Skip to content
← Back to job listings

Senior Manager, Cyber Architecture

AirAsia · Kuala Lumpur - RedQ, Malaysia

CybersecurityExternal listingfull-timeabout 2 hours ago

About The Role

The Senior Manager, Cyber Architecture owns the enterprise cybersecurity architecture and the technical strategy that shapes how security capabilities are designed, governed and evolved across the organisation which protects the ecosystem while enabling

business growth.

Reporting to the Chief Information Security Officer (CISO), this role is the senior technical authority on secure by design architecture. It partners directly with business and technology teams to embed security into enterprise solutions from inception and translates an expanding t hreat landscape into architectural direction, control standards and investment priorities.

Operating within a lean enterprise team, the role provides architectural leadership and assurance across all security domains, owns the enterprise security tooling roadmap, and sets the standards and technical governance for repeatable, secure and sustainable solutions across the multi-business organisation in a fit-for-purpose environment whilst enabling individual business agility.

Responsibilities

Architecture Oversight, Planning & Enablement

  • Own the enterprise cybersecurity architecture, ensuring comprehensive coverage of security capabilities and proactively identifying and prioritising gaps for remediation.
  • Establish and maintain effective security architecture governance which includes standards,
  • reference patterns, processes and a common architectural “language” that informs repeatable, secure by design delivery.
  • Advise and partner with business divisions on the development, implementation and maintenance of architectures that uphold enterprise cybersecurity policies, standards and baselines, in collaboration with the cybersecurity

Governance, Risk & Compliance (GRC) team.

  • Define actionable control lists, implementation guidelines and required levels of protection aligned to the enterprise cybersecurity control framework.
  • Lead periodic assurance reviews across all architecture domains to confirm business solutions are built and implemented in line with the agreed target state architecture.

Acquisition & Development of Security Systems & Tools

  • Own the enterprise security tooling roadmap, ensuring appropriate systems and tools are reflected and aligned to the overall cybersecurity strategy.
  • Evergreen the enterprise security portfolio with consideration of the business portfolio to ensure the cyber defence layers along with the baselines are effective and deliver the value for the investment.
  • Partner with the Threat Intelligence Management team to ensure security systems and tools meet or exceed functional, threat-informed requirements.
  • Maintain and routinely publish an enterprise wide required and preferred tools library.
  • Advise business divisions on cybersecurity vendor and tool selection, emphasising fit to entity requirements and maximum reusability across the group.
  • Collaborate with the GRC team to evaluate enterprise tooling exception requests.

Secure-by-Design & Business Enablement

  • Provide architectural direction on major initiatives, ensuring security is designed in from inception rather than retrofitted.
  • Translate business objectives into secure, pragmatic architectural options that balance risk, cost and speed to market.
  • Emerging Threat & Digital Risk Architecture
  • Assess the architectural impact of an expanding attack surface driven by AI adoption, digital assets and cryptocurrency, complex data risk and third-party integrations.
  • Define architectural controls and guardrails to mitigate emerging digital risks across the enterprise.
  • Maintain forward awareness of the evolving threat landscape and convert it into architectural priorities and investment recommendations.

Operational Management & Assurance

  • Design, secure and manage solutions for enterprise security systems and tools, and ensure their continuous, reliable operation.
  • Develop people, process and technology capability in line with the organisation’s cybersecurity roadmap and target-state model

Governance, Reporting & Leadership

  • Maintain architecture governance standards and documentation, ensuring consistency and quality across all domains.
  • Prepare and contribute executive-ready architecture and strategy materials for the CISO, senior leadership and Board-level reviews.
  • Support audit, assurance and regulatory review activities through strong architectural documentation and evidence.
  • Provide technical leadership within a lean enterprise team, ensuring essential oversight without operational bottlenecks, and coach analysts and architects to uplift architectural maturity across the function.

Key Stakeholders

  • Chief Information Security Officer (CISO) and Cybersecurity Leadership Team
  • Cybersecurity Governance, Risk & Compliance (GRC) team
  • Threat Intelligence Management team
  • Business Division and Functional Leaders across AirAsia and Capital A entities
  • Group ICT, Procurement and Legal teams

Experience & Skills

Experience

  • 8–12 years of experience in cybersecurity architecture, security strategy or enterprise solution architecture, including senior or lead-level responsibility.
  • Proven track record defining and governing enterprise security architecture in complex, matrixed, multi-entity environments.
  • Demonstrated experience partnering with business leaders to deliver secure-by-design solutions that enable growth.
  • Exposure to emerging risk domains such as AI, cloud, digital assets / cryptocurrency, data protection and third-party / supply-chain risk.

Technical & Architecture Skills

  • Strong command of security architecture frameworks and methodologies (e.g. SABSA, TOGAF, NIST CSF, ISO 27001, Zero Trust).
  • Deep understanding of enterprise security domains (network, cloud, application, data, identity and OT / IoT where relevant)
  • Ability to define control frameworks, reference architectures and assurance processes.
  • Relevant certifications preferred (e.g. CISSP, CISSP-ISSAP, SABSA, TOGAF, CCSP).

Leadership & Communication

  • Strong written and verbal communication, with the ability to translate complex technical concepts for technical and non-technical audiences.
  • Ability to influence and align stakeholders across functions without direct authority.
  • Executive presence to represent architecture and strategy at leadership and Board level.

This is an external listing. JobSpring does not represent or verify the employer. Report this listing