Cyber Security Specialist (Application/Infrastructure/Cloud)

Posted 2 Days Ago
Be an Early Applicant
Singapore, SGP
In-Office
Senior level
Financial Services
The Role
Provide security architecture guidance across application, cloud, and infrastructure initiatives. Identify risks early, define mitigation strategies, maintain security standards and blueprints, conduct threat modelling and risk assessments, embed Zero Trust and secure-by-design principles, integrate controls into SDLC/CI-CD, review network controls, and support vulnerability management including container/image scanning.
Summary Generated by Built In
WHO WE ARE:

As Singapore’s longest established bank, we have been dedicated to enabling individuals and businesses to achieve their aspirations since 1932. How? By taking the time to truly understand people. From there, we provide support, services, solutions, and career paths that meet their individual needs and desires.

 Today, we’re on a journey of transformation. Leveraging technology and creativity to become a future-ready learning organisation. But for all that change, our strategic ambition is consistently clear and bold, which is to be Asia’s leading financial services partner for a sustainable future.

 We invite you to build the bank of the future. Innovate the way we deliver financial services. Work in friendly, supportive teams. Build lasting value in your community. Help people grow their assets, business, and investments. Take your learning as far as you can. Or simply enjoy a vibrant, future-ready career.

Your Opportunity Starts Here.

Why Join
Protecting our customers' assets and data is at the heart of everything we do at OCBC. As a Cyber Security Specialist, you'll play a critical role in safeguarding our systems and networks from cyber threats. You'll be part of a team that's shaping the future of cybersecurity in the financial industry.
How you succeed
To succeed in this role, you'll need to stay one step ahead of emerging threats. You'll work closely with our engineering teams to identify and mitigate risks, and develop strategies to protect our systems and data. You'll need to be proactive, collaborative, and always looking for ways to improve our cybersecurity posture.
What you do

  • Provide security architecture guidance to application, cloud (AWS, Azure, GCP, hybrid), and infrastructure initiatives from design through implementation and delivery.

  • Identify security risks early in the project lifecycle and define pragmatic, risk‑based mitigation strategies.

  • Translate business, regulatory, and technical requirements into secure, resilient, and scalable architectures.

  • Define, maintain, and govern security architecture standards, blueprints, and reference architectures across application, cloud, and infrastructure domains.

  • Embed security‑by‑design, Zero Trust, defense‑in‑depth, and least‑privilege principles across all solutions.

  • Conduct threat modelling, architectural risk assessments, and secure design reviews.

  • Integrate security controls into SDLC and CI/CD pipelines, supporting DevSecOps maturity.

  • Architect and review network and infrastructure security controls, including segmentation, firewalls, IDS/IPS, and related technologies.

  • Support vulnerability and exposure management, including container and image scanning tools (e.g., Red Hat ACS, Aqua, Trivy).

Who you are

More than 5 years of experience in security architecture, spanning application, cloud, and/or infrastructure security (cloud‑focused profiles may be considered with 5+ years of strong hands‑on experience).

Strong knowledge of:

  • Secure SDLC and DevSecOps practices

  • Application security concepts (OWASP Top 10, CWE; application threat modelling)

  • Cloud and infrastructure security architectures

  • API and microservices security patterns

  • Identity and access management and modern authentication protocols

  • Experience securing cloud‑native and containerised environments.

  •  Strong communication, stakeholder engagement, and advisory skills, with the ability to influence across technology and business teams.

