699,089open jobs
41,455companies
98,822added this week
Browse all
Salary
$94k – $242k per year (Estimated)
Location
In office (Singapore)
Seniority
Architect
Employment
Full-Time
Overview
Company
Impact
Profile match
Dyson is a technology company founded in 1991 by James Dyson after he built more than five thousand prototypes of a bagless vacuum cleaner that no established manufacturer would license. It applies high-speed digital motors and airflow engineering across vacuum cleaners, hair care products including the Supersonic and Airwrap, air purifiers, lighting and headphones, and sells almost entirely direct to consumers at premium prices. The company moved its head office from Wiltshire to Singapore in 2019 to sit closer to its Asian manufacturing and markets, remains privately held by the Dyson family, and funds an engineering university at its Malmesbury campus.

About us

At Dyson, we are not just creating innovative, technology-enabled products; we are also breaking new ground in cybersecurity. Our products are becoming more advanced and interconnected, which means we face a constantly evolving cyber threat landscape. This requires a highly skilled candidate to join our team, with a passion for staying ahead of emerging threats and keeping our products secure.

We take a proactive approach to cybersecurity. We do not wait for threats to emerge; we anticipate them and respond with innovative solutions. This means that at Dyson, you will have the opportunity to work with innovative technologies, like artificial intelligence and machine learning, to protect our products and customers.

You will be part of a team of cybersecurity experts, utilizing the latest tools and technologies to identify and respond to threats in real-time. You will work closely with our engineering and product teams to ensure that security is integrated into every aspect of our business.

Join our team at Dyson, and you will be at the forefront of cybersecurity, working on some of the most innovative and advanced products in the industry. You will have the opportunity to develop your skills and knowledge, collaborating with a talented team of experts to ensure we are always secure. If you are passionate about cybersecurity and looking for an exciting and challenging role, Dyson is the place for you.

About the role

As Principal Cybersecurity Architect for Application Security and DevSecOps, you will be the senior architecture authority for security across Dyson's digital application landscape, including eCommerce, customer and ownership experiences, mobile applications, APIs and supporting cloud-native services.

You will define reusable security architectures, patterns and guardrails, and help establish a scalable DevSecOps capability that embeds proportionate security controls throughout the software development lifecycle. You will work with engineering teams to make secure delivery repeatable, measurable and developer-friendly, while retaining clear risk ownership and governance.

What you will do

  • Set the application security and DevSecOps architecture direction, translating enterprise risk appetite and security policy into practical target architectures, principles, standards, patterns and control objectives.
  • Provide authoritative security advice across web, mobile, API, microservices, serverless and cloud-native architectures, balancing security, resilience, customer experience, delivery speed and cost.
  • Lead security architecture reviews and risk assessments from discovery through design, build, release and operation. Record design decisions, material risks, required controls, exceptions and residual risk in an audit-defensible manner.
  • Facilitate threat modelling using fit-for-purpose techniques such as STRIDE, attack trees, abuse cases and data-flow analysis. Ensure identified threats are translated into owned engineering requirements and verified mitigations.
  • Design and govern reusable security patterns for identity and access, session management, API protection, secrets, encryption, key and certificate use, tenant isolation, input and output handling, logging, monitoring and secure failure modes.
  • Define the DevSecOps control framework and reference pipeline, including policy-as-code, security quality gates, risk-based thresholds, exception workflows, evidence capture and feedback loops across CI/CD.
  • Guide the integration and effective use of security testing capabilities, including SAST, DAST, software composition analysis, secrets scanning, infrastructure-as-code scanning, container and image scanning, API security testing, mobile testing and penetration testing.
  • Strengthen software supply-chain security by defining expectations for dependency governance, software bills of materials, provenance and integrity, artifact signing, trusted build environments and third-party component risk.
  • Partner with engineering enablement and platform teams to create secure-by-default paved roads, templates and reusable controls that reduce friction and prevent recurring vulnerabilities.
  • Establish vulnerability triage and remediation models that include severity, exploitability, business context, ownership, service-level expectations, risk acceptance and verification of closure.
  • Develop application security metrics and capability measures covering control coverage, effectiveness, engineering adoption, security debt, remediation performance and recurring defect patterns. Use evidence to prioritise improvement.
  • Build capability through security champions, role-based training, coaching, communities of practice and practical guidance for architects, developers, testers, product managers and platform engineers.
  • Act as a trusted partner to Cyber Security and Risk, Digital, Engineering and Technology stakeholders. Provide technical leadership to virtual teams and suppliers, assure delivery quality and support effective transition into operations.
  • Support the investigation and resolution of significant application security incidents, vulnerabilities and control failures, converting lessons learned into improved patterns, guardrails and engineering practices.

About you

You are an experienced application security architect who can operate at both strategic and technical depth. You can define a target state, influence senior stakeholders and work directly with engineering teams to make security controls effective in real delivery environments.

To succeed in this role you should,

· Extensive experience in application security, security architecture or secure software engineering, with demonstrable ownership of complex, enterprise-scale outcomes.

· Strong knowledge of secure software design and the software development lifecycle across web, mobile, API, microservices and cloud-native services.

· Practical experience designing or maturing DevSecOps capabilities and integrating security controls into modern CI/CD platforms and developer workflows.

