Roles & Responsibilities
Our client is seeking an experienced Security Consultant to join its Security Architecture and Consultancy team. The role will act as a trusted security advisor to project teams, providing guidance across secure solution design, security architecture, threat modelling, risk assessment, and emerging technologies such as AI.
Location: Central
Responsibilities
- Act as a trusted security advisor to project teams, providing guidance on secure system design across cloud, on-premises, and hybrid environments throughout the project lifecycle.
- Conduct security architecture reviews to identify vulnerabilities, misconfigurations, control gaps, and design risks, and provide prioritised remediation recommendations.
- Advise on security architecture and design patterns across cloud security, application security, IAM, data protection, and AI systems.
- Perform threat modelling and security risk assessments, identifying attack vectors, evaluating risks, and recommending appropriate security controls.
- Translate technical security findings into clear business impact and risk considerations for technical teams and senior stakeholders.
- Develop and maintain enterprise security standards, baselines, and reusable security design patterns across areas such as network, endpoint, cryptography, cloud, application, and AI security.
- Assess the security posture of AI and machine learning systems across development, training, deployment, and operational lifecycles.
- Advise on the secure and responsible deployment of AI, including security guardrails, human oversight, incident response, and third-party AI/LLM risks.
- Evaluate third-party AI services and LLM integrations, considering data residency, vendor access, model behaviour, and supply-chain risks.
Requirements
- 8 or more years of relevant cybersecurity experience, with strong experience in security architecture, risk assessment, and security consultancy.
- Familiarity with security compliance frameworks and Singapore Government security policies, including IM8 and CCoP. Experience working with Singapore Government agencies is advantageous.
- CISSP, CISM, CRISC, or equivalent certifications are preferred.
- Bachelor's degree in Computer Science, Information Security, Cybersecurity, or a related discipline.
- Strong expertise in security architecture across cloud, on-premises, and hybrid environments.
- Good knowledge of cloud security, application security, IAM, data protection, threat modelling, and security risk management.
- Working knowledge of AI/ML security, including risks associated with AI system deployment and third-party AI/LLM services.
- AWS Certified Security - Specialty, CCSP, or equivalent cloud security certifications are good to have.