Cybersecurity Architect - #1169769
DYMON ASIA CAPITAL (SINGAPORE) PTE. LTD.
Role Overview
The Cybersecurity Architect is the technical blueprint master and engineering anchor for the firm's security infrastructure. Reporting directly to the Head of Cybersecurity, this role is responsible for designing, validating, and steering the technical implementation of security controls across on-premises and cloud environments.
Given our lean team structure, this is not an "ivory tower" role. The ideal candidate must be a highly hands-on, deeply technical engineering expert capable of translating high-level policy and regulatory requirements into concrete, secure infrastructure designs. Working as a direct peer to the Cybersecurity Project Manager, the Architect ensures that all security initiatives are architected for resilience, seamless user adoption, and long-term operational sustainability.
Crucially, the architect must possess the business acumen to design size-appropriate defenses; we require highly effective, streamlined security frameworks tailored for a fast-paced, lean hedge fund environment, rather than the hyper-complex, over-engineered architectures found in massive enterprises.
Key Responsibilities
1. Architecture Design and Strategy
- Define, own, and maintain the security architecture blueprints, ensuring a robust "Defense in Depth" posture across the enterprise.
- Architect defense mechanisms that are right-sized and scaled appropriately to the organization's footprint; avoid unnecessary complexity by prioritizing high-impact, elegant, and efficient controls over sprawling enterprise-scale solutions.
- Design and optimize secure landing zones, ingress/egress controls, identity fabrics, privileged access management (PAM), and secrets management within Azure Cloud infrastructure.
- Architect and optimize enterprise endpoint security baselines and automated vulnerability management frameworks, establishing robust mechanisms for fleet-wide software risk mitigation and compliance remediation.
- Collaborate closely with infrastructure, cloud, and application teams to embed "Security by Design" into the systems lifecycle.
2. Engineering and Project Collaboration
- Partner with the Cybersecurity Project Manager to provide technical scoping, design validation, and engineering guardrails for all major security deployments. Not only the Cybersecurity Architect is responsible for designing a robust security architecture, he is also responsible for ensuring the delivery of the project, and the operationalization of it.
- Serve as the technical lead for complex implementation projects, including SIEM/SOC integrations, data loss prevention (DLP) programs, network segmentation, and advanced EDR/XDR deployments.
- Develop clear technical documentation, engineering standards, and deployment playbooks to ensure smooth operational handoffs.
3. Operations and Threat Modeling
- Keep abreast of the evolving threat landscape to continuously evaluate, stress-test, and update the firm's architectural defenses.
- Provide tier-3 technical escalation support for major security incidents, working alongside outsourced SIEM/SOC vendors to conduct deep technical forensics and root-cause analysis.
- Design and conduct technical threat modeling exercises for new trading applications, financial platforms, and infrastructure changes.
4. Regulatory and Risk Alignment
- Ensure all technical architectures strictly align with MAS TRM guidelines, local regulations across our operating regions and NIST CSF 2.0.
- Translate identified cyber risk register items and audit findings into remediated engineering solutions.
- Support technical validation for penetration testing, red team exercises, and vulnerability assessments.
Required Experience
Core Requirements
- 8-12 years of progressive hands-on cybersecurity engineering and architecture experience.
- Proven experience working within a regulated financial services environment (Hedge Fund or Asset Management experience is highly advantageous).
- Demonstrated track record of designing and delivering complex, enterprise-grade security architectures across hybrid cloud environments.
- Strong collaborative history working alongside project management functions to drive technical initiatives to completion.
- Strong communication skills and ability to articulate business value of technical projects.
Technical Depth
- Microsoft Stack Mastery: Deep, expert-level implementation experience with the Microsoft E5 security suite, specifically Microsoft Defender for Endpoint, identity protection, and cloud security controls.
- Cloud Architecture: Advanced engineering knowledge of Azure Cloud Security, secure network design, and zero-trust architectures.
- Operations & Infrastructure: Robust understanding of SIEM/SOC engineering, automated vulnerability management programs, network segmentation, and modern patch/software deployment mechanisms.
Preferred Certifications
- Microsoft Certified: Azure Security Engineer Associate (AZ-500) or Microsoft 365 Certified: Security Administrator.
- CISSP, CCSP, or equivalent high-level security architecture certifications.
Personal Attributes
- Pragmatic Engineer: A strategic thinker who loves getting their hands dirty in the console; completely comfortable operating in a lean, fast-paced environment.
- Right-Sizing Mindset: Proven ability to balance rigorous security principles with operational realities, avoiding security friction or technical debt from over-engineering.
- Technical Influencer: Ability to communicate complex technical security concepts clearly to infrastructure engineers, application developers, and business stakeholders alike.
- Execution Focused: Highly organized, detail-oriented, and resilient under pressure.
How to apply
To apply for this job you need to authorize on our website. If you don't have an account yet, please register.
Post a resumeSimilar jobs
3108 Technical Support Officer (Science Laboratory) /Buangkok
Senior/Staff Nurse (Inpatient/Oncology/Palliative Care/Geriatrics/Gerontology)