You are the security guardian for Centience's cloud environment, with particular responsibility for protecting the data and AI infrastructure the business depends on.
Every byte of data, at rest or in transit, must be encrypted, monitored, and access-controlled at all times. Day-to-day, you work closely with the Head of Data Science & Analytics so that machine learning models and AI products can be built and shipped boldly on a security posture robust enough that compliance is a foundation, never a bottleneck.
Your reporting will be to the MD & the Head of Data Science & Analytics.
Key Responsibilities
1. Data Security Architecture
- Design and enforce end-to-end encryption: AES-256 at rest across S3, Redshift, RDS, and Snowflake; TLS 1.2+ in transit for all inter-service communication and API calls.
- Manage the cryptographic key lifecycle with AWS KMS, and implement tokenisation, dynamic data masking, and column-level encryption for PII and sensitive fields used in analytics and ML pipelines.
- Enforce private endpoints, VPC isolation, and network segmentation to eliminate public exposure of sensitive workloads.
2. Identity, Access Management & Zero Trust
- Design and enforce least-privilege IAM policies across all AWS accounts and platform tooling (SageMaker, Databricks, Snowflake,Airflow).
- Implement RBAC and ABAC so each role accesses only what it requires; enforce MFA and federated identity (SSO/SAML) and eliminate long-lived static credentials.
- Conduct quarterly access reviews and automated privilege-creep detection; revoke stale and excessive permissions proactively.
- Operate continuous monitoring with GuardDuty, Security Hub, CloudTrail, and Config, with automated alerting for anomalous access, privilege escalation, and policy violations.
- Build and maintain incident response playbooks for scenarios such as data exfiltration, model poisoning, unauthorised API access, and pipeline tampering.
- Lead vulnerability management (penetration testing cadence, CVE scanning) and establish SIEM integration (AWS Security Lake or Splunk) for correlation and forensics.
4. Compliance, Regulatory Assurance & Audit
- Own security compliance posture for PDPA, GDPR, and applicable industry regulations, maintaining assessments and evidence packages.
- Enforce data residency and cross-border transfer safeguards; maintain audit-ready logs and conduct environment security reviews before every major launch or new data source onboarding.
5. DevSecOps Integration & Enablement
- Embed security scanning (SAST, DAST, SCA, container image scanning) into CI/CD pipelines with pass/fail gates for production deployments.
- Partner with the DevOps Engineer on secrets management, immutable artifacts, and signed model registries, and run security awareness sessions so secure practice is embedded across teams.
Qualifications
- Bachelor's degree in Computer Science, Cybersecurity, or related field.
- 5+ years of cloud security engineering experience, with AWS as the primary platform.
- AWS Security Specialty certification required; CISSP, CISM, or CEH strongly preferred.
- Deep hands-on expertise in AWS security services: GuardDuty, Security Hub, Macie, KMS, IAM, VPC, WAF, CloudTrail, Config,Inspector.
- Experience securing data platforms (S3 policies, Redshift/Snowflake row- and column-level security, Lake Formation) and with SIEM and security automation (Python, Lambda, EventBridge).
- Solid understanding of PDPA and GDPR as they apply to analytics and AI/ML pipelines, plus penetration testing and vulnerability management experience.
Success Indicators
- Zero data breach or unauthorised data access incidents.
- 100% encryption coverage — all data at rest and in transit confirmed via automated compliance scans.
- Critical security alerts acknowledged and initial response initiated within 1 hour; resolved within SLA.
- All environments pass quarterly security audits with no critical or high findings; PDPA/GDPR compliance maintained continuously.