{"id":1251114,"url":"https://alion.io/job/time-dotcom-principal-security-architect-git","title":"Principal Security Architect (GIT)","company":{"id":49623,"name":"TIME dotCom","domain":"time.com.my","url":"https://alion.io/company/time-dotcom","size_band":"501-1000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"SuccessFactors","truth_index":null},"role":"Security","role_family":"Security","seniority":"lead","employment_type":null,"work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"inferred","locations":[],"countries":[],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":20000,"max_usd":52000,"period":"year","method":"global_role_cell_scaled_by_country","sample_n":330},"experience_years_min":12,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"CI/CD","optional":false},{"name":"DLP","optional":false},{"name":"ISO 27001","optional":false},{"name":"Microsoft Entra ID","optional":false},{"name":"MITRE ATT&CK","optional":false},{"name":"MITRE D3FEND","optional":false},{"name":"NIST CSF","optional":false},{"name":"Rest API","optional":false},{"name":"SBOM","optional":false},{"name":"SIEM","optional":false},{"name":"STRIDE","optional":false},{"name":"Threat Modeling","optional":false},{"name":"Zero Trust","optional":false},{"name":"Zscaler","optional":false}],"status":"live","first_seen_at":"2026-09-16T02:00:00Z","employer_posted_date":"2026-09-16","last_verified_at":"2026-09-25T19:11:11Z","board_verified":false,"closed_at":null,"days_open":12,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":12},"description":"Position Overview\nLead the design of security architectures and standards across applications, infrastructure, cloud, and data. Act as technical lead in projects to ensure secure-by-design outcomes and oversee implementation quality. Partner closely with SOC and GRC to embed architecture controls, reduce systemic risk, and ensure alignment with NIST CSF 2.0 and Malaysian regulatory standards (NACSA, MCMC, Cyber Security Act 2024).\nRoles & Responsibilities\n Enterprise Architecture & StrategyDefine enterprise security architecture patterns (network, identity, application, cloud, data).\nDevelop reference designs for core controls: SIEM/SOAR, CNAPP, DLP/CASB, PAM, zero trust, endpoint security, API security.\nMaintain security standards and design baselines mapped to NIST CSF 2.0 and internal policies.\n\n Project EngagementTranslate business and regulatory requirements (PDPA, NACSA/MCMC) into technical guardrails. \nReview solution designs and conduct technical risk assessments.\nProvide hands-on guidance during build-e.g., IaC guardrails, identity design, secret management, workload hardening.\n\nArchitecture Governance:Chair/participate in Security Design Reviews and drive remediation plans.\nCreate and maintain Design Decision Records and reusable patterns.\nSign off on security non-functionals for new solutions to ensure consistency and compliance.\n\nTechnologyLifecycle ManagementLead the 12-36 month security capability roadmap, including evaluating emerging technologies and running PoCs to validate solutions.\nSet configuration baselines, tagging standards, and onboarding patterns for new apps/services.\n\nCross-Functional CollaborationWork with SOC for use case design, log onboarding and detection coverage. \nWork with GRC for control testing and exception management. \nAdvise DevOps/Cloud teams on CI/CD security, SAST/DAST/IAST, SBOM, supply-chain risk.\n\nYour Traits\nStrategic Thinking & Problem Solving: Demonstrated ability to align security architecture with long-term business goals while providing practical solutions to complex technical challenges.\nStakeholder Management & Communication: Excellent interpersonal skills with the ability to communicate technical security concepts to both technical and non-technical audiences, including senior leadership.\nTechnical Leadership & Influence: Proven track record of leading cross-functional teams and driving consensus on security standards and design decisions without direct formal authority.\nContinuous Learning & Agility: A proactive mindset regarding the evolving threat landscape, with a commitment to staying current on emerging security technologies, frameworks, and regulatory requirements.\nAttention to Detail & Analytical Rigor: A methodical approach to conducting risk assessments and reviewing solution designs to ensure no security gaps are overlooked.\nYour Merits\nExperience: 12+ years in security engineering/architecture; led security design for complex systems, multi-cloud or cloud migrations.\nTechnical Depth:Identity & Access: Entra ID, MFA/SSO, Conditional Access, PAM.\nCloud security (Azure/AWS): Micro-segmentation, Landing Zones, CNAPP, KMS, secrets, workload identity.\nApp/API security: OAuth/OIDC, mTLS, WAF, rate limiting, SDLC integration.\nData protection: DLP/CASB, classification, encryption-at-rest/in-transit, key management.\nInfra: Endpoint hardening, EDR, vulnerability management, patch orchestration.\n\nMethodologies: Threat Modeling, STRIDE, attack trees, reference architecture, Zero Trust Architecture, MITRE ATT&CK and D3FEND.\nCertifications: CISSP or CISM with ISO 27001 and TOGAFSpecialized: CCSP, Azure Security Architect (AZ-305/SC-100), AWS Security Speciality, CSSLP, SABSA, Google Professional Cloud Security Engineer, CCNP, Zscaler, GIAC GDSA/GCSA\n\nOur Commitment to You\nAt Time, we believe great work deserves great support. Here’s what you can look forward to when you join us:\nComprehensive medical coverage for you and your immediate family, including outpatient care, hospitalisation, dental and optical benefits.\nWellness support with an annual spending account for health-related needs, alternative treatments, or even paid-up premiums for personal insurance.\nEmployee assistance during life’s big moments, from celebrations to times of bereavement.\nLearning & growth opportunities through dedicated time for learning, access to LinkedIn Learning and rewards for upskilling.\n Cash rewards for recognised certifications and full reimbursement for up to two approved professional memberships each year.\n*Only shortlisted candidates will be notified.","description_format":"text","description_chars":4577,"description_truncated":false,"requirements":{"experience_years_min":12,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":["Continuous learning","Growth opportunities"],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Cybersecurity","Telecommunications","Broadband"],"lifecycle":[{"event":"open","at":"2026-09-25T18:32:08Z"}],"liveness":{"score":69,"band":"ok","label":"Likely open","p_open":0.9,"p_active":0.847,"p_room":0.9,"age_days":12,"expected_fill_days":34,"reasons":["conf:58","velocity","win:mid"],"computed_at":"2026-09-28T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/time-dotcom-principal-security-architect-git","json_url":"https://alion.io/job/time-dotcom-principal-security-architect-git.json","meta":{"generated_at":"2026-09-28T06:11:25Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":4308,"day_limit":5000,"remaining_today":692,"minute_limit":60,"resets_at":"2026-09-29T00:00:00Z"}}}