Cyber and IT Security Advisory Principal Specialist SG

CIMB Singapore

Singapore

On-site

SGD 120,000 - 180,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

CIMB Singapore is seeking an experienced cloud security architect to provide strategic security guidance for AWS environments, ensure alignment with security-by-design, and enforce standards across regions and workloads.

The role requires deep knowledge of IAM, data protection, regulatory compliance, and threat intelligence. You will collaborate with cross-functional teams to manage risks, budgets, and security programs while driving proactive security improvements.

Qualifications

  • Bachelor's degree or equivalent in a relevant field.
  • Professional security certifications preferred (e.g., CISSP, CISA).
  • 10+ years in IT security with cloud and regulated environments.

Responsibilities

  • Provide security advisory for AWS architectures aligned with best practices.
  • Define and enforce AWS cloud security standards and guardrails.
  • Conduct security architecture reviews for AWS-based apps and infra.
  • Review remediation of cloud security findings and drive closure.
  • Ensure AWS environments meet MAS TRM, NIST, and regulatory requirements.
  • Collaborate with Information Security to monitor and reduce risk.
  • Manage project risks, issues, and governance escalation.
  • Lead multiple security solutions across Cyber Program Management, Threat Intelligence, IAM, Data Protection.
  • Oversee security program budgeting and reporting to committees.
  • Coordinate IT security roadmap changes and program management.
  • Manage IT security incidents and mitigation planning.
  • Review vulnerability assessments and pen tests to drive risk reduction.
  • Raise cybersecurity awareness across the organization.

Skills

Cloud security
AWS security
Security architecture
Threat intelligence
Incident response
Vulnerability assessment
Data protection
IAM
Regulatory compliance
Vendor coordination

Education

Bachelor's degree in computer science or equivalent

Tools

Firewall
IDS/IPS
Proxy
VPN technologies
Cloud native security tools

Job description

Key Responsibilities
  • Provide security advisory and oversight for AWS cloud architectures, ensuring alignment with security-by-design and defense‑in‑depth principles.
  • Define, implement, and enforce AWS cloud security standards, guardrails, and best practices across accounts, regions, and workloads.
  • Conduct security architecture reviews for AWS‑based applications and infrastructure, including VPC design, IAM models, data protection, and network segmentation.
  • Review and track remediation of cloud security findings.
  • Ensure AWS environments comply with applicable regulatory and industry requirements (e.g. MAS TRM, NIST).
  • Responsible for ensuring IT systems and applications within our organization meet the needs of the business while adhering to security best-practices, compliance and regulatory requirements.
  • Collaborate with teams within and outside of Information Security to assess, monitor, and reduce security risk within the organisation.
  • Manage project risks and issues, including risk identification, assessment, monitoring, remediation, and ensure escalation in project governance
  • Experience in leading and implementing multiple security solutions and technologies across one or more IT Security domains (Cyber Program Management, Threat Intelligence, Identity & Access Management, Data Protection, Privacy). This experience should include responding to compliance and advisories from regulatory bodies.
  • Ensure cybersecurity programs are structured and well-planned and budgeted
  • Oversee CAPEX & OPEX budget for security services and projects and manage all reporting to Committees
  • Work with IT Security Leads to manage changes in IT Security Roadmap and manage the change management for IT Security programs
  • Manage IT Security incidents, mitigation planning, damage assessment and corrective measures.
  • Review vulnerability assessment & penetration testing to assess the residual risks & mitigation plans.
  • Responsible for ensuring identified cyber security issues are addressed in a timely manner.
  • Raise cybersecurity knowledge and awareness within the organisation
JOB DESCRIPTION
  • Provide security advisory and oversight for AWS cloud architectures, ensuring alignment with security-by-design and defense‑in‑depth principles.
  • Define, implement, and enforce AWS cloud security standards, guardrails, and best practices across accounts, regions, and workloads.
  • Conduct security architecture reviews for AWS‑based applications and infrastructure, including VPC design, IAM models, data protection, and network segmentation.
  • Review and track remediation of cloud security findings.
  • Ensure AWS environments comply with applicable regulatory and industry requirements (e.g. MAS TRM, NIST).
  • Responsible for ensuring IT systems and applications within our organization meet the needs of the business while adhering to security best-practices, compliance and regulatory requirements.
  • Collaborate with teams within and outside of Information Security to assess, monitor, and reduce security risk within the organisation.
  • Manage project risks and issues, including risk identification, assessment, monitoring, remediation, and ensure escalation in project governance
  • Experience in leading and implementing multiple security solutions and technologies across one or more IT Security domains (Cyber Program Management, Threat Intelligence, Identity & Access Management, Data Protection, Privacy). This experience should include responding to compliance and advisories from regulatory bodies.
  • Ensure cybersecurity programs are structured and well-planned and budgeted
  • Oversee CAPEX & OPEX budget for security services and projects and manage all reporting to Committees
  • Work with IT Security Leads to manage changes in IT Security Roadmap and manage the change management for IT Security programs
  • Manage IT Security incidents, mitigation planning, damage assessment and corrective measures.
  • Review vulnerability assessment & penetration testing to assess the residual risks & mitigation plans.
  • Responsible for ensuring identified cyber security issues are addressed in a timely manner.
  • Raise cybersecurity knowledge and awareness within the organisation
Key Requirements
  • Minimally Bachelor's degree in computer science or equivalent
  • Security industry certifications such as CISSP, CISA, CREST, CEH, SANS, GSEC, AWS Certified Security etc are preferred.
  • Minimum 6-10 years’ experience working in a highly-regulated IT Security/CII environment; Including 5 years of threat intelligence, incident response and VAPT experience
Technical / Functional skills
  • Good knowledge and hands-on experience in native-cloud services on Cloud Security
  • Good understanding of TCP/IP protocol and OSI Seven Layer Model.
  • Strong knowledge of security best practices and concepts.
  • Analyzes & prepares recommendations relating to security for existing IT infrastructures / Applications.
  • Expert understanding of firewall technologies.
  • Advance knowledge & Hands-on experience in supporting and maintaining enterprise IT Security solutions and technologies such as Firewall, IDS/IPS and Proxy, etc
  • Advance knowledge of Windows and/or Unix-based systems / architectures and related security.
  • Advance knowledge of cryptography / cryptographic systems
  • Advance level of knowledge of LAN / WAN technologies
  • Knowledge of VPN technologies.
  • Be able to articulate threats and risk to business and technology leaders.
Personal skills (Soft Competencies [Core/Leadership])
  • Ability to plan, organize and prioritize tasks to complete within established time frames.
  • Highly result oriented and can work independently.
  • Ability to build relationships and interact effectively with internal and external parties.
  • Strong analytical, technical, and communication (both oral and written) skills.
  • Strong interest in the field of information security.
  • Creative, independent with good problem solving skills.
  • Ability to work effectively as a team
About Us

