- Location
- Singapore - Technology Centre
- Type
- Full-time
- Department
- Engineering
- Seniority
- Entry
- Closing date
- Today
- Source
- Workday
Description
About us
At Dyson, we are not just creating innovative, technology-enabled products; we are also breaking new ground in cybersecurity. Our products are becoming more advanced and interconnected, which means we face a constantly evolving cyber threat landscape. This requires a highly skilled candidate to join our team, with a passion for staying ahead of emerging threats and keeping our products secure.
We take a proactive approach to cybersecurity. We do not wait for threats to emerge; we anticipate them and respond with innovative solutions. This means that at Dyson, you will have the opportunity to work with innovative technologies, like artificial intelligence and machine learning, to protect our products and customers.
You will be part of a team of cybersecurity experts, utilizing the latest tools and technologies to identify and respond to threats in real-time. You will work closely with our engineering and product teams to ensure that security is integrated into every aspect of our business.
Join our team at Dyson, and you will be at the forefront of cybersecurity, working on some of the most innovative and advanced products in the industry. You will have the opportunity to develop your skills and knowledge, collaborating with a talented team of experts to ensure we are always secure. If you are passionate about cybersecurity and looking for an exciting and challenging role, Dyson is the place for you.
About the role
As Associate Principal Cybersecurity Architect for Data, you will provide architecture leadership for Dyson's data security capabilities. Your core focus will be Data Loss Prevention, data discovery and classification, and protection of structured and unstructured information across endpoints, collaboration services, email, SaaS, cloud platforms, databases, data platforms and integrations.
You will translate business, legal, privacy and security requirements into a coherent data protection architecture. You will define patterns, control objectives and implementation guardrails that follow data through its lifecycle and apply proportionate protection based on sensitivity, context, user activity and approved business use. The role must balance strong protection of intellectual property and regulated information with a usable employee and engineering experience.
What you will do
- Set the data security architecture direction, principles, target state and multi-year capability roadmap for data classification, Data Loss Prevention and associated protective controls.
- Define enterprise data classification and handling architecture, including classification levels, labelling, inheritance, metadata, ownership, approved handling rules, retention dependencies and integration with technical enforcement.
- Architect data discovery and classification capabilities for structured and unstructured data across endpoints, file repositories, collaboration platforms, email, SaaS, cloud storage, databases and data platforms.
- Design risk-based DLP controls across endpoint, email, web, cloud and collaboration channels, including detection logic, contextual policy conditions, user prompts, blocking, quarantine, encryption, alerting and exception handling.
- Ensure controls address data at rest, in use and in motion, including approved sharing, downloads, printing, clipboard use, removable media, browser uploads, application transfers and external collaboration.
- Define patterns for encryption, key management, tokenisation, masking, rights management, access control and secure data sharing, selecting controls according to data sensitivity and business context.
- Lead security architecture reviews and risk assessments for initiatives that create, collect, store, process, analyse, share or dispose of sensitive data. Record decisions, control requirements, exceptions and residual risk in an audit-defensible manner.
- Partner with data owners, Data Governance, Privacy, Legal, HR, Employee Relations, Insider Risk, Cyber Operations and technology teams to establish clear ownership and proportionate enforcement processes.
- Design the integration of DLP and classification telemetry into monitoring, investigation and incident response processes, with sufficient context, evidence handling, access controls and escalation routes.
- Create and govern reusable security patterns for Microsoft 365, endpoints, SaaS applications, cloud platforms, data lakes, analytics services, databases, data integration and artificial intelligence use cases.
- Define requirements for Data Security Posture Management and data-security visibility, including discovery of sensitive stores, exposure paths, excessive access, stale data, risky sharing and control coverage gaps.
- Establish policy lifecycle governance covering design, simulation, testing, deployment, tuning, false-positive management, change control, exceptions, periodic review and measurable retirement criteria.
- Guide technical product teams and suppliers through design, implementation and transition into operations, ensuring solutions are scalable, supportable, privacy-aware and aligned with architecture standards.
- Develop metrics and control evidence for data discovery coverage, classification adoption, DLP effectiveness, policy quality, alert disposition, exception ageing, remediation and material data-risk reduction.
- Build organisational capability by producing standards, reference architectures, patterns, playbooks and role-based guidance, and by coaching architects, engineers, data owners and operational teams.
About you
You are an experienced data security architect who can work at strategic, solution and operational depth. You can guide senior stakeholders through complex data-risk trade-offs while remaining sufficiently technical to challenge product design, policy logic, integration patterns and delivery plans.
To succeed in this role you should,
· Significant experience in security architecture, data security or information protection, with accountability for complex enterprise-scale outcomes.
· Deep practical knowledge of Data Loss Prevention architecture across endpoint, email, web, cloud and collaboration channels, including policy design, deployment, tuning and operational integration.
· Strong understanding of data discovery, classification and labelling for structured and unstructured data, including metadata, exact data matching, document fingerprinting, classifiers and contextual detection.
· Experience defining classification taxonomies and translating legal, privacy, regulatory and business requirements into clear handling rules and technical controls.
· Strong knowledge of data lifecycle risks covering creation, collection, storage, processing, analytics, sharing, archival and secure disposal.
· Experience designing data protection controls such as encryption, rights management, key management, tokenisation, masking, access controls and secure collaboration.
· Ability to assess data flows, trust boundaries, identities, entitlements, storage locations, third parties and cross-border transfers, and to turn findings into actionable architecture requirements.
· Knowledge of cloud, SaaS, endpoint and collaboration architectures, with the ability to evaluate control consistency across hybrid and multi-platform environments.
· Understanding of Data Security Posture Management concepts, data inventories, exposure analysis, over-permissioning and sensitive-data attack paths.
· Experience connecting data-security controls to SIEM, case management, incident response and insider-risk workflows while preserving privacy, confidentiality and appropriate segregation of duties.
· Experience creating reference architectures, standards, design patterns, technical requirements, low-level design guidance and risk decisions for both engineering and governance audiences.
· Ability to evaluate security products and suppliers through requirements, proof-of-value criteria, architecture fit, integration, operational sustainability and measurable outcomes.
· Strong communication, facilitation and influencing skills, including the ability to broker workable decisions across Security, Data, Legal, Privacy, HR and technology teams.
· Ability to lead through influence, mentor others and coordinate virtual teams and external partners with limited supervision.
· Hands-on experience with enterprise information-protection and DLP platforms, including Microsoft Purview, FortiDLP, Netskope, or comparable technologies, without being limited to a single vendor.
· Experience securing high-value intellectual property, source code, engineering data, customer information, employee data or regulated datasets.
· Experience with database and data-platform protections, including activity monitoring, fine-grained access, masking, tokenisation and sensitive-data discovery.
· Knowledge of privacy engineering, records management, data retention, eDiscovery and insider-risk disciplines, and how their responsibilities intersect with security architecture.
· Experience designing data controls for analytics, machine learning and generative AI, including data preparation, training inputs, prompts, outputs, retrieval sources and model-access boundaries.
· Relevant certifications such as CISSP, ISSAP, CCSP, CISM, Microsoft security credentials or privacy and data-governance certifications. Certifications support, but do not replace, demonstrated practical capability.
Dyson is an equal opportunity employer. We know that great minds don’t think alike, and it takes all kinds of minds to make our technology so unique. We welcome applications from all backgrounds and employment decisions are made without regard to race, colour, religion, national or ethnic origin, sex, sexual orientation, gender identity or expression, age, disability, protected veteran status or other any other dimension of diversity.