jobs in ST ENGINEERING ENTERPRISE DIGITAL PTE. LTD.

全职 AVP, Technology Risk - Security 工作, 薪水 up to SGD 12,000, ST ENGINEERING ENTERPRISE DIGITAL PTE. LTD. Central Region (Singapore) 公司招聘中 - Ricebowl

AVP, Technology Risk - Security

ST ENGINEERING ENTERPRISE DIGITAL PTE. LTD.

SGD12,000 - SGD12,000 每月

Central Region (Singapore)

分享
保存

工作地点

  • 3 ANG MO KIO ELECTRONICS PARK ROAD Central Region (Singapore) Singapore

职位描述

岗位职责

Enterprise Digital designs, builds, deploys, and sells a diverse portfolio of technology products across financial services, healthcare, and the public sector, spanning AI, quantum-safe systems, data centre infrastructure, and contact centre solutions. This role embeds security and technology risk directly into that life cycle as a Line 1 function.

The role works within the product, project, and presales teams to ensure that security is built into products as they are designed, implemented securely in client environments, and credibly assured to customers during the sales cycle. It operates against internal security and GRC standards and policies, translating those requirements into practical execution at the point of build, deployment, and sale.

Product team

01   Product security

Embed security into the design and development of Enterprise Digital products across their architecture, build, testing, and deployment stages.

·    Provide secure architecture input during product design, identifying security requirements and risks before development begins

·    Conduct threat modelling on product architectures to surface design-level vulnerabilities and define mitigations

·    Advise engineering teams on secure coding practices and secure-by-design principles appropriate to each product's technology stack

·    Coordinate product security testing within the existing change and SDLC process, acting as the interface between product teams and the security testing function, ensuring vulnerability assessment and penetration testing requirements are met and tracking remediation to closure

·    Ensure products meet the organisation's security standards and relevant regulatory requirements before release

·    Align product security controls to the frameworks the products will be assessed against in client and regulatory contexts

Project team

02   Secure deployment& client environment integration

Ensure Enterprise Digital products are deployed securely into client environments and integrated safely with client systems.

·    Define the security requirements for deploying each product into a client environment, covering identity, access, network, and data protection

·    Determine privileged and non-privileged access requirements for each deployment and how they should be implemented in the client's environment, including integration with client PAM tooling, Active Directory, and identity services

·    Hands-on implementation of access and security configurations during deployment where required

·    Integrate products securely with client local systems and services, ensuring integrations do not introduce vulnerabilities

·    Harden product deployments against the client's specific environment and threat profile

·    Validate that deployed environments meet both ST Engineering's security standards and the client's security obligations

Presales team

03   Security assurance& presales support

Act as the senior security authority supporting client-facing assurance during the sales cycle.

·    Serve as the security subject matter expert in presales conversations, giving clients confidence in the security of Enterprise Digital products

·    Respond to client security questionnaires, due diligence requests, and RFP security sections

·    Build and maintain a reusable catalogue of security assurance responses to common client queries

·    Present and explain SOC 2 reports and other assurance artefacts to clients, articulating how products are secured

·    Translate technical security controls into business-level assurance that non-technical client stakeholders understand

·    Support clients in understanding how products meet their regulatory and compliance obligations

What the role requires

·    Strong foundation in cyber security across application security, cloud security, identity and access management, and security architecture

·    Ability to conduct threat modelling, secure architecture review, and security testing of technology products

·    Working knowledge of secure deployment, client environment integration, and privileged access management concepts and tooling (PAM, Active Directory, identity services)

·    Familiarity with security assurance frameworks and artefacts, including SOC 2, ISO 27001, and common client due diligence processes

·    Understanding of AI security and governance, and the ability to extend security thinking to emerging technologies including AI, quantum-safe systems, and data centre and contact centre environments

·    Ability to translate technical security into clear business-level assurance for client-facing conversations

·    Strong stakeholder engagement across engineering, delivery, sales, and clients

·    Relevant certifications such as CISSP preferred

·    Background in regulated industries(financial services, healthcare, public sector) advantageous

重要安全守则

申请工作时,切勿提供您的银行或信用卡详细资料。不要转账或完成无关的在线调查问卷。如果您发现可疑内容,请举报此招聘广告。

了解更多