Apply for Job
Platform Cybersecurity Enterprise Architect
SG
Job Description
- Own and maintain the current-state, transition-state and target-state cybersecurity architecture for the platform and managed service portfolio, aligned with the product and technology roadmap.
- Design reusable and productised managed security offerings, including but not limited to, for eg. centrally managed firewall service, covering multi-tenancy, tenant segregation, policy and change lifecycle, high availability, disaster recovery, secure onboarding, telemetry, auditability and customer reporting.
- Ensure other managed offerings, including managed Wi-Fi, LAN, SD-WAN, cloud, infrastructure and related platform services, are designed with security by default and with consistent controls across the service portfolio.
- Define and maintain platform guardrails, reference architectures, approved design patterns, technical standards and control baselines across network, identity, cloud, application and API, data, encryption, key and secrets management, endpoint and platform engineering domains.
- Partner with the CISO and Cybersecurity Governance teams to translate security policies, regulatory obligations and risk requirements into implementable architecture and control requirements, and provide technical impact assessments and remediation options.
- Lead architecture review, design assurance and threat-modelling activities throughout the platform lifecycle, from concept and build through release, customer onboarding, operation and technology refresh.
- Work closely with Product Owners, the Platform Architect, Engineering, SOC, Operations, Service Delivery, ITSM and other domain architects to prioritise security capabilities and ensure implementation remains aligned with the approved architecture.
- Define non-functional requirements and acceptance criteria covering security, availability, scalability, performance, resilience, recoverability, maintainability, observability, supportability and cost efficiency.
- Architect secure automation and orchestration capabilities, including infrastructure as code, CI/CD, configuration and policy as code, automated compliance checks, standardised service provisioning and controlled customer changes.
- Ensure platform and service telemetry supports effective operations and security monitoring, including the logging of permitted, blocked, failed, administrative and policy-change activities, with integration into observability, SIEM/SOC, ITSM/CMDB and customer reporting processes.
- Evaluate technologies, products, vendors and cloud services; lead technical assessments and proof-of-concept activities; and maintain technology standards, lifecycle roadmaps, end-of-life plans and technical debt priorities.
- Govern the standard platform boundaries and assess customer-specific deviations for feasibility, security impact, operational complexity, cost and reusability before approval or escalation.
- Produce and maintain architecture artefacts, including principles, blueprints, high-level designs, logical and physical diagrams, data flows, trust boundaries, control mappings, threat models, architecture decision records and roadmaps.
- Support implementation, security testing, operational readiness, service transition, go-live and post-implementation reviews, while providing architectural guidance and mentoring to engineering and operations teams.
- Provide platform capability, constraint and reusable design guidance to solution and customer-facing teams for complex requirements.
Qualifications
- Degree in Information Technology, Computer Science, Engineering, Cybersecurity or a related field, with at least 10 years of relevant experience, including significant experience in enterprise, security or platform architecture.
- Proven experience designing multi-tenant, centrally managed platforms or managed security services at scale.
- Strong end-to-end technical and architectural knowledge across networking, cybersecurity, cloud, platform engineering, service management and observability.
- Familiarity with technologies such as firewalls, IPS/IDS, SASE/ZTNA, SD-WAN, NAC, wireless security, WAF, DDoS protection, NDR, EDR/XDR/MDR, SIEM, SOAR, IAM/PAM, PKI, key and secrets management, public and private cloud, and container platforms.
- Strong understanding of Zero Trust, defence in depth, tenant isolation, secure APIs, encryption, threat modelling, vulnerability and configuration management, secure software development and security-by-design principles.
- Good understanding of managed-service and operational design considerations, including availability, disaster recovery, capacity, service levels, change, incident and problem management, patching, lifecycle management and ITSM/CMDB integration.
- Working knowledge of relevant architecture, security and control frameworks, such as TOGAF, SABSA, NIST Cybersecurity Framework, ISO/IEC 27001, CIS Controls and CSA Cloud Controls Matrix, together with applicable regulatory requirements.
- Relevant certifications are preferred, such as CISSP, CCSP, SABSA, TOGAF, CISM, cloud security or recognised network and security vendor certifications.
- Strong stakeholder-management and communication skills, with the ability to engage the CISO, senior management, product, engineering, operations, delivery and customer-facing teams, and to translate technical risks into clear decisions and actions.
- Strong research, analytical, vendor-evaluation and problem-solving skills, with the ability to balance security, customer experience, operability, standardisation and commercial sustainability.
- Able to operate effectively in a dynamic, fast-paced environment and provide clear architectural direction across multiple concurrent platform initiatives.