Skip to content
← Back to job listings

Senior Security Business Partner – S-SDLC / Product Security

hytech · Kuala Lumpur, Kuala Lumpur, Malaysia

External listingfull-time26 days ago

About The Role

About Hytech Hytech is a leading management consulting firm headquartered in Australia and Singapore, specialising in digital transformation for fintech and financial services organisations. We deliver end-to-end consulting services and provide robust middle- and back-office solutions that enable our clients to optimise operations, enhance efficiency, and stay ahead in a fast-evolving digital landscape. Our client portfolio includes top global trading platforms and leading crypto exchanges. With more than 2,000 professionals worldwide, Hytech has a strong and growing international presence, with offices across Australia, Singapore, Malaysia, Taiwan, the Philippines, Thailand, Morocco, Cyprus, Dubai, and beyond. ​​​​​​‬​​​​​​​⁠‬​​ Job Overview We are looking for a Senior Security Business Partner to serve as the primary security partner for designated business lines within a high-risk financial trading environment. The role works closely with Product, Engineering, Architecture, QA, DevOps and business stakeholders to embed security across the full software development lifecycle. You will understand the business, system architecture, data flows and key risks of the supported business line, and coordinate the appropriate security resources to ensure risks are identified, addressed and tracked to closure. This is a hands-on product security role , not a pure coordination or compliance position. You are expected to lead and personally perform threat modelling, security architecture reviews, application security assessments and security testing for medium- to high-complexity systems, while coordinating specialist support (DevSecOps, Red Team, SOC, GRC, Data Security & Privacy) for depth when required. Key Responsibilities Partnering & Business Understanding Act as the primary security contact for designated business lines and maintain close working relationships with Product, Engineering, Architecture, QA, DevOps and business stakeholders. Develop a strong understanding of the supported business, including business processes, system architecture, APIs, data flows, sensitive data, privileged access paths and third-party dependencies. Translate security risks into clear, executable requirements for Product, Engineering, QA and DevOps teams, driving remediation across teams without relying solely on formal authority. S-SDLC & Technical Assessment (hands-on) Drive implementation of the Secure Software Development Lifecycle (S-SDLC) across requirements, design, development, testing, release and production operations. Participate in project initiation and risk classification to determine the appropriate level of security review based on business criticality, data sensitivity, financial exposure, external attack surface and regulatory requirements. Conduct or lead security architecture reviews for web applications, APIs, microservices, mobile applications, cloud-native platforms and containerised environments. Perform threat modelling (STRIDE, attack trees, data flow diagrams) and translate identified threats into security requirements, engineering tasks, test cases and monitoring requirements. Review authentication, authorisation, session management, API security, data protection, secrets management, third-party integration and privileged access designs. Analyse and validate findings from SAST, SCA, DAST, secrets scanning, infrastructure-as-code scanning and container image scanning. Perform code security reviews and provide practical remediation guidance to engineering teams. Coordinate penetration testing, API security testing, business logic testing and pre-production security assessments. Risk & Governance Assess the actual exploitability and business impact of security findings and assign appropriate remediation priorities. Define security requirements and release conditions for high-risk projects and support the design of compensating controls where immediate remediation is not feasible. Maintain a business-line security risk register, including risk owners, remediation owners, due dates, evidence requirements, exceptions and closure status. Track Critical and High risks through remediation and ensure closure decisions are supported by sufficient technical evidence. Coordinate internal security resources (Security Architecture, DevSecOps, Red Team, SOC, GRC, Data Security and Privacy) to support business projects and risk remediation. Ensure security incidents, penetration testing findings and recurring production issues are fed back into security standards, secure development practices and engineering controls. Reporting Provide regular security updates to business and security management, covering major risks, remediation progress, recurring issues, blockers and resource requirements. Use approved AI tools to support architecture analysis, threat modelling, code review, security test design and reporting, ensuring all AI-generated outputs are professionally validated. Job Requirements Bachelor's degree or above in Computer Science, Software Engineering, Cybersecurity, Information Security or a related discipline. At least 5 years of experience in application security, product security, security architecture, DevSecOps, secure software development, code review or penetration testing. Proven hands-on experience implementing or operating an S-SDLC programme across security requirements, design review, threat modelling, secure development, security testing and release assessment. Ability to independently conduct threat modelling and security architecture reviews for medium- to high-complexity systems. Strong understanding of common application and API security risks. Practical experience with at least 3 of the following: SAST, SCA, DAST, secrets scanning, infrastructure-as-code scanning, container image scanning, penetration testing, code security review. Ability to analyse security testing results, identify false positives, assess exploitability and provide actionable remediation advice. Code reading and basic code audit capability in at least one mainstream language (Java, Go, Python or JavaScript). Good understanding of Git-based development workflows, CI/CD pipelines, artefact repositories, containers, Kubernetes and public cloud environments. Strong stakeholder management and influencing skills, with the ability to drive remediation across teams without relying solely on formal authority. Strong project management and organisational skills, with the ability to manage multiple projects, security reviews and remediation activities concurrently. Strong written and verbal communication skills in both English and Chinese . Preferred Qualifications Experience in fintech, payments, digital wallets, trading platforms, Web3 or other high-risk financial services environments. Experience working in a Product Security, Application Security, Security Business Partner or business-line security role. Experience supporting multiple products or business lines in a large or complex organisation. Strong cloud-native security experience involving AWS, Kubernetes, microservices, API gateways or service mesh technologies. Experience building or implementing an S-SDLC, Product Security or security release governance programme from the ground up. Experience assessing transaction security, account security, administrative portals, privileged systems or complex business logic. Familiarity with OWASP ASVS, OWASP SAMM, NIST SSDF, PCI DSS, ISO 27001 or similar standards and frameworks. Familiarity with financial-services regulatory regimes relevant to the business lines in scope e.g. FCA / ASIC. Practical AI capability — using AI to support security analysis, code review, threat modelling and testing, with the ability to validate AI-generated outputs and manage sensitive data appropriately. Scripting or automation experience using Python, Go or another language. Relevant certifications such as CISSP, CSSLP, OSCP, OSWE, AWS Certified Security – Specialty or equivalent.

This is an external listing. JobSpring does not represent or verify the employer. Report this listing