Manager - Cybersecurity Architect (Offensive AI Security)
Mercedes-benz Singapore · Singapore
Job ObjectiveServe as an Offensive Cybersecurity Architect for conventional applications, AI-enabled applications, products and cloud platforms by assessing system designs, identifying security weaknesses and validating relevant findings. Use AI-assisted tools and automation to enhance penetration testing, vulnerability validation, evidence analysis and the quality, speed and consistency of security outputs.Translate technical observations into clear risk exposure statements, architectural considerations and reproducible evidence. Make findings transparent through structured documentation, reporting and communication, while ownership of risk treatment, remediation implementation, acceptance and closure remains with the respective business, product, platform and operational stakeholders.Tasks Description1. Application and AI Security Architecture AssessmentAssess conventional and AI-enabled application designs through threat modelling, trust-boundary analysis and abuse-case development.Use AI-assisted analysis to expand test scenarios, identify attack paths and improve the completeness and consistency of architecture assessments.Document architectural observations, risk exposure and security design options for stakeholder evaluation and action.2. AI-Assisted Penetration Testing, Validation and Findings CommunicationPerform or coordinate penetration testing and vulnerability assessments for conventional applications, AI-enabled applications, APIs, cloud-connected services and relevant products.Use AI-assisted automation to generate and execute test cases, analyse responses, correlate evidence and accelerate validation while maintaining human verification.Support the Vulnerability Alerting Process (VAP) by assessing8 high-priority vulnerabilities using criticality, exploitability, publicity and asset-context signals, and by contributing validated evidence for alerts and escalation.Validate reported vulnerabilities, confirm exploitability and potential business impact, reduce false positives and document reproducible evidence.Communicate findings, affected assets, risk exposure and technical considerations to accountable owners; remediation and closure remain with responsible stakeholders.3. Cloud Security and Global Vulnerability Detection (GVD) Exposure AnalysisCorrelate cloud asset inventory, vulnerability findings, exposure context, ownership data and business criticality.Support Global Vulnerability Detection (GVD) activities by reviewing internal asset scope, scan coverage and Qualys findings, and by linking relevant evidence to ServiceNow records for accountable stakeholder follow-up.Define and document risk exposure using exploitability, reachability, asset criticality and business context.Make ownership and exposure information transparent to the stakeholders responsible for treatment decisions and follow-up.Provide technical architecture observations and security options for cloud-hosted products and services.4. Secure Architecture AdvisoryFacilitate threat-modelling and secure design reviews with development and platform teams.Identify security control gaps and explain their technical and business exposure where required.Recommend architecture patterns, security requirements and treatment options for implementation by responsible teams.Provide clarification and technical consultation without owning implementation or remediation closure.5. AI-Enhanced Findings Transparency and Risk CommunicationUse AI-assisted analysis to correlate findings, affected assets, evidence, ownership and business context across conventional and AI-enabled applications.Verify generated outputs and maintain clear, traceable records that distinguish validated findings from unconfirmed observations.Define risk exposure and provide concise reports and briefings on technical implications, business relevance and treatment options.Monitor and report stakeholder-provided status while leaving treatment, implementation, acceptance and closure accountability with designated owners.QualificationsDegree in Computer Science, Cybersecurity, Information Technology, Software Engineering or a related field ; equivalent relevant professional experience may be considered.Relevant security certification in application security, cloud security, penetration testing or security architecture is beneficial.Training in secure software development, threat modelling, AI application security, AI-assisted penetration testing, security automation or cloud-native security is beneficial.Minimum 5 years of cybersecurity experience across product security, application security, cloud security, security architecture or related disciplines.Practical experience conducting threat modelling, penetration testing, vulnerability assessment and validation, and secure design reviews for conventional and AI-enabled applications.Experience using AI-assisted tools, automation, scripting and APIs to improve testing coverage, validation accuracy, evidence analysis and reporting efficiency.Experience documenting technical evidence, defining risk exposure and communicating findings clearly to technical and non-technical stakeholders.Strong technical judgement, stakeholder communication and advisory skills in distributed, multicultural environments.Strong knowledge of security architecture, product and application security, threat modelling, trust boundaries, abuse cases and secure design patterns for conventional and AI-enabled applications.Knowledge of AI application security, including adversarial prompt testing, guardrail by pass scenarios, data leakage, insecure integrations, model or agent abuse and related attack surfaces.Practical penetration-testing and vulnerability-validation skills for web applications, APIs, cloud-connected services and AI-enabled applications, including development of reproducible evidence.Ability to apply AI-assisted testing, scripting, APIs and workflow automation to generate testcases, support automated penetration testing, validate findings, correlate evidence and improve reporting outputs.Ability to critically verify AI-generated outputs, minimize false positives, protect sensitive information and maintain appropriate human oversight and traceability.Understanding of cloud assets, vulnerability findings, exposure context, ownership mapping, business criticality and secure SDLC practices.Working knowledge of vulnerability disclosure, researcher-submission triage, validation, ownership identification and risk communication.Ability to translate technical findings into transparent risk statements, business exposure, architectural considerations and treatment options for decision by accountable stakeholders.Please be informed that only shortlisted candidates will be notified.