Principal Cyber Security Architect (Application Security)
Core
Define reusable security architectures, patterns, and guardrails for Dyson's digital application landscape (eCommerce, mobile, APIs, cloud-native services) while establishing a scalable DevSecOps capability.
Role type
Principal Cyber Security Architect (Application Security & DevSecOps)
Builds
Secure-by-default paved roads, templates, reusable controls, and a scalable DevSecOps control framework for engineering teams.
Domain
Application Security, DevSecOps, Cloud-Native, Software Supply Chain
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Application security architecture, DevSecOps strategy, Threat modeling (STRIDE, attack trees), Identity protocols (OAuth 2.0, OIDC, SAML), Cloud/Container security (Kubernetes, serverless), Software supply chain security, Security testing automation (SAST, DAST, SCA, IaC scanning), Risk assessment and governance, Code review and challenge, Architecture documentation.
Preferred skills
Proficiency in Python, Java, JavaScript, TypeScript, C#, or Go; REST/GraphQL API design; YAML/JSON scripting; Security champion program leadership.
Technologies
Kubernetes, Serverless, API Gateways, CI/CD pipelines, SAST/DAST tools, SCA tools, IaC scanners, Container image scanners, OAuth 2.0, OpenID Connect, SAML, REST, GraphQL, JSON, YAML.
Responsibilities
Set application security and DevSecOps architecture direction; Lead security architecture reviews and risk assessments; Design and govern reusable security patterns for identity, access, and encryption; Define the DevSecOps control framework and reference pipeline; Guide integration of security testing capabilities; Strengthen software supply-chain security; Establish vulnerability triage and remediation models; Develop application security metrics; Build capability through security champions and training; Support investigation and resolution of security incidents.
Seniority
Principal, strategic authority with hands-on technical depth