Key Responsibilities
1. Security by Design (Application & Platform)
- Integrate Application Security (SAST/DAST) into CI/CD pipelines and development workflows
- Partner with engineering teams to embed security controls into system design (shift-left security)
- Define secure coding and architecture standards across platforms
2. Cloud & Network Security
- Design and manage secure cloud environments (VPC, Subnets, VPN)
- Implement and drive Zero Trust Architecture
- Work closely with DevOps / Platform teams to strengthen infrastructure security
3. AI Security (Emerging Capability)
- Establish baseline practices for secure AI/ML usage within the organization
- Identify risks related to AI adoption (e.g., data leakage, model misuse, prompt risks)
- Work with data teams to ensure secure data pipelines and model lifecycle governance
4. Identity, Access & Data Protection
- Govern IAM policies based on Least Privilege principles
- Ensure proper encryption (at rest & in transit) and Key Management practices
- Protect sensitive data across applications and AI-related workflows
5. Compliance, Risk & Governance
- Align security practices with relevant standards (e.g., ISO 27001, PDPA)
- Develop internal policies and controls for both Cybersecurity and AI usage
- Support audits and internal risk assessments
6. Build & Lead AI Security Capability
- Define team structure, roles, and hiring roadmap for AI Security
- Act as the go-to expert for security-related topics across teams
- Upskill engineering and data teams on secure practices (not just enforce, but enable)
Qualification
- 5+ years of experience in Cybersecurity (Application / Cloud / Network Security
- Strong hands-on experience with Application Security (SAST/DAST
- Cloud Security (AWS / Azure / GCP)IAM, Encryption, Key Management
- Experience working with engineering or DevOps teams in real environment
- Ability to design practical, scalable security solutions (not only policy-level)Exposure to AI / Data / ML workflow
- Experience in DevSecOps or modern CI/CD environment
- Familiarity with AI-related risks or data governance
Certifications
- CISM,
- CISSPCEH
- Cloud Security