Security Architect
This is the employer's own posting, not a copy on a job board.
What we know
Is it still open?
Confirmed still open
Last checked 2d ago — checked against the employer's own applicant tracking system, which is the company answering directly.
We re-read the employer's own applicant tracking system and the posting was still there. That is the company answering directly.
How old is it?
Posted 2d ago
The date the source published, not the day we noticed it (2026-09-29). Last seen at its source just now.
We have tracked this listing since 29 Sep 2026 (2 days). The employer's own board has carried it every time we have read it, most recently just now.
Is it remote?
Marked remote on the employer's board
Their board carries a remote setting on this posting — a field they filled in, not wording we read. The location field names somewhere specific, which is usually where the team or the entity sits.
Who may apply?
Available worldwide
The description states no restriction of its own. This is the source's own tag.
Pay not stated
Similar roles pay $101.2k–162.2k/yr
Middle 50% of 15 listings that do state pay — Engineering · all levels · Worldwide · USD/year. This employer has published no salary; this is what comparable listings we hold disclose, never converted between currencies or periods. How this is calculated.
Skills named in the ad
Recognised terms only, from a fixed vocabulary — this is what CV matching compares against.
Carried by 1 source
-
ashby employer's own board first seen 2d ago · last seen just now
The listing
About BJAK
The original mission of BJAK is we believe people deserve smarter ways to plan, save and grow their money. This is the origin of our name.
Started in 2019, we built the first mobile-first, insurance platform, enabling insurance to be accessible online by millions in the region. Today, its the leading insurance platform in Southeast Asia.
Today, we are expanding ways to help people in the region — this includes spending, saving, investing, exchanging, travelling, and more. Our mission is help people get more from their money every day.
We have teams working around the world, with over 20 nationalities from our offices and remotely, who truly enjoys their work. We are looking for the most talented and driven people we can find. We are looking for people who work for their passion, not counting hours. Who loves building great next-generation products, not status quo. Who cares about redefining how everyone around us can get the best financial applications, not for an exclusive few.
If you're this person, we'd love to talk to you.
The RoleDefine security architecture across BJAK products, applications, cloud platforms, and infrastructure. Partner with Engineering, Product, Cloud, Compliance, and Security to build secure systems and meet regulatory requirements.
What You Will BuildDefine security architecture, patterns, and standards across products, applications, APIs, cloud environments, and integrations.
Own architecture implementation and ongoing alignment with SC TRM and BNM RMiT, including control evidence, reviews, remediation, and audit support.
Lead threat modeling and security design reviews for new products, major changes, third-party integrations, and critical systems.
Design and review IAM, privileged access, network security, encryption, key management, secrets, logging, and threat detection controls.
Review web, API, native mobile, AI-enabled, and data processing architectures for security and privacy risks.
Guide secure architecture across TypeScript/Node.js, Python, Swift, and Kotlin applications and services on AWS and GCP.
Evaluate security technologies, advise engineering leaders, and track remediation of material architecture risks.
Degree in Computer Science, Information Security, or related field, or equivalent experience.
5+ years in security engineering, security architecture, or a related security role.
Experience implementing and owning SC TRM and BNM RMiT requirements, including control operation, evidence, and audit remediation.
Strong knowledge of cloud and application security, IAM, networking, encryption, secure design, and distributed systems.
Hands-on familiarity with AWS and GCP and architectures using TypeScript/Node.js, Python, Swift, and Kotlin.
Experience with threat modeling, architecture reviews, risk assessments, and frameworks such as ISO 27001, NIST, CIS, or OWASP.
Able to translate regulatory and technical risks into clear, actionable plans for technical and non-technical stakeholders.
Language
English is our main working language across global teams. Strong English communication is required.