Security Architect

Confidential

Kuala Lumpur

On-site

MYR 180,000 - 260,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Confidential in Malaysia seeks a Security Architect to define and own the security design of applications, APIs, and platforms, within the Application Security team and Crypto division. You will translate risk appetite into architectural patterns and drive secure-by-design principles across the portfolio.

You will lead threat modelling, security reviews, and tooling evaluations, collaborating with engineers, product managers, and senior stakeholders to ensure cloud-native and hybrid setups meet

Qualifications

  • 8+ years in information security with at least 3 years in security architecture or principal/staff security engineering.
  • Deep expertise in application security architecture across web, mobile, API, and microservices, with crypto/digital asset experience.
  • Strong knowledge of OWASP Top 10 and blockchain-specific threat vectors and mitigations.
  • Experience designing secure cloud-native and hybrid architectures (AWS/Azure/GCP).
  • Proficiency in threat modelling methodologies (STRIDE/PASTA/MITRE ATT&CK).
  • Familiarity with regulatory frameworks such as DORA, PCI-DSS, ISO, SOC; excellent communication skills.

Responsibilities

  • Define and own the application security architecture vision, standards, and reference patterns across surfaces.
  • Provide architectural guidance and security assurance on new products, features, and crypto-related platforms.
  • Conduct security architecture reviews and threat modelling for new and existing applications.
  • Develop and maintain security design patterns, guardrails, and secure-by-default frameworks for SDLC adoption.
  • Lead evaluation of security technologies and tooling to align with architectural principles.
  • Partner with Cloud and Infrastructure teams to ensure secure deployment architectures across cloud and hybrid environments.
  • Collaborate with Risk & Compliance to align architecture with regulatory obligations including DORA, PCI DSS, ISO and SOC.
  • Represent the Application Security team in cross-functional architecture forums and governance bodies.

Skills

Application security
Threat modelling
Cloud security
Blockchain security
Regulatory compliance
Communication
Certifications
Software engineering
English fluency

Education

Bachelor's degree in Computer Science or related field

Job description

As part of the Security team, you will help to define and own the security design of our applications, APIs, and supporting platforms. Sitting within the Application Security team, you will translate the organisation risk appetite into clear, actionable architectural patterns that engineering teams can build to, ensuring security is a foundational consideration rather than an afterthought. You will also bring a dedicated security architecture focus to our Crypto division, helping shape secure design patterns for digital asset products in a fast-evolving regulatory landscape. You will serve as the senior technical authority on application security architecture, working closely with engineers, product managers, and senior stakeholders to drive secure-by-design principles across the product portfolio.

As our Security Architect, your key responsibilities include, but may not be limited to:

  • Define and own the application security architecture vision, standards, and reference patterns across web, mobile, API, and cloud-hosted application surfaces.
  • Provide architectural guidance and security assurance on new products, major feature delivery, and significant changes to existing systems, including addressing risks specific to Crypto digital asset custody, wallet infrastructure, exchange connectivity, and blockchain integrations.
  • Conduct security architecture reviews and threat modelling for new and existing applications, identifying risks and recommending mitigating controls.
  • Develop and maintain security design patterns, guardrails, and secure-by-default frameworks that engineering teams can adopt within the SDLC.
  • Lead the evaluation and selection of application security technologies and tooling, ensuring alignment with the team's architectural principles and business needs.
  • Partner with Cloud and Infrastructure teams to ensure application deployment architectures meet security requirements across AWS, Azure, and hybrid environments.
  • Collaborate with Risk & Compliance to align application security architecture with regulatory obligations including DORA, PCI DSS, ISO and SOC.
  • Represent the Application Security team in cross-functional architecture forums and technology governance bodies.

About You

  • 8+ years of progressive experience in information security, with at least 3 years in a security architecture or principal/staff security engineering role.
  • Deep expertise in application security architecture across web, mobile, API, and microservices domains including prior experience securing cryptocurrency, blockchain, or digital asset platforms (e.g. wallet security, custody solutions, exchange/DeFi integrations).
  • Strong working knowledge of common vulnerability classes, OWASP Top 10, and application-layer attack patterns as well as blockchain-specific threat vectors (smart contract risk, key management, on-chain/off-chain attack surfaces) and common mitigations.
  • Demonstrated experience designing secure architectures for cloud-native and hybrid environments (AWS, Azure, or GCP).
  • Proficiency in threat modelling methodologies such as STRIDE, PASTA, or MITRE ATT&CK, with the ability to lead sessions with engineering teams.
  • Experience working in or with regulated financial services organisations and familiarity with frameworks such as DORA, PCI-DSS, ISO and SOC.
  • Excellent communication skills; able to translate complex security design decisions into clear guidance for engineers and risk-based recommendations for senior leadership.
  • Relevant certifications such as CISSP, CSSLP, OSCP, CCSP, or AWS/Azure Security is a plus.
  • Hands‑on background in software engineering or development is strongly advantageous.
  • Fluency in English.
  • Committed to ongoing learning and development.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Architect - App & Crypto Platform Design
Senior Security Architect - App & Crypto Platform Design

Confidential • Kuala Lumpur

On-site
MYR 180,000 - 260,000
Security Architect
Security Architect

Teleport • Kuala Lumpur

On-site
MYR 120,000 - 210,000
Application Security Lead
Application Security Lead

Salmon Group Ltd • Kuala Lumpur

On-site
MYR 280,000 - 420,000
Enterprise Security Architect
Enterprise Security Architect

Neuron Solutions Sdn Bhd • Kuala Lumpur

On-site
MYR 180,000 - 240,000
Senior Security Advisor & Technical Project Manager
Senior Security Advisor & Technical Project Manager

Hong Leong Bank Berhad • Petaling Jaya

On-site
MYR 180,000 - 300,000
Senior Security Business Partner – Product Security
Senior Security Business Partner – Product Security

Hytech • Kuala Lumpur

On-site
MYR 180,000 - 260,000
Assistant Vice President, Cloud Security Engineer
Assistant Vice President, Cloud Security Engineer

Permodalan Nasional Berhad • Kuala Lumpur

On-site
MYR 180,000 - 240,000
Lead Application Security Engineer
Lead Application Security Engineer

Encora Inc. • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Cyber Defense Lead
Cyber Defense Lead

Hong Leong Bank Berhad • Selangor

On-site
MYR 120,000 - 160,000
Associate Director,Information Security Strategy
Associate Director,Information Security Strategy

aia • Cyberjaya

On-site
MYR 180,000 - 300,000