· Deep understanding of common application and API threats, including the OWASP Top 10 and OWASP API Security Top 10, and the ability to translate weaknesses into design and engineering controls.

· Hands-on understanding of SAST, DAST, software composition analysis, secrets scanning, infrastructure-as-code scanning, container and image scanning and security test automation, including tuning, coverage, false-positive management and quality gates.

· Strong threat-modelling and security-risk-assessment skills, including the ability to model trust boundaries, data flows, abuse paths and compensating controls.

· Experience with identity protocols and application security controls, including OAuth 2.0, OpenID Connect, SAML, token handling, authorisation design, session security, secrets and cryptographic key management.

· Knowledge of cloud and container security concepts across at least one major cloud platform, with sufficient breadth to assess Kubernetes, serverless, API gateways, service-to-service communication and infrastructure as code.

· Working knowledge of software supply-chain controls, including dependency governance, SBOMs, artifact integrity, signing, provenance, build-pipeline security and third-party component risk.

· Ability to read and challenge code, configuration and pipeline definitions. Proficiency in at least one relevant language such as Python, Java, JavaScript or TypeScript, C# or Go, plus practical use of REST or GraphQL APIs, JSON, YAML and scripting for automation.

· Experience defining architecture documentation, security requirements, patterns, technical standards, low-level designs and risk decisions that are clear to both engineers and governance stakeholders.

· Strong communication, facilitation and influencing skills, with the ability to explain technical risk, trade-offs and required decisions to engineering teams and senior leaders.

· Ability to work independently, lead through influence and coordinate multidisciplinary internal teams and external partners.

· Experience establishing security-champion networks, developer security education or product security communities of practice.

· Experience with web application and API protection services, including WAF policy design, bot management, rate limiting and carefully governed virtual patching, without treating perimeter controls as a substitute for remediation.

· Experience defining control evidence and metrics for regulated, high-assurance or audit-sensitive environments.

· Knowledge of mobile application security testing, secure mobile design and relevant OWASP mobile guidance.

· Relevant certifications such as ISC2 CSSLP, CISSP, GIAC secure software credentials or cloud security certifications. Certifications are valued as supporting evidence, not a substitute for demonstrated practical capability.

Dyson is an equal opportunity employer. We know that great minds don’t think alike, and it takes all kinds of minds to make our technology so unique. We welcome applications from all backgrounds and employment decisions are made without regard to race, colour, religion, national or ethnic origin, sex, sexual orientation, gender identity or expression, age, disability, protected veteran status or other any other dimension of diversity.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
699,089 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Singapore
In office • 2+ years exp • Almaty
Go
JavaScript
TypeScript
SQL
C#
Databases
PostgreSQL
Redis
ClickHouse
ElasticSearch
Apache Kafka
Frontend
React.js
DevOps
Rest API
gRPC
CI/CD
Docker
Kubernetes
SOAP
Cybersecurity
Keycloak
Management
BPMN
QA
Swagger
Apply
$15k – $37k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • Bengaluru
JavaScript
TypeScript
SQL
Frontend
React.js
DevOps
Rest API
CI/CD
Jenkins
Git
Management
Agile
QA
Selenium
Cucumber
Playwright
Postman
Rest-Assured
Apply
$13k – $34k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Bengaluru
Python
JavaScript
Java
Node JS
DevOps
Git
Management
Confluence
Agile
Scrum
Apply
QA Playwright 4 hours ago
In office • Full-Time • Bengaluru
JavaScript
TypeScript
DevOps
Azure DevOps
GitHub Actions
Azure
CI/CD
Jenkins
Git
Bitbucket
GitHub
Management
Jira
Agile
QA
Playwright
Postman
Rest-Assured
Apply
$28k – $59k per year (Estimated) • Remote/Hybrid • Moscow
Python
SQL
Databases
PostgreSQL
Apache Kafka
Mobile
Clean Architecture
DevOps
Rest API
gRPC
CI/CD
Apply
$98k – $253k per year (Estimated) • In office • Full-Time • Singapore
AI/ML
LLM Guardrails
Machine Learning
Cybersecurity
SIEM
DLP
Apply
$28k – $59k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • Shenzhen
Design
Adobe Photoshop
Management
Agile
Apply
$39k – $92k per year (Estimated) • In office • Full-Time • 8+ years exp • Bachelor's Degree • Shanghai
Apply
Product Test Engineer 7 hours ago
$31k – $80k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Shenzhen
Python
Java
DevOps
RTOS
Apply
$26k – $63k per year (Estimated) • In office • Full-Time • 8+ years exp • Philippines
MATLAB
Chips/EDA
LTspice
HyperLynx
Apply
$105k – $232k per year (Estimated) • In office • Singapore
Apply
$32k – $62k per year (Estimated) • In office • Internship • Singapore
Apply
$58k – $128k per year (Estimated) • In office • Full-Time • 5+ years exp • Singapore
Management
Microsoft Office
Apply
In office • Full-Time • Singapore
Python
Analytics
Power BI
Apply
$38k – $112k per year (Estimated) • In office • Full-Time • 3+ years exp • Singapore
Apply
See all jobs
This is one of many
699,089 more open roles from verified company boards, updated every day.