With operations that span 15 different markets across the region, the opportunity to expand your experience, test your capabilities, and exhibit your resilience is ample. #teamCIMB is always keen to welcome the ones who are ready to make that very special difference – for themselves and the bank.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber and IT Security Engineering Principal Specialist SG
Cyber and IT Security Engineering Principal Specialist SG

CIMB Singapore • Singapore

On-site
SGD 120,000 - 180,000
Cyber and IT Security Advisory, Specialist / Principal Specialist
Cyber and IT Security Advisory, Specialist / Principal Specialist

CIMB Bank Berhad • Singapore

On-site
SGD 180,000 - 250,000
Security Engineer
Security Engineer

NCS Group • Singapore

On-site
SGD 60,000 - 90,000
Specialist (Cybersecurity)
Specialist (Cybersecurity)

NTUC First Campus • Singapore

On-site
SGD 90,000 - 130,000
Security Consultant, Global Proserve Security
Security Consultant, Global Proserve Security

Amazon Web Services (AWS) • Singapore

On-site
SGD 150,000 - 230,000
Head of Information and Cyber Security
Head of Information and Cyber Security

Tech Aalto Pte ltd • Singapore

On-site
SGD 250,000 - 350,000
Senior Engineer, Cyber Security, Smart Security & Automation
Senior Engineer, Cyber Security, Smart Security & Automation

St Engineering • Singapore

On-site
SGD 90,000 - 150,000
Senior Specialist, Cybersecurity (2 Years Contract)
Senior Specialist, Cybersecurity (2 Years Contract)

NTUC Health Co-operative Limited • Singapore

On-site
SGD 120,000 - 180,000
Cyber Security Specialist (Cloud) - AMK/Project Site - Permanent #5252
Cyber Security Specialist (Cloud) - AMK/Project Site - Permanent #5252

PERSOL OUTSOURCING SINGAPORE PTE. LTD. • Singapore

On-site
SGD 90,000 - 135,000
Cybersecurity Engineer
Cybersecurity Engineer

Alliance Healthcare Group Limited • Singapore

On-site
SGD 60,000 - 100,000