  • One or more of: CISSP, CCSP, CSSLP, GWAPT (or equivalent)

  • Cloud security certifications such as:

    • AWS Certified Security – Specialty

    • Azure Security Engineer Associate

    • GCP Professional Cloud Security Engineer

Who we are
As Singapore's longest established bank, we have been dedicated to enabling individuals and businesses to achieve their aspirations since 1932. How? By taking the time to truly understand people. From there, we provide support, services, solutions, and career paths that meet their individual needs and desires.
Today, we're on a journey of transformation. Leveraging technology and creativity to become a future-ready learning organisation.
But for all that change, our strategic ambition is consistently clear and bold, which is to be Asia's leading financial services partner for a sustainable future.
We invite you to build the bank of the future. Innovate the way we deliver financial services. Work in friendly, supportive teams. Build lasting value in your community. Help people grow their assets, business, and investments. Take your learning as far as you can. Or simply enjoy a vibrant, future-ready career. Your Opportunity Starts Here.
 

What we offer:


Competitive base salary. A suite of holistic, flexible benefits to suit every lifestyle. Community initiatives. Industry-leading learning and professional development opportunities. Your wellbeing, growth and aspirations are every bit as cared for as the needs of our customers.

Skills Required

  • More than 5 years experience in security architecture across application, cloud, or infrastructure
  • Hands-on experience securing cloud-native and containerised environments
  • Strong knowledge of Secure SDLC and DevSecOps practices and integrating security into CI/CD pipelines
  • Knowledge of application security concepts, threat modelling, OWASP Top 10 and CWE
  • Designing cloud and infrastructure security architectures, including segmentation, firewalls, IDS/IPS
  • Experience with API and microservices security patterns
  • Experience with identity and access management and modern authentication protocols
  • Experience with container and image scanning tools (Red Hat ACS, Aqua, Trivy)
  • Strong communication, stakeholder engagement, and advisory skills
  • One or more certifications: CISSP, CCSP, CSSLP, GWAPT (or equivalent)
  • Cloud security certifications such as AWS Certified Security - Specialty, Azure Security Engineer Associate, GCP Professional Cloud Security Engineer
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Singapore
Year Founded: 1932

What We Do

OCBC is the longest established Singapore bank, formed in 1932 from the merger of three local banks, the oldest of which was founded in 1912. It is now the second largest financial services group in Southeast Asia by assets and one of the world’s most highly-rated banks, with an Aa1 rating from Moody’s. Recognised for its financial strength and stability, OCBC is consistently ranked among the World’s Top 50 Safest Banks by Global Finance and has been named Best Managed Bank in Singapore by The Asian Banker. OCBC and its subsidiaries offer a broad array of commercial banking, specialist financial and wealth management services, ranging from consumer, corporate, investment, private and transaction banking to treasury, insurance, asset management and stockbroking services. OCBC’s key markets are Singapore, Malaysia, Indonesia and Greater China. It has more than 570 branches and representative offices in 19 countries and regions. These include about 300 branches and offices in Indonesia under subsidiary Bank OCBC NISP, and over 90 branches and offices in Mainland China, Hong Kong SAR and Macau SAR under OCBC Wing Hang. OCBC’s private banking services are provided by its wholly-owned subsidiary Bank of Singapore, which operates on a unique open-architecture product platform to source for the best-in-class products to meet its clients’ goals. OCBC's insurance subsidiary, Great Eastern Holdings, is the oldest and most established life insurance group in Singapore and Malaysia. Its asset management subsidiary, Lion Global Investors, is one of the largest private sector asset management companies in Southeast Asia.

Similar Jobs

CSC Logo CSC

Senior Corporate Secretarial Associate

Fintech • Legal Tech • Software • Financial Services • Cybersecurity • Data Privacy
Remote or Hybrid
2 Locations
8500 Employees

CrowdStrike Logo CrowdStrike

Architect

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Hybrid
Singapore, SGP
11000 Employees

Micron Technology Logo Micron Technology

Principal Engineer

Artificial Intelligence • Hardware • Information Technology • Machine Learning
In-Office
Singapore, SGP
45000 Employees

Citadel Logo Citadel

Software Engineer

Information Technology • Software • Financial Services • Big Data Analytics
In-Office
5 Locations
4000 Employees
150K-300K Annually

Similar Companies Hiring

Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account