Remote job
Security Architect
Job details
About this role
Role overview A senior architecture role defining security standards across a large-scale consumer financial services platform serving users across Southeast Asia. The position partners closely with Engineering, Product, Cloud, Compliance, and Security teams to design secure systems spanning web, mobile, APIs, AI-enabled features, and data processing, while meeting regional regulatory expectations.
Responsibilities - Define security architecture, patterns, and standards across products, applications, APIs, cloud environments, and integrations. - Own ongoing alignment with SC TRM and BNM RMiT, including control evidence, reviews, remediation, and audit support. - Lead threat modeling and security design reviews for new products, major changes, third-party integrations, and critical systems. - Design and review IAM, privileged access, network security, encryption, key management, secrets handling, logging, and threat detection controls. - Review web, API, native mobile, AI-enabled, and data processing architectures for security and privacy risks. - Guide secure architecture across TypeScript and Node.js, Python, Swift, and Kotlin services running on AWS and GCP. - Evaluate emerging security technologies, advise engineering leaders, and track remediation of material architecture risks.
Requirements - Degree in Computer Science, Information Security, or a related field, or equivalent practical experience. - 5+ years in security engineering, security architecture, or a closely related role. - Hands-on experience implementing and owning SC TRM and BNM RMiT requirements, including control operation, evidence, and audit remediation. - Strong knowledge of cloud and application security, IAM, networking, encryption, secure design, and distributed systems. - Familiarity with AWS and GCP, and with architectures using TypeScript or Node.js, Python, Swift, and Kotlin. - Experience with threat modeling, architecture reviews, risk assessments, and frameworks such as ISO 27001, NIST, CIS, or OWASP. - Ability to translate regulatory and technical risks into clear, actionable plans for both technical and non-technical stakeholders. - Strong English communication skills, as English is the main working language across global teams.
Nice to have - Exposure to AI and machine learning security considerations. - Background working in regulated financial services environments.