Principal Cyber Security Architect (Application Security)
Core
Senior architecture authority for security across Dyson's digital application landscape, defining reusable security architectures and establishing scalable DevSecOps capabilities.
Role type
Principal Cyber Security Architect (Application Security & DevSecOps)
Builds
Secure digital applications (eCommerce, mobile, APIs), cloud-native services, and DevSecOps pipelines.
Domain
Cybersecurity, Application Security, DevSecOps, Cloud-Native
Required skills
Security architecture design, DevSecOps framework definition, threat modeling (STRIDE, attack trees), identity and access management, API security, supply-chain security, security testing (SAST, DAST, SCA), vulnerability triage, security metrics, engineering enablement
Preferred skills
Experience with policy-as-code, container and image scanning, secure failure modes, security champions programs
Technologies
STRIDE, attack trees, SAST, DAST, SCA, policy-as-code, CI/CD pipelines, container scanning, API security testing, mobile testing, penetration testing
Responsibilities
Define reusable security architectures and patterns; lead security architecture reviews and risk assessments; facilitate threat modeling; design and govern security controls for identity, API, and encryption; define DevSecOps control frameworks; guide integration of security testing capabilities; strengthen software supply-chain security; establish vulnerability triage models; develop application security metrics; build security capability through training and coaching.
Seniority
Principal, hands-on IC with strategic leadership