.
  • Establish DevSecOps controls, security quality gates, exception workflows, evidence capture, and feedback loops.
  • Guide SAST, DAST, software composition analysis, secrets scanning, infrastructure-as-code scanning, container and image scanning, API security testing, mobile testing, and penetration testing.
  • Define software supply-chain security expectations for dependencies, SBOMs, provenance, artifact signing, trusted builds, and third-party components.
  • Partner with platform and engineering enablement teams to create secure-by-default templates, paved roads, and reusable controls.
  • Establish vulnerability triage, remediation, risk acceptance, verification, security metrics, and capability measurement.
  • Build security champion networks, role-based training, communities of practice, and developer security guidance.
  • Provide technical leadership to multidisciplinary teams and suppliers, support transition to operations, and assist with significant security incidents and control failures.

Requirements

  • Extensive experience in application security, security architecture, or secure software engineering with ownership of complex enterprise-scale outcomes.
  • Strong knowledge of secure software design and software development lifecycles across web, mobile, APIs, microservices, and cloud-native services.
  • Practical experience designing or maturing DevSecOps capabilities and integrating security controls into modern delivery platforms and developer workflows.
  • Deep knowledge of the OWASP Top 10, OWASP API Security Top 10, application threats, and API threats.
  • Hands-on experience with security testing capabilities, including tuning, coverage, false-positive management, and quality gates.
  • Strong threat-modeling and security-risk-assessment skills covering trust boundaries, data flows, abuse paths, and compensating controls.
  • Experience with OAuth 2.0, OpenID Connect, SAML, token handling, authorization design, session security, secrets, and cryptographic key management.
  • Knowledge of cloud and container security across at least one major cloud platform, including Kubernetes, serverless, API gateways, service-to-service communication, and infrastructure as code.
  • Working knowledge of software supply-chain controls, dependency governance, SBOMs, artifact integrity, signing, provenance, build-pipeline security, and third-party component risk.
  • Ability to read and challenge code, configuration, and pipeline definitions, with proficiency in Python, Java, JavaScript, TypeScript, C#, or Go and practical use of REST or GraphQL APIs, JSON, YAML, and scripting.
  • Experience producing architecture documentation, security requirements, patterns, technical standards, low-level designs, and risk decisions.
  • Strong communication, facilitation, influencing, independent working, and multidisciplinary coordination skills.
  • Experience establishing security-champion networks, developer security education, or product security communities of practice.
  • Experience with WAF policy design, bot management, rate limiting, and governed virtual patching.
  • Experience defining control evidence and metrics for regulated, high-assurance, or audit-sensitive environments.
  • Knowledge of mobile application security testing, secure mobile design, and relevant OWASP mobile guidance.
  • Relevant certifications such as ISC2 CSSLP, CISSP, GIAC secure software credentials, or cloud security certifications are valued.
Dyson

About Dyson

10,000+ employees

Dyson designs and sells consumer appliances and electronics, including bagless vacuum cleaners, air treatment products, haircare tools, hand dryers, lighting, and home robots, for households and commercial settings. The family-owned company was founded in 1993 by Sir James Dyson and has its global headquarters in Singapore, selling through its own stores, online, and major retailers in more than 80 markets.

Contact me