Get more replies from employers
Send a job-specific resume in minutes.
Dyson GmbH is seeking a Principal Workspace Security Architect to define the end-to-end workplace security strategy, architecture, and governance across end-user computing, collaboration, identity, and communications platforms.
You will drive Zero Trust adoption, lead technical design reviews, and own the long-term security roadmap, working with platform engineering to embed secure-by-design principles across IT delivery.
Salary : Competitive Job Family : Cyber Security Location : Singapore - Technology Centre
Principal – Workspace Security Architecture and EngineeringRole: Principal Workspace Security Architecture and EngineeringReporting to: Chief Information Security OfficerRole type: ManagerRole PurposeAs the Principal Workplace Security Architect, you are accountable for defining and driving the end-to-end workplace security strategy, architecture, technology roadmap, and governance across end-user computing, collaboration, identity, and communications platforms globally.Operating as a strategic Individual Contributor and Technical Design Authority, you will lead the adoption of Zero Trust principles across workforce technologies. By establishing robust security standards and reference architectures, you will proactively reduce cyber risk, guide platform engineering execution, and ensure that workplace capabilities are secure-by-design.In this role, you will lead and manage the following domains:
Bachelor's degree in cyber security, Information Technology, Computer Science, or a related discipline (or equivalent practical experience). A minimum of 7–10 years’ experience in cybersecurity, with a strong focus on vulnerability management, security operations, or risk management within enterprise environments. Demonstrated experience operating and improving vulnerability management programmes at scale, including ownership of tooling, governance, and remediation outcomes. Relevant industry certifications (e.g. CISSP, CISM, CRISC, GIAC) are highly desirable, along with proven experience engaging senior stakeholders, managing cross functional delivery, and aligning security outcomes to business risk and priorities.
Strong understanding of the end to end vulnerability management lifecycle, including discovery, assessment, prioritisation, remediation, and validation. Strong grasp of remediation assurance activities of common vulnerabilities (e.g. CVEs, OWASP, configuration weaknesses) and how they manifest across infrastructure, cloud, endpoint, and application environments, with the ability to apply risk based thinking to reduce exposure.
Hands on experience with vulnerability management platforms such as Qualys, Tenable, or Rapid7, including asset discovery, agent based and network scanning, and scan optimisation. Ability to interpret scan outputs, manage false positives, tune scan policies, and integrate with CMDB and ITSM platforms (e.g. ServiceNow) to ensure accurate and actionable results.
Ability to assess, quantify, and articulate cyber risk in business terms, leveraging frameworks such as NIST or ISO. Skilled in risk based prioritisation that combines asset criticality, exploitability, and threat intelligence to ensure remediation efforts are focused on the highest impact vulnerabilities.
Experience designing and embedding scalable vulnerability management policies, standards, and procedures aligned to audit and compliance expectations. Strong understanding of control frameworks, with the ability to manage exceptions, risk acceptance, and compensating controls in a structured and defensible manner.
Proven capability in running a large scale security service, including managing SLAs, KPIs, backlog, and remediation workflows. Able to drive consistent service performance, ensure high scan coverage and quality, and enforce accountability across distributed engineering and infrastructure teams.
Strong analytical skills to interpret vulnerability data, identify trends, and generate actionable insights. Ability to develop clear reporting and dashboards for both technical and executive audiences, using metrics such as MTTR, SLA adherence, and exposure windows to drive continuous improvement.
Highly effective communicator with the ability to engage, influence, and challenge both technical and non technical stakeholders. Skilled in translating technical findings into business impact, driving remediation accountability, and building strong relationships across infrastructure, product, and risk domains.
Understanding of how to integrate cyber threat intelligence into vulnerability management processes, including awareness of actively exploited vulnerabilities and attacker tactics. Ability to collaborate with CTI teams to ensure prioritisation reflects real world threat activity and emerging risks.
Experience leading and developing teams, setting priorities, and managing competing demands. Strong decision making capability, with a focus on building team capability, improving performance, and fostering a culture of accountability and continuous improvement.
A continuous improvement mindset with a focus on optimising processes, increasing automation, and reducing manual effort. Experience identifying opportunities to enhance workflows, tooling integration, and efficiency through scripting, APIs, or process redesign.
Dyson is an equal opportunity employer. We know that great minds don’t think alike, and it takes all kinds of minds to make our technology so unique. We welcome applications from all backgrounds and employment decisions are made without regard to race, colour, religion, national or ethnic origin, sex, sexual orientation, gender identity or expression, age, disability, protected veteran status or other any other dimension of diversity.