Security Architect

OneConnect Financial Technology

Singapore

On-site

SGD 150,000 - 200,000

Full time

39 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

OneConnect Financial Technology is seeking an experienced security architect to lead customer-facing security reviews and forward-deployed cybersecurity engineering for high-volume financial and digital platforms.

You will drive secure design across AWS, Java-based stacks, DevSecOps and AI-assisted security tooling, balancing risk with delivery timelines and commercial requirements.

Qualifications

  • Bachelor’s degree in Computer Science, Information Security, IT, Engineering or related discipline.
  • 5+ years of experience in financial services, banking, fintech or payment environments.
  • Strong knowledge of Java enterprise architecture, AWS security architecture and DevSecOps practices.

Responsibilities

  • Lead customer-facing security architecture and forward-deployed cybersecurity engineering for financial services and high-volume digital businesses.
  • Perform end-to-end security architecture reviews and convert findings into implementable remediation and architecture solutions.
  • Design and recommend AWS-native security architectures and review cloud and infrastructure configurations.
  • Support secure SDLC, SAST, SCA, container security and automation across large estates.
  • Develop reusable security patterns, playbooks and governance to support pre-sales and customer delivery.

Skills

Security architecture
Customer-facing
DevSecOps
AWS security
AI/GenAI for security
Security automation
Threat modelling
Communication

Education

Bachelor's degree in CS/Info Sec/IT/Engineering

Tools

Java ecosystem
Kubernetes/EKS
CI/CD tools
Maven/Gradle

Job description

Lead customer-facing security architecture and forward-deployed cybersecurity engineering for financial services and high-volume digital businesses. The role reviews complex application, cloud and infrastructure architectures, identifies material security risks, and converts findings into practical, deployable solutions. It bridges security, engineering and customer delivery by supporting technical design, prototyping, implementation, validation and reusable solution development across AWS, Java-based platforms, DevSecOps and AI-assisted security engineering.

