AIA

Assistant Manager, Technology Centre

AIA  •  Kuala Lumpur, MY (Onsite)  •  4 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Are you ready to shape a better tomorrow?

AIA Digital+ is a Technology, Digital and Analytics innovation hub dedicated to powering AIA to be more efficient, connected and innovative as it fulfils its Purpose to help millions of people across Asia-Pacific live Healthier, Longer, Better Lives.

If you are hungry and driven to play an active role in shaping a better tomorrow, we want to hear from you. Because the work we do at AIA Digital+ makes a difference in the lives of millions of people, every day. We will equip you with the critical skills, tools and technology, and endless opportunities to learn, contribute and thrive in a dynamic and exciting environment.

If you want to shape a brighter future at AIA Digital+, please read on.

About the Role

We are seeking a Security & Cloud Architect with strong hands‑on experience in designing and reviewing secure, cloud‑native solutions across interconnected applications, platforms, and infrastructure. The role provides security architecture leadership and advisory support covering application security, identity and access management, data protection, cryptographic controls, compliance, and the secure adoption of emerging technologies such as Generative AI (GenAI) and Large Language Models (LLMs).

This position partners closely with architecture, engineering, and delivery teams to perform security design reviews, architecture assessments, and risk‑based advisory for strategic digital initiatives—ensuring solutions enable business growth while maintaining a strong security and regulatory posture.

Key Responsibilities

Secure Solution Design & Technical Direction

  • Lead security‑focused design of cloud solutions across application, integration, data, and infrastructure layers (Azure‑centric).
  • Shape and evolve reference architectures and secure design patterns aligned to enterprise and Group standards.
  • Produce and maintain key architecture deliverables (e.g. SAD, HLD) with clear security considerations and design decisions.

Cloud Application Security & Identity

  • Design and review authentication and authorization models for cloud applications, ensuring strong access control, token handling, session management, cryptography, and data protection.
  • Assess security implications of new or changed applications, tools, and platforms, including impact to existing architectures.
  • Embed secure‑by‑design principles across APIs, integrations, and middleware components.

Emerging Technology & GenAI Security

  • Provide security architecture input and assessment for solutions leveraging GenAI, LLMs, and machine‑learning technologies.
  • Identify and address GenAI‑specific risks such as prompt injection, insecure outputs, model abuse, data poisoning, and sensitive data exposure.
  • Apply OWASP Top 10 for LLM Applications and/or OWASP Top 10 for Machine Learning Security Risks when conducting design reviews and security assessments.
  • Establish guardrails for LLM usage, including validation, access restriction, monitoring, data boundaries, and human‑oversight controls.
  • Support responsible and compliant GenAI adoption aligned with enterprise risk, privacy, and regulatory expectations.

Security Architecture Execution & Improvement

  • Implement and continuously enhance cloud security architecture and controls.
  • Drive automation of security checks and controls across delivery pipelines and operational processes.
  • Monitor evolving threats, vulnerabilities, and industry practices to improve the organisation’s security posture.

Risk, Compliance & Architecture Assurance

  • Perform threat modelling, risk assessments, and security impact analysis for new and existing solutions.
  • Contribute to Architecture Review Board (ARB) discussions and provide architectural assurance against standards, policies, and roadmaps.
  • Ensure compliance with internal IT policies, regulatory requirements, and industry standards (e.g. NIST, PCI DSS).
  • Support Local Information Security (LIS) activities related to audits, compliance reviews, and control validation.

Delivery Partnership & Advisory

  • Work closely with enterprise architects, developers, DevOps teams, and vendors throughout delivery lifecycles.
  • Provide practical guidance to resolve security design and implementation challenges.
  • Communicate security risks and trade‑offs clearly to technical and business stakeholders, including senior leadership.

Capability Building & Enablement

  • Act as the security architecture subject matter expert across cloud, application, and GenAI‑enabled solutions.
  • Mentor junior team members and promote secure design awareness across IT and business teams.
  • Facilitate balanced discussions where business needs, innovation, and security standards intersect.

Minimum Requirements

Education

  • Bachelor’s degree in Computer Science, Information Security, Software/Computer Engineering, Enterprise/Solution Architecture, or related discipline.

Experience

  • 8+ years in solution and/or security architecture roles (10–15 years preferred for senior profiles).
  • 5+ years hands‑on experience in cloud and application security architecture (IaaS / PaaS / SaaS).
  • Experience delivering secure digital solutions within financial services or insurance environments (preferred).
  • Exposure to API‑based architectures, microservices, event‑driven integration, and DevSecOps practices.

Security & Technology Expertise

  • Strong understanding of security frameworks such as ISO/IEC 27001, NIST, and COBIT; familiarity with PDPA, GDPR, and PCI DSS where applicable.
  • Deep knowledge of identity and access management, data protection, cryptographic controls, and cloud security (Azure preferred).
  • Working knowledge of CI/CD pipelines, infrastructure‑as‑code, and operational security guardrails.
  • Awareness or hands‑on experience securing GenAI / LLM‑enabled applications, including prompt safety and data governance.
  • Familiarity with OWASP Top 10 for LLM Applications and/or OWASP Top 10 for Machine Learning Security Risks.

Professional Attributes

  • Strong communication skills with the ability to translate complex security topics into business‑relevant language.
  • Analytical, pragmatic, and decisive with a collaborative mindset and strong ownership.

Certifications (Preferred)

  • Security / Cloud: CISSP, CCSP, CISM, SABSA, Azure Solutions Architect, Azure DevOps.
  • Architecture / Governance (nice to have): TOGAF, IASA.
  • GenAI / AI security‑related training or experience (must).

Build a career with us as we help our customers and the community live healthier, longer, better lives.

You must provide all requested information, including Personal Data, to be considered for this career opportunity. Failure to provide such information may influence the processing and outcome of your application. You are responsible for ensuring that the information you submit is accurate and up-to-date.

AIA

About AIA

AIA Group Limited and its subsidiaries (collectively “AIA” or the “Group”) comprise the largest independent publicly listed pan-Asian life insurance group. It has a presence in 18 markets – wholly-owned branches and subsidiaries in Mainland China, Hong Kong SAR(1), Thailand, Singapore, Malaysia, Australia, Cambodia, Indonesia, Myanmar, New Zealand, the Philippines, South Korea, Sri Lanka, Taiwan (China), Vietnam, Brunei and Macau SAR(2), and a 49 per cent joint venture in India. In addition, AIA has a 24.99 per cent shareholding in China Post Life Insurance Co., Ltd.

The business that is now AIA was first established in Shanghai more than a century ago in 1919. It is a market leader in Asia (ex-Japan) based on life insurance premiums and holds leading positions across the majority of its markets. It had total assets of US$328 billion as of 30 June 2025.

AIA meets the long-term savings and protection needs of individuals by offering a range of products and services including life insurance, accident and health insurance and savings plans. The Group also provides employee benefits, credit life and pension services to corporate clients. Through an extensive network of agents, partners and employees across Asia, AIA serves the holders of more than 43 million individual policies and over 16 million participating members of group insurance schemes.

AIA Group Limited is listed on the Main Board of The Stock Exchange of Hong Kong Limited under the stock codes “1299” for HKD counter and “81299” for RMB counter with American Depositary Receipts (Level 1) traded on the over-the-counter market under the ticker symbol “AAGIY”.

(1) Hong Kong SAR refers to the Hong Kong Special Administrative Region.

(2) Macau SAR refers to the Macau Special Administrative Region.

Industry
Finance & Insurance
Company Size
10,000+ employees
Headquarters
Central, HK
Year Founded
Unknown
Website
aia.com
Social Media