***Only local applicants who do not require visa/work permit will be considered***
Why This Role Matters
As the Cloud & Infra Solution Architect, you are the technical authority and the “Brain” of our technology direction. You don’t just design infrastructure; you design a secure, resilient, and scalable ecosystem where code meets cloud. You are responsible for ensuring our product platform is built on a high-performance, cloud-native foundation with security embedded by design. By mastering the intersection of DevOps, CI/CD automation, infrastructure security and application architecture, you ensure our product factories can deploy secure, scalable banking solutions at high velocity while maintaining strong cyber resilience and regulatory alignment.
How You’ll Make a Difference
- Architectural Engineering: Research, evaluate, and test cloud-native technologies to design the future direction of the product platform with security, scalability, and resilience built into the architecture.
- DevOps & CI/CD Design: Architect secure end-to-end automation pipeline (CI/CD) and DevOps standards and deployment standards that all product teams must follow.
- Security-by-Design: Embed cybersecurity controls including IAM, secrets management, encryption, vulnerability management, container security, and policy enforcement across the platform lifecycle.
- App-to-Infra Alignment: Collaborate with developers to ensure Java-based applications are optimized and secured for containerized environments (Kubernetes/Docker).
- Hybrid Modernization: Design secure integration between modern cloud-native stacks and legacy on-prem core banking systems while ensuring network segmentation, data protection, and regulatory compliance.
- Platform Resilience & Compliance: Ensure platform architecture supports high availability, disaster recovery, observability, auditability, and compliance with banking and security standards.
- Practical Validation: Conduct deep-dive testing, security reviews and "proof of concept" (PoC) work to ensure all architectural ideas are realistic, secure, and suitable for long-term growth.
What You’ll Bring
- Deep Technical Leadership: Extensive experience in architectural thinking coupled with a "builder" mindset. You can code the PoC for the architecture you design.
- Application & Security Savvy: Strong understanding of Java/J2EE application frameworks, secure coding principles and application behaviour in distributed, high-availability environments.
- DevOps Expertise: Proven track record in designing automated deployment workflows, integrating security scanning into CI/CD pipelines and container orchestration strategy.
- Cloud Security Knowledge: Strong knowledge of cloud security architecture, zero-trust principles, identity and access management (IAM), encryption, and workload protection
- Hybrid Knowledge: Mastery of both public cloud (Huawei, AWS, Azure) and on-prem hardware constraints (Storage, Network, Virtualization).
- Risk & Governance Awareness: Experience aligning architecture decisions with enterprise security policies, regulatory requirements, and operational risk management.
- Open & willing to travel locally and overseas as required to support business needs.
Technical Competencies
- Programming & Frameworks: Solid understanding of Java, secure application server configurations, API security, application server configurations, and microservices architecture.
- DevOps Ecosystem: Expert knowledge in designing and implementing CI/CD pipelines with integrated security tooling (SAST, DAST, SCA, container scanning), Jenkins, GitHub, and Jira integration.
- Container & Platform Security: Hands-on mastery of Kubernetes (K8s), Docker, container networking, runtime security, image hardening, and Kubernetes security best practices
- Identity & Access Management: Knowledge of RBAC, PAM, MFA, secrets management, certificate management, and privileged access controls.
- Orchestration: Hands-on mastery of Kubernetes (K8s), Docker, and container networking/security.
- Cloud Platforms: Architectural proficiency across Huawei Cloud, AWS, and Azure.
- Observability: Knowledge of designing monitoring and logging frameworks (e.g., Grafana, Prometheus, ELK) to support platform reliability.
- Infrastructure Security: Strong understanding of network security, firewalls, segmentation, WAF, endpoint protection, vulnerability management, and disaster recovery architecture.
- Compliance & Standards: Familiarity with banking and security standards such as PCI DSS, ISO 27001, CIS Benchmarks, and regulatory security requirements.
***Only local applicants who do not require visa/work permit will be considered***