Senior Manager, Security Innovation
Senior Manager, Security Innovation
prudential services asia8-10 Years
- Posted 22 hours ago
- Be among the first 10 applicants
Job Description
Prudential's purpose is to be partners for every life and protectors for every future. Our purpose encourages everything we do by creating a culture in which diversity is celebrated and inclusion assured, for our people, customers, and partners. We provide a platform for our people to do their best work and make an impact to the business, and we support our people's career ambitions. We pledge to make Prudential a place where you can Connect, Grow, and Succeed.
This is a hands-on role focused on security innovation, combining building with applied research. The incumbent primarily builds security automation, orchestration, and AI-augmented tooling that make GISP processes faster and more consistent, and research new and emerging technologies, threats, and security approaches to inform what the team builds.
The role exists to improve the efficiency and scale of GISP's security work through automation and orchestration, while also exploring new and emerging technologies through applied research and proofs-of-concept that help Prudential adopt them safely and effectively.
Key Contributions Of The Role Include
The incumbent is expected to work across Prudential's business units in Asia, Africa, and the UK, collaborating with Group and local business unit (LBU) architecture, engineering, risk, compliance, and business stakeholders. The team operates in a fast-moving environment where the ability to build practical tooling, exercise sound judgement under ambiguity, and the ability to communicate clearly with senior stakeholders are as important as technical depth.
Security Innovation & Automation
This is a hands-on role focused on security innovation, combining building with applied research. The incumbent primarily builds security automation, orchestration, and AI-augmented tooling that make GISP processes faster and more consistent, and research new and emerging technologies, threats, and security approaches to inform what the team builds.
The role exists to improve the efficiency and scale of GISP's security work through automation and orchestration, while also exploring new and emerging technologies through applied research and proofs-of-concept that help Prudential adopt them safely and effectively.
Key Contributions Of The Role Include
- Building security automation and orchestration that integrate GISP's security tools, controls, and processes into efficient, repeatable workflows.
- Applying AI augmentation where it improves the consistency and effectiveness of security controls and processes within GISP.
- Researching new and emerging technologies and security tooling, including proofs-of-concept and hands-on evaluation.
- Translate research findings into practical recommendations, reference approaches, and working prototypes the team can operationalize.
The incumbent is expected to work across Prudential's business units in Asia, Africa, and the UK, collaborating with Group and local business unit (LBU) architecture, engineering, risk, compliance, and business stakeholders. The team operates in a fast-moving environment where the ability to build practical tooling, exercise sound judgement under ambiguity, and the ability to communicate clearly with senior stakeholders are as important as technical depth.
Security Innovation & Automation
- Builds and orchestrates security automation workflows that connect tools, data sources, and controls across the security stack, reducing manual effort and turnaround time.
- Integrates disparate security tooling and telemetry into end-to-end automated workflows, for example assessment of intake, evidence collection, control validation, and reporting, so processes run with minimal manual handoffs.
- Applies AI augmentation within these workflows where it adds value, such as triage, summarisation, and drafting, with appropriate human-in-the-loop checkpoints and guardrails.
- Integrates security checks into CI/CD and infrastructure-as-code workflows where appropriate.
- Research new and emerging technologies (AI/ML, agentic frameworks, developer tools) and their security implications, tracking the threat landscape and relevant technology trends.
- Runs proofs-of-concept, tool evaluations, and experiments to test new security approaches and inform build and adoption decisions.
- Translates research into practical recommendations, reference approaches, and prototypes that the team can operationalise, and shares findings to build collective capability.
- Maintains situational awareness of the global threat landscape, emerging attack techniques, regulatory expectations, and technology trends relevant to Prudential's risk profile.
- Exercises sound judgement on security architecture and tooling decisions within defined authority levels and escalates appropriately when decisions carry material risk.
- Operates effectively in ambiguous environments, thinking laterally and proactively identifying architecture gaps before issues escalate.
- Partners with business, engineering, risk, and compliance stakeholders to prioritise control requirements proportionate to inherent and residual risk, and ensures requirements, controls, and residual risks are documented in line with GISP governance.
- Contributes to the GISP community of practice through internal guidance, knowledge sharing, and cross-domain collaboration.
- Provides guidance and mentorship to junior team members, and supports the Senior Manager, Enterprise Security Architecture & Innovation on assigned priorities.
- Take ownership of assigned deliverables and personal career growth, driving capability uplift through skills development, certifications, and hands-on learning.
- Bachelor's degree in information technology / computer engineering / computer science
- 8 years experience and above in supporting large organizations with a focus on Information Security, Enterprise Management System, or IT.
- Possess 5 years experience in security engineering, security automation, security architecture, or a closely related security discipline.
- Hands-on ability to build security automation and orchestration: comfortable writing and maintaining scripts and tooling (e.g. Python), integrating security tools via APIs, and building SOAR-style workflows. Candidates are not required to submit a portfolio but must be genuinely hands-on rather than advisory-only.
- Practical experience with CI/CD platforms and DevOps toolsets.
- Demonstrated curiosity and self-direction in researching new technologies, evaluating tools, and building proofs-of-concept.
- Sound working knowledge of major cybersecurity domains (cloud, infrastructure, data, application, IAM) and willingness to move into new areas
- Strong written and spoken English, able to communicate security requirements to management and cross-functional team across locations.
- Able to work in a dynamic, ambiguous environment.
- Professional Certifications: CISSP, CISM, AAISM, SANS GIAC, CCSP, AWS/Azure/GCP Security certification is preferred, but hands-on engineering capability is weighted equally.
- Exposure to AI-enabled or agentic automation applied to security workflows is desirable.
- Previous working experience with financial organizations is desirable.
More Info
Key Skills
AI augmentation
proofs-of-concept
DevOps toolsets
SOAR-style workflows
CI/CD platforms




