jobs in Maybank

Maybank Hiring! Full Time Cloud Security Architect I IT Security in Federal Territory - Ricebowl

Cloud Security Architect I IT Security

Undisclosed

KL City, Federal Territory

Share
Save

Working Location

  • Kuala Lumpur Federal Territory Malaysia

Job Description

Responsibilities

Job Purposes

  • The Cloud Security Architect serves as the subject matter expert for cloud's application, workload, and cloud-native security architecture across the Bank. The role designs and validates secure cloud and application environments, embedding controls across workloads, containers, automation pipelines, and DevSecOps practices. Working closely with development, cloud, and operations teams, the architect ensures solutions are secure by design and consistently implemented across multi-cloud and hybrid deployments.
  • The role supports the enterprise security strategy by converting cloud and application objectives into actionable controls and measurable outcomes. Through posture assessments, the architect defines security baselines for workloads, applications, and automation, ensuring that risks from emerging cloud-native technologies are identified early and addressed through structured improvement programs.
  • As the Bank’s representative in cloud and application solutioning forums, the CSA provides domain expertise to ensure secure design adoption across development, automation, and platform engineering. The role validates that cloud security tooling and governance frameworks integrate effectively across environments and align with enterprise architecture principles.
  • The architect contributes to enterprise-level programs such as Cyber Defense, Zero Trust, and technology modernization by embedding security practices within cloud transformation initiatives. It ensures that security automation, container governance, and application controls are designed to scale consistently across regions and environments.
  • In the area of risk and compliance, the CSA identifies and quantifies risks across cloud, app, and DevSecOps domains, ensuring exposures are mapped to regulatory obligations and enterprise frameworks. The role provides actionable recommendations to mitigate control gaps and strengthen compliance assurance in dynamic, continuously integrated environments.
  • During project execution, the CSA ensures cloud and application projects incorporate required security controls from design through deployment. It validates implementations across services, pipelines, and containers, ensuring consistent adherence to architecture standards and enterprise security models.
  • The architect also evaluates cloud and application security tools for their fit, scalability, and integration efficiency within the enterprise environment. It provides structured assessments and recommendations to maintain an optimized, cohesive security technology stack.
  • As a change agent, the CSA contributes to workshops and process clinics aimed at integrating security into agile and DevSecOps workflows. The architect advocates for secure coding, automation patterns, and pipeline standardization, ensuring security is built into everyday development practice.
  • Secure implementation is achieved by validating governance, workload protection, and automation controls, ensuring each deployment meets enterprise baselines and feeds lessons learned back into continuous improvement cycles.
  • Finally, the CSA provides expert advisory on cloud and application architecture decisions. The role evaluates alternative designs, balancing security, efficiency, and sustainability, and ensures selected solutions align with enterprise security principles and modernization strategies.


Job Responsibilities

  • Design and validate cloud security architecture covering workloads, applications, containers, and platform services.
  • Collaborate with development, operations, and cloud platform teams to embed secure patterns into delivery pipelines.
  • Provide authority on secure integration of cloud-native and application-level security tools, ensuring automation and consistency across multi-environment deployments.
  • Support the cloud security strategy by defining measurable controls for applications, workloads, and development pipelines.
  • Apply posture assessments to refine requirements for container security, application security, and automation.
  • Anticipate risks from emerging cloud-native practices and technologies, ensuring architectural designs account for secure adoption while aligning with enterprise direction.
  • Represent cloud and application security in solutioning forums, ensuring cloud adoption and application development align with secure design patterns.
  • Provide specialist input on cloud security automation, container governance, and application-level assurance.
  • Validate that cloud security tooling integrates effectively across environments and aligns with security reference models.
  • Contribute to enterprise programs by embedding cloud-native controls, application security, and DevSecOps practices into technology modernization and transformation initiatives.
  • Provide architectural expertise to ensure security tooling is integrated consistently into programs.
  • Monitor adoption of new cloud-related technologies and define how they are secured within enterprise environments.
  • Identify and assess risks in cloud, application, and container environments, with focus on governance, automation, and development practices.
  • Quantify exposures and communicate risks in business terms.
  • Ensure controls for DevSecOps, application security, and automation are embedded into architecture to maintain compliance and reduce residual risk.
  • Ensure cloud and application projects embed security from design to deployment.
  • Validate that controls for cloud services, applications, and containers are implemented consistently, with automation where appropriate.
  • Provide authoritative guidance where gaps or misalignments are identified, ensuring secure and scalable outcomes.
  • Evaluate cloud and application security solutions to determine how they fit into governance, automation, and development practices.
  • Provide detailed assessments of how proposed security tools align with architectural patterns and enterprise requirements, and recommend solutions that aligned with cloud security architecture and operating models.
  • Support change in cloud and application domains by contributing to improvement-focused workshops and process clinics.
  • Provide detailed input on embedding security into development, automation, and operational practices. Advocate for secure design patterns that become part of standard workflows in cloud and application delivery.
  • Validate secure implementation in cloud and application environments by ensuring governance, workload protection, and automation controls are consistently applied.
  • Confirm security requirements are embedded in delivery practices and provide detailed feedback that drives continuous improvement in future deployments.
  • Provide advisory for cloud and application projects by analyzing business requirements and recommending secure architecture choices.
  • Evaluate alternatives for governance, application delivery, and automation models and propose the most effective approach that balances security, efficiency, and sustainability.


Job Requirements

  • Bachelor’s Degree in Computer Science, Information Security, Software Engineering, or a related field. Advanced studies or specialization in Cloud Computing or Cybersecurity is advantageous.
  • Minimum 8–10 years of experience in IT security, together with cloud & application security, or DevSecOps, preferably within a regulated or financial services environment.
  • At least 5 years’ hands-on experience designing or engineering secure cloud architectures, workloads, and automation pipelines.
  • Minimum 3 years’ exposure to cloud-based security platforms and enterprise security tools.
  • Demonstrated expertise integrating application and container security within modern CI/CD ecosystems and ensuring compliance with industry standards.
  • Preferred certifications include CCSP, AWS Certified Security Specialty, Azure Security Engineer Associate, or Google Cloud Security Engineer. Complementary credentials such as CISSP, CISM, or DevSecOps/Container Security (GIAC, Kubernetes Security Specialist) are a plus.

Important Information

Never provide your bank or credit card details when applying for jobs. Do not transfer any money or complete unrelated online surveys. If you see something suspicious, Report this Job ad.

Learn More