Principal Cyber Security Architect (Application Security)

dyson

Singapore

On-site

SGD 250,000 - 380,000

Full time

4 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Dyson is seeking a Principal Cybersecurity Architect for Application Security and DevSecOps to lead security across our digital application landscape, including eCommerce, mobile apps, APIs, and cloud-native services. You will define reusable architectures, patterns and guardrails to enable secure delivery.

You will work with engineering teams to integrate security into the software development lifecycle, drive threat modelling, security testing, and governance, and build secure-by-default

Qualifications

  • Experience in designing and governing scalable security architectures across web/mobile/API/maaS environments.
  • Proven ability to lead security reviews, risk assessments and governance across SDLC.

Responsibilities

  • Set application security and DevSecOps architecture direction aligned with policy and risk.
  • Provide security guidance across web, mobile, API, microservices, serverless and cloud-native architectures.

Skills

Security architecture
DevSecOps
Threat modelling
Security testing

Job description

About us

At Dyson, we are not just creating innovative, technology-enabled products; we are also breaking new ground in cybersecurity. Our products are becoming more advanced and interconnected, which means we face a constantly evolving cyber threat landscape. This requires a highly skilled candidate to join our team, with a passion for staying ahead of emerging threats and keeping our products secure.

We take a proactive approach to cybersecurity. We do not wait for threats to emerge; we anticipate them and respond with innovative solutions. This means that at Dyson, you will have the opportunity to work with innovative technologies, like artificial intelligence and machine learning, to protect our products and customers.

You will be part of a team of cybersecurity experts, utilizing the latest tools and technologies to identify and respond to threats in real-time. You will work closely with our engineering and product teams to ensure that security is integrated into every aspect of our business.

Join our team at Dyson, and you will be at the forefront of cybersecurity, working on some of the most innovative and advanced products in the industry. You will have the opportunity to develop your skills and knowledge, collaborating with a talented team of experts to ensure we are always secure. If you are passionate about cybersecurity and looking for an exciting and challenging role, Dyson is the place for you.

About the role

As Principal Cybersecurity Architect for Application Security and DevSecOps, you will be the senior architecture authority for security across Dyson's digital application landscape, including eCommerce, customer and ownership experiences, mobile applications, APIs and supporting cloud-native services.

You will define reusable security architectures, patterns and guardrails, and help establish a scalable DevSecOps capability that embeds proportionate security controls throughout the software development lifecycle. You will work with engineering teams to make secure delivery repeatable, measurable and developer-friendly, while retaining clear risk ownership and governance.

What you will do
  • Set the application security and DevSecOps architecture direction, translating enterprise risk appetite and security policy into practical target architectures, principles, standards, patterns and control objectives.
  • Provide authoritative security advice across web, mobile, API, microservices, serverless and cloud-native architectures, balancing security, resilience, customer experience, delivery speed and cost.
  • Lead security architecture reviews and risk assessments from discovery through design, build, release and operation. Record design decisions, material risks, required controls, exceptions and residual risk in an audit-defensible manner.
  • Facilitate threat modelling using fit-for-purpose techniques such as STRIDE, attack trees, abuse cases and data-flow analysis. Ensure identified threats are translated into owned engineering requirements and verified mitigations.
  • Design and govern reusable security patterns for identity and access, session management, API protection, secrets, encryption, key and certificate use, tenant isolation, input and output handling, logging, monitoring and secure failure modes.
  • Define the DevSecOps control framework and reference pipeline, including policy-as-code, security quality gates, risk-based thresholds, exception workflows, evidence capture and feedback loops across CI/CD.
  • Guide the integration and effective use of security testing capabilities, including SAST, DAST, software composition analysis, secrets scanning, infrastructure-as-code scanning, container and image scanning, API security testing, mobile testing and penetration testing.
  • Strengthen software supply-chain security by defining expectations for dependency governance, software bills of materials, provenance and integrity, artifact signing, trusted build environments and third-party component risk.
  • Partner with engineering enablement and platform teams to create secure‑by‑default paved roads, templates and reusable controls that reduce friction and prevent recurring vulnerabilities.
  • Establish vulnerability triage and remediation models that include severity, exploitability, business context, ownership, service‑level expectations, risk acceptance and verification of closure.
  • Develop application security metrics and capability measures covering control coverage, effectiveness, engineering adoption, security debt, remediation performance and recurring defect patterns. Use evidence to prioritise improvement.
  • Build capability through security champions, role‑based training, coaching, communities of practice and practical guidance for architects, developers, testers, product managers and platform engineers.
  • Act as a trusted partner to Cyber Security and Risk, Digital, Engineering and Technology stakeholders. Provide technical leadership to virtual teams and suppliers, assure delivery quality and support e
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Principal Cyber Security Architect (Application Security)
Principal Cyber Security Architect (Application Security)

Dyson Operations Pte Ltd • Singapore

On-site
SGD 180,000 - 280,000
Principal Cyber Security Architect (Application Security)
Principal Cyber Security Architect (Application Security)

Dyson Institute • Singapore

On-site
SGD 180,000 - 240,000
Principal AppSec Architect & DevSecOps Leader
Principal AppSec Architect & DevSecOps Leader

Dyson Operations Pte Ltd • Singapore

On-site
SGD 180,000 - 280,000
Associate Principal Cyber Security Architect (Data)
Associate Principal Cyber Security Architect (Data)

dyson • Singapore

On-site
SGD 140,000 - 210,000
Senior Application Security Architect & DevSecOps Lead
Senior Application Security Architect & DevSecOps Lead

dyson • Singapore

On-site
SGD 250,000 - 380,000
Principal DevSecOps & App Security Architect
Principal DevSecOps & App Security Architect

Dyson Institute • Singapore

On-site
SGD 180,000 - 240,000
Associate Principal Cyber Security Architect (Data)
Associate Principal Cyber Security Architect (Data)

Dyson Institute • Singapore

On-site
SGD 180,000 - 240,000
Principal – Workspace Security Architecture and Engineering
Principal – Workspace Security Architecture and Engineering

Dyson Institute • Singapore

On-site
SGD 250,000 - 360,000
Principal Security Solution Architect (IAM)
Principal Security Solution Architect (IAM)

Dyson • Singapore

On-site
SGD 180,000 - 260,000
Senior Director, Security Architecture & Engineering
Senior Director, Security Architecture & Engineering

Dyson • Singapore

On-site
SGD 180,000 - 340,000