Security Architect

Bjak

2h ago • 2 views • 0 applications
Full-time Remote
Global
Competitive
Full-time
Security Architect

Job Description

About BJAK: Reshaping Financial Futures in Southeast Asia
At BJAK, we believe everyone deserves smarter, more accessible ways to manage their money. Since our inception in 2019, we've been on a mission to empower millions in Southeast Asia. We revolutionized the industry by building the region's first mobile-first insurance platform, quickly becoming the market leader.
But that was just the beginning. Today, we're expanding our reach across spending, saving, investing, exchanging, and travel – continually innovating to help people get more from their money every single day. We're not just building products; we're crafting the future of finance for everyone, not just an exclusive few.
Our global team, representing over 20 nationalities, thrives on passion, innovation, and a shared commitment to building next-generation products that redefine the status quo. If you're driven by impact, eager to solve complex challenges, and passionate about creating groundbreaking financial applications, you've found your home.

Security Architect
Are you a visionary Security Architect ready to define and implement the robust security posture for a leading FinTech platform? At BJAK, you'll be instrumental in safeguarding our expansive product ecosystem, cloud infrastructure, and critical data. You will partner with Engineering, Product, Cloud, Compliance, and our Security teams to embed security by design, ensuring compliance and building trust across every layer of our systems.

What You Will Build & Secure:

Architect & Define: Lead the definition of security architecture, patterns, and standards across all BJAK products, applications, APIs, cloud environments (AWS, GCP), and integrations.
Regulatory Leadership: Own the architecture implementation and ensure ongoing alignment with critical regulatory requirements like SC TRM and BNM RMiT. This includes meticulously managing control evidence, conducting reviews, driving remediation efforts, and providing essential audit support.
Proactive Threat Mitigation: Lead comprehensive threat modeling exercises and security design reviews for all new products, significant system changes, third-party integrations, and critical internal systems.
Robust Control Design: Design and critically review key security controls, including Identity and Access Management (IAM), privileged access management, network security, encryption schemes, key management systems, secrets management, comprehensive logging, and advanced threat detection mechanisms.
Holistic Security Assessment: Proactively assess and secure architectures for web, API, native mobile, AI-enabled systems, and data processing pipelines to mitigate security and privacy risks.
Developer Empowerment: Champion secure architecture principles and provide expert guidance across our diverse technology stack, including TypeScript/Node.js, Python, Swift, and Kotlin applications and services deployed on AWS and GCP.
Strategic Innovation: Evaluate cutting-edge security technologies, provide strategic counsel to engineering leaders, and rigorously track the remediation of all identified material architecture risks.

What We Look For in You:

Foundational Expertise: A degree in Computer Science, Information Security, or a related technical field, or equivalent practical experience.
Proven Track Record: 5+ years of progressive experience in security engineering, security architecture, or a closely related security role.
Regulatory Mastery: Deep, hands-on experience implementing and owning SC TRM and BNM RMiT requirements, including direct involvement in control operation, evidence gathering, and audit remediation.
Technical Acumen: Strong, demonstrable knowledge of cloud security, application security, IAM principles, network security, encryption methodologies, secure design patterns, and distributed systems.
Platform & Language Proficiency: Hands-on mastery of AWS and GCP environments and architectures utilizing TypeScript/Node.js, Python, Swift, and Kotlin.
Risk & Framework Savvy: Extensive experience with threat modeling, architecture security reviews, risk assessments, and practical application of industry frameworks such as ISO 27001, NIST, CIS, or OWASP.
Translational Skills: Exceptional ability to translate complex regulatory and technical risks into clear, actionable plans and communicate effectively with both technical and non-technical stakeholders.

Language
English is the primary working language across our diverse global teams. Strong verbal and written English communication skills are essential for this role.

CyberJob.app

Your trusted source for cybersecurity job opportunities worldwide.


© 2026 CyberJob.app. All rights reserved.