Job Description
Working Hours: Monday – Thursday (8.30am – 6pm), Friday (8.30am – 5.30pm) (Hybrid working arrangement)
Working Location: Clarke Quay
Salary Package: Up to SGD 11,000 + AWS
Employment Type: Full-time Contract (2 years renewable with chances of conversion)
We are seeking a Principal Security Architect to lead threat modelling and risk assessment transformation for our hybrid infrastructure environments whilst pioneering security frameworks for emerging AI implementations. This role moves beyond compliance-driven checklists to conduct architecture-based threat analysis across on-premises, cloud, and hybrid systems, with additional responsibility for developing AI security assessment capabilities. The successful candidate will partner with engineering teams to identify technical attack paths and establish security practices for our evolving AI technology landscape.
Key Responsibilities
- Advanced Threat Modelling: Lead comprehensive threat modelling exercises for complex hybrid infrastructure using established frameworks such as STRIDE, or MITRE focusing on technical attack path analysis rather than compliance verification.
- Cross-Environment Risk Assessment: Conduct deep-dive security assessments spanning on-premises legacy systems, public cloud environments, and SaaS integrations, identifying trust boundary weaknesses and potential breach scenarios.
- Architecture Security Review: Collaborate with engineering teams to analyse system architecture diagrams, data flow diagrams, and Infrastructure as Code templates to identify security design flaws and misconfigurations before implementation.
- AI Security Framework Development: Develop and implement threat modelling approaches for generative AI systems, autonomous agents, and AI-integrated applications, establishing security assessment methodologies for emerging AI technologies within our organisation.
- Attack Surface Analysis: Map potential lateral movement paths between legacy and modern environments, including AI-enhanced systems, identifying how compromised systems could escalate privileges or access sensitive resources across the hybrid estate.
- Technical Risk Translation: Partner with project managers and development teams to convert high-level security risks into specific technical vulnerabilities with clear remediation guidance and implementation priorities.
- Security Design Consultation: Provide architectural security guidance for new systems and major infrastructure changes, including AI implementations, ensuring security controls are embedded into design rather than retrofitted post-deployment.
Requirements
- Infrastructure Architecture Expertise: Comprehensive knowledge of enterprise infrastructure architectures including on-premises systems, public cloud platforms (AWS/Azure), networking protocols, and identity management systems.
- Cloud Security Mastery: Deep understanding of cloud-native security services, identity and access management, network segmentation, serverless architectures, and cloud security best practices across major platforms.
- Infrastructure as Code Proficiency: Ability to analyse and interpret Terraform, CloudFormation, ARM templates, or similar IaC technologies to understand intended system architectures and identify potential security gaps.
- Threat Modelling Frameworks: Proven experience applying structured threat modelling methodologies such as STRIDE, MITRE to complex enterprise systems and architectures.
- AI Security Awareness: Foundational understanding of AI/ML security concepts, including prompt injection risks, model security, and emerging AI threat landscapes, with willingness to develop specialised expertise in AI security assessment.
- Systems Engineering Background: Experience in systems engineering, security architecture, or infrastructure design with demonstrated expertise in enterprise-scale environments.
- Risk Assessment Methodology: Strong analytical skills in conducting technical risk assessments, vulnerability analysis, and security control effectiveness evaluation across traditional and emerging technology stacks.
By submitting your resume, you consent to the collection, use, and disclosure of your personal information per ScienTec’s Privacy Policy (scientecconsulting.com/privacy-policy).
This authorizes us to:
- Contact you about potential opportunities.
- Delete personal data as it is not required at this application stage.
- All applications will be processed with strict confidence. Only shortlisted candidates will be contacted.
Wong Siew Ting (Maeve) - R25127375
ScienTec Consulting Pte Ltd - 11C5781