Search by job, company or skills

Assistant Manager, Technology Centre

Early Applicant
  • Posted 12 hours ago
  • Be among the first 10 applicants

Job Description

AIA Digital+ is a Technology, Digital and Analytics innovation hub dedicated to powering AIA to be more efficient, connected and innovative as it fulfils its Purpose to help millions of people across Asia-Pacific live Healthier, Longer, Better Lives.

If you are hungry and driven to play an active role in shaping a better tomorrow, we want to hear from you. Because the work we do at AIA Digital+ makes a difference in the lives of millions of people, every day. We will equip you with the critical skills, tools and technology, and endless opportunities to learn, contribute and thrive in a dynamic and exciting environment.

If you want to shape a brighter future at AIA Digital+, please read on.

About the Role

We are seeking a Security & Cloud Architect with strong handson experience in designing and reviewing secure, cloudnative solutions across interconnected applications, platforms, and infrastructure. The role provides security architecture leadership and advisory support covering application security, identity and access management, data protection, cryptographic controls, compliance, and the secure adoption of emerging technologies such as Generative AI (GenAI) and Large Language Models (LLMs).

This position partners closely with architecture, engineering, and delivery teams to perform security design reviews, architecture assessments, and riskbased advisory for strategic digital initiatives-ensuring solutions enable business growth while maintaining a strong security and regulatory posture.

Key Responsibilities

Secure Solution Design & Technical Direction

  • Lead securityfocused design of cloud solutions across application, integration, data, and infrastructure layers (Azurecentric).
  • Shape and evolve reference architectures and secure design patterns aligned to enterprise and Group standards.
  • Produce and maintain key architecture deliverables (e.g. SAD, HLD) with clear security considerations and design decisions.

Cloud Application Security & Identity

  • Design and review authentication and authorization models for cloud applications, ensuring strong access control, token handling, session management, cryptography, and data protection.
  • Assess security implications of new or changed applications, tools, and platforms, including impact to existing architectures.
  • Embed securebydesign principles across APIs, integrations, and middleware components.

Emerging Technology & GenAI Security

  • Provide security architecture input and assessment for solutions leveraging GenAI, LLMs, and machinelearning technologies.
  • Identify and address GenAIspecific risks such as prompt injection, insecure outputs, model abuse, data poisoning, and sensitive data exposure.
  • Apply OWASP Top 10 for LLM Applications and/or OWASP Top 10 for Machine Learning Security Risks when conducting design reviews and security assessments.
  • Establish guardrails for LLM usage, including validation, access restriction, monitoring, data boundaries, and humanoversight controls.
  • Support responsible and compliant GenAI adoption aligned with enterprise risk, privacy, and regulatory expectations.

Security Architecture Execution & Improvement

  • Implement and continuously enhance cloud security architecture and controls.
  • Drive automation of security checks and controls across delivery pipelines and operational processes.
  • Monitor evolving threats, vulnerabilities, and industry practices to improve the organisation's security posture.

Risk, Compliance & Architecture Assurance

  • Perform threat modelling, risk assessments, and security impact analysis for new and existing solutions.
  • Contribute to Architecture Review Board (ARB) discussions and provide architectural assurance against standards, policies, and roadmaps.
  • Ensure compliance with internal IT policies, regulatory requirements, and industry standards (e.g. NIST, PCI DSS).
  • Support Local Information Security (LIS) activities related to audits, compliance reviews, and control validation.

Delivery Partnership & Advisory

  • Work closely with enterprise architects, developers, DevOps teams, and vendors throughout delivery lifecycles.
  • Provide practical guidance to resolve security design and implementation challenges.
  • Communicate security risks and tradeoffs clearly to technical and business stakeholders, including senior leadership.

Capability Building & Enablement

  • Act as the security architecture subject matter expert across cloud, application, and GenAIenabled solutions.
  • Mentor junior team members and promote secure design awareness across IT and business teams.
  • Facilitate balanced discussions where business needs, innovation, and security standards intersect.

Minimum Requirements

Education

  • Bachelor's degree in Computer Science, Information Security, Software/Computer Engineering, Enterprise/Solution Architecture, or related discipline.

Experience

  • 8+ years in solution and/or security architecture roles (10-15 years preferred for senior profiles).
  • 5+ years handson experience in cloud and application security architecture (IaaS / PaaS / SaaS).
  • Experience delivering secure digital solutions within financial services or insurance environments (preferred).
  • Exposure to APIbased architectures, microservices, eventdriven integration, and DevSecOps practices.

Security & Technology Expertise

  • Strong understanding of security frameworks such as ISO/IEC 27001, NIST, and COBIT familiarity with PDPA, GDPR, and PCI DSS where applicable.
  • Deep knowledge of identity and access management, data protection, cryptographic controls, and cloud security (Azure preferred).
  • Working knowledge of CI/CD pipelines, infrastructureascode, and operational security guardrails.
  • Awareness or handson experience securing GenAI / LLMenabled applications, including prompt safety and data governance.
  • Familiarity with OWASP Top 10 for LLM Applications and/or OWASP Top 10 for Machine Learning Security Risks.

Professional Attributes

  • Strong communication skills with the ability to translate complex security topics into businessrelevant language.
  • Analytical, pragmatic, and decisive with a collaborative mindset and strong ownership.

Certifications (Preferred)

  • Security / Cloud: CISSP, CCSP, CISM, SABSA, Azure Solutions Architect, Azure DevOps.
  • Architecture / Governance (nice to have): TOGAF, IASA.
  • GenAI / AI securityrelated training or experience (must).

About Company

Job ID: 153230055

Beware of Scammers

We don’t charge money for job offers