Menu

Principal – Workspace Security Architecture and Engineering

Summary

Salary
Competitive
Job Family
Cyber Security
Location
Singapore - Technology Centre
Principal – Workspace Security Architecture and Engineering Role: Principal Workspace Security Architecture and Engineering Reporting to: Chief Information Security Officer Role type: Manager Role Purpose As the Principal Workplace Security Architect, you are accountable for defining and driving the end-to-end workplace security strategy, architecture, technology roadmap, and governance across end-user computing, collaboration, identity, and communications platforms globally. Operating as a strategic Individual Contributor and Technical Design Authority, you will lead the adoption of Zero Trust principles across workforce technologies. By establishing robust security standards and reference architectures, you will proactively reduce cyber risk, guide platform engineering execution, and ensure that workplace capabilities are secure-by-design. In this role, you will lead and manage the following domains: • Workplace Security Strategy & Governance: Defining enterprise-wide workplace security policies, architectural standards, and governance frameworks. • Zero Trust & Target Architecture: Designing reference architectures and driving Zero Trust adoption across all end-user technologies. • Technical Design Authority: Serving as the final technical authority for workplace security controls, architectural patterns, and design reviews. • Security Roadmap & Investment: Owning long-term security roadmaps, technology selections, and risk-reduction investment plans. • Cross-Functional Security Alignment: Partnering with platform engineering teams to embed secure-by-design principles throughout IT delivery. Key Skills & Qualifications Bachelor's degree in cyber security, Information Technology, Computer Science, or a related discipline (or equivalent practical experience). A minimum of 7–10 years’ experience in cybersecurity, with a strong focus on vulnerability management, security operations, or risk management within enterprise environments. Demonstrated experience operating and improving vulnerability management programmes at scale, including ownership of tooling, governance, and remediation outcomes. Relevant industry certifications (e.g. CISSP, CISM, CRISC, GIAC) are highly desirable, along with proven experience engaging senior stakeholders, managing cross functional delivery, and aligning security outcomes to business risk and priorities. Vulnerability Management & Security Expertise Strong understanding of the end to end vulnerability management lifecycle, including discovery, assessment, prioritisation, remediation, and validation. Strong grasp of remediation assurance activities of common vulnerabilities (e.g. CVEs, OWASP, configuration weaknesses) and how they manifest across infrastructure, cloud, endpoint, and application environments, with the ability to apply risk based thinking to reduce exposure. Tooling & Technical Proficiency Hands on experience with vulnerability management platforms such as Qualys, Tenable, or Rapid7, including asset discovery, agent based and network scanning, and scan optimisation. Ability to interpret scan outputs, manage false positives, tune scan policies, and integrate with CMDB and ITSM platforms (e.g. ServiceNow) to ensure accurate and actionable results. Risk Management & Prioritisation Ability to assess, quantify, and articulate cyber risk in business terms, leveraging frameworks such as NIST or ISO. Skilled in risk based prioritisation that combines asset criticality, exploitability, and threat intelligence to ensure remediation efforts are focused on the highest impact vulnerabilities. Governance, Process & Control Design Experience designing and embedding scalable vulnerability management policies, standards, and procedures aligned to audit and compliance expectations. Strong understanding of control frameworks, with the ability to manage exceptions, risk acceptance, and compensating controls in a structured and defensible manner. Service Delivery & Operational Management Proven capability in running a large scale security service, including managing SLAs, KPIs, backlog, and remediation workflows. Able to drive consistent service performance, ensure high scan coverage and quality, and enforce accountability across distributed engineering and infrastructure teams. Data Analysis, Reporting & Insight Strong analytical skills to interpret vulnerability data, identify trends, and generate actionable insights. Ability to develop clear reporting and dashboards for both technical and executive audiences, using metrics such as MTTR, SLA adherence, and exposure windows to drive continuous improvement. Stakeholder Management & Influence Highly effective communicator with the ability to engage, influence, and challenge both technical and non technical stakeholders. Skilled in translating technical findings into business impact, driving remediation accountability, and building strong relationships across infrastructure, product, and risk domains. Threat Intelligence Integration Understanding of how to integrate cyber threat intelligence into vulnerability management processes, including awareness of actively exploited vulnerabilities and