Key Responsibilities
  • Security Architecture & Risk-to-Solution Delivery: Perform end-to-end security architecture reviews for banking, mobile banking, core banking, payment, e-commerce, online retail, marketplace and cloud-native platforms. Assess application, API, identity, data, network, cloud, containers, CI/CD, third-party integration, resilience and operational security, and convert findings into implementable remediation and architecture solutions.
  • Customer-Facing Forward Deployed Engineering: Work directly with customers, application, infrastructure, DevOps and security teams from problem discovery through technical design, prototyping, implementation support, production validation and measurable security outcomes. Balance security requirements with delivery timelines, business operations and commercial practicality.
  • AWS, Infrastructure & Application Security Engineering: Design and recommend AWS-native security architectures using services such as IAM, KMS, WAF, Shield, GuardDuty, Security Hub, Inspector, CloudTrail, Config, EKS, ECR and Systems Manager. Review VPC architecture, segmentation, routing, security groups, NACLs, load balancers, VPN, Direct Connect, Transit Gateway, PrivateLink, DNS and ingress/egress controls. Assess Java/Spring application risks, including framework upgrades, dependencies, middleware interaction, API compatibility and production impact.
  • DevSecOps, AI & Security Automation: Support secure SDLC and DevSecOps implementation across SAST, SCA, container security, CI/CD security, secrets management and security gates. Use AI/GenAI-assisted engineering for source-code analysis, dependency analysis, vulnerability remediation, architecture review, impact assessment, testing and automation. Build prototypes, security tooling, standardized patterns and implementation accelerators for large application and infrastructure estates.
  • Governance, Reuse, Measurement & Pre-Sales: Develop reusable security reference architectures, security patterns and remediation playbooks for common banking, e-commerce and AWS scenarios. Validate implemented controls through testing and operational review, measure risk reduction and remediation progress, communicate technical and business impact to stakeholders, and support pre-sales by turning security challenges into solution offerings, architecture proposals and implementation roadmaps.
Qualifications & Requirements
  • Education: Bachelor’s degree or above in Computer Science, Information Security, Information Technology, Engineering or a related discipline.
  • Experience: 5+ years of relevant experience in financial services, banking, fintech or payment environments. Experience in e-commerce, online retail, digital marketplaces, payment platforms or other high-volume digital businesses is also valuable. Demonstrated experience in security architecture reviews, complex vulnerability remediation and customer-facing technical solution delivery is required.
  • Technical Skills: Strong knowledge of Java enterprise architecture (Java/JDK, Spring Framework, Spring Boot, Spring Security, REST APIs, Maven/Gradle and dependency management); application and API security; IAM; cryptography and data protection; AWS security architecture; VPC and hybrid networking; TCP/IP, DNS, TLS, routing, firewalls, segmentation, reverse proxies and load balancers; containers, Kubernetes/EKS, microservices, API gateways and CI/CD; DevSecOps, SAST, SCA, container security and secrets management; and practical use of AI/GenAI for engineering, security analysis or automation.
  • Soft Skills: Strong customer-facing communication, architecture thinking, problem-solving and ownership. Able to work effectively in ambiguous environments, collaborate across security and engineering teams, explain complex technical risks in business terms, and balance security, delivery, operational and commercial requirements.
  • Certifications (if applicable): Relevant certifications such as CISSP, CCSP, AWS Certified Solutions Architect – Professional, AWS Certified Security – Specialty, CISA or equivalent are advantageous.
  • Language Requirements: Fluent professional English is required. Additional languages used in regional banking or customer engagements are an advantage.
Preferred Qualifications
  • Experience with core banking, mobile banking, payment platforms or large-scale financial applications.
  • Experience with e-commerce, online retail, digital marketplaces, order-management platforms, customer-facing digital platforms or high-volume transaction environments.
  • Experience designing AWS security landing zones, cloud security foundations, enterprise security platforms or multi-account security architectures.
  • Deep familiarity with Java/Spring-based banking, e-commerce or enterprise platforms and the security/compatibility impact of framework and library upgrades.
  • Advanced AWS networking experience, including VPC, Transit Gateway, Direct Connect, PrivateLink, Route 53 and multi-account network design.
  • Knowledge of OWASP ASVS/MASVS, NIST SSDF, threat modelling and secure architecture principles.
  • Knowledge of AI security, AI governance, AI-assisted development and agentic security workflows.
  • Experience developing security architecture governance, standards, reusable reference architectures and review processes.
  • Experience in forward-deployed engineering, embedded consulting, technical solution delivery or customer-facing cybersecurity engineering.
  • Experience turning customer-specific security solutions into reusable products, accelerators, reference implementations or managed services.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer
Security Engineer

GXS Bank Pte. Ltd. • Singapore

On-site
SGD 90,000 - 130,000
Cyber and IT Security Advisory, Specialist / Principal Specialist
Cyber and IT Security Advisory, Specialist / Principal Specialist

CIMB Bank Berhad • Singapore

On-site
SGD 180,000 - 250,000
Director - Cyber Security Architect
Director - Cyber Security Architect

Selby Jennings • Singapore

On-site
SGD 240,000 - 360,000
Senior Security Solution Architect, APJC Customer Security, APJC Customer Security (AWS)
Senior Security Solution Architect, APJC Customer Security, APJC Customer Security (AWS)

Amazon • Singapore

On-site
SGD 210,000 - 360,000
Senior Security Solution Architect, APJC Customer Security, APJC Customer Security
Senior Security Solution Architect, APJC Customer Security, APJC Customer Security

amazon web services singapore private limited • Singapore

On-site
SGD 240,000 - 360,000
Senior Cybersecurity Solutions Architect
Senior Cybersecurity Solutions Architect

Selby Jennings • Singapore

On-site
SGD 240,000 - 360,000
Security Consultant, Global Proserve Security
Security Consultant, Global Proserve Security

AMAZON WEB SERVICES SINGAPORE PRIVATE LIMITED • Singapore

On-site
SGD 110,000 - 170,000
G01 - IT Security Officer
G01 - IT Security Officer

FPT Asia Pacific • Singapore

On-site
SGD 120,000 - 180,000
Senior Lead Cybersecurity Engineer
Senior Lead Cybersecurity Engineer

Charterhouse Pte Ltd • Singapore

On-site
SGD 180,000 - 240,000
Security & Compliance Engineer, AWS Security Assurance Services, LLC
Security & Compliance Engineer, AWS Security Assurance Services, LLC

Amazon Web Services (AWS) • Singapore

On-site
SGD 120,000 - 180,000