attacker tactics. Ability to collaborate with CTI teams to ensure prioritisation reflects real world threat activity and emerging risks. Leadership & People Management Experience leading and developing teams, setting priorities, and managing competing demands. Strong decision making capability, with a focus on building team capability, improving performance, and fostering a culture of accountability and continuous improvement. Continuous Improvement & Automation A continuous improvement mindset with a focus on optimising processes, increasing automation, and reducing manual effort. Experience identifying opportunities to enhance workflows, tooling integration, and efficiency through scripting, APIs, or process redesign. Key Accountabilities Key Skills & Qualifications Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related discipline (or equivalent practical experience). A minimum of 7–10 years' experience in cybersecurity, with a strong emphasis on enterprise security architecture, end-user security, and Zero Trust frameworks. Demonstrated experience establishing enterprise workplace security strategies and leading complex security transformations across global organizations. Industry certifications such as CISSP, ISSAP, SABSA, or Microsoft Cybersecurity Architect (SC-100) are highly desirable. Security Expertise & Architecture Deep understanding of end-to-end workplace security architecture, Zero Trust maturity models, and modern secure design principles across identities, endpoints, and cloud collaboration suites. Tooling & Technical Proficiency Deep architectural proficiency in Microsoft Entra ID, Defender Suite, Microsoft 365, Exchange Online, Microsoft Teams, Conditional Access, Intune, and JAMF. Risk Management & Prioritisation Ability to quantify cyber risk within end-user computing and translate technical security posture into clear business context for senior executives. Governance, Process & Control Design Proven experience defining security standards, reference patterns, and control requirements aligned to enterprise risk tolerances and regulatory frameworks. Service Delivery & Operational Management Ability to guide security engineering priorities, oversee architectural review lifecycles, and maintain consistency across complex operational environments. Data Analysis, Reporting & Insight Skill in analyzing security telemetry and enterprise architecture coverage metrics to demonstrate systemic risk reduction and security debt clearance. Stakeholder Management & Influence Exceptional ability to influence and challenge senior stakeholders, engineering leads, and business partners to align technology choices with security architectures. Threat Intelligence Integration Ability to apply threat intelligence and modern adversary tactics to workplace architecture designs, neutralizing emerging attack pathways. Leadership & Strategic Direction Proven capability to provide technical leadership, mentor senior engineers, set architectural direction, and foster a culture of security engineering excellence. Continuous Improvement & Automation A continuous improvement mindset with a focus on embedding security-as-code and automated compliance guardrails into workplace deployment pipelines. Success Measures Workplace Security Strategy & Governance • Accountability: Define, maintain, and enforce workplace security strategies, target architectures, reference patterns, and security governance standards. • Success Measures: 100% alignment of workplace technology designs with enterprise Zero Trust architecture patterns; High compliance and zero major architectural non-conformances during audit reviews. Technical Design Authority & Architecture Review • Accountability: Serve as the final technical authority for workplace security choices, conducting design reviews for all workspace engineering projects. • Success Measures: 100% of major workplace technology changes reviewed and approved through the technical design authority process; Zero high-risk unmitigated architectural flaws introduced into production workspace environments. Secure-by-Design & Platform Alignment • Accountability: Partner directly with modern workplace platform engineering teams to integrate secure-by-design baseline standards into build pipelines. • Success Measures: Measurable structural reduction in workplace vulnerability and misconfiguration surface area; High satisfaction and strong operational alignment scores from partner platform engineering teams. Security Roadmap & Investment Management • Accountability: Maintain and execute the workplace security roadmap, aligning security technology investments to overall risk reduction targets. • Success Measures: Delivery of key security roadmap milestones on schedule and within budget; Quantifiable reduction in global workplace cyber risk posture.


Dyson is an equal opportunity employer. We know that great minds don’t think alike, and it takes all kinds of minds to make our technology so unique. We welcome applications from all backgrounds and employment decisions are made without regard to race, colour, religion, national or ethnic origin, sex, sexual orientation, gender identity or expression, age, disability, protected veteran status or other any other dimension of diversity.

Awards & Accreditations