Ajip.ai
ajip.ai
រកការងារប្រព័ន្ធបង្កើតប្រវត្តិរូប
Ajip.aiajip.ai

AI talent intelligence platform for Cambodia and Southeast Asia.

Job Seekers

  • Browse Jobs
  • Profile Builder
  • Career Advice
  • Salary Guide

Employers

  • Post a Job
  • Find Talent
  • Pricing
  • Resources

ajip.ai

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

Browse jobs

Cities

  • Phnom Penh jobs
  • Siem Reap jobs
  • Battambang jobs
  • Sihanoukville jobs

Districts

  • BKK1 jobs
  • Toul Kork jobs
  • Daun Penh jobs
  • Sen Sok jobs
  • Chamkarmon jobs

Industries

  • Technology jobs
  • Banking & Finance jobs
  • Sales & Marketing jobs
  • Hospitality jobs
  • Operations jobs

Types

  • Full-time jobs
  • Part-time jobs
  • Internship jobs
  • Contract jobs
Site directory

© 2026ajip.ai · Ajip Consulting. All rights reserved.

SupportPrivacyTerms
  1. Home
  2. /
  3. Jobs
  4. /
  5. CONTRACT
  6. /
  7. Senior Information Security Architect – AI Security
Back to jobs
ABA BankHead OfficeActive opening
ABA Bank

Senior Information Security Architect – AI Security

SecurityPosted 9 hr ago

Location

Head Office

Job Type

CONTRACT

Work Mode

On-site

Apply Now

About the role

  • p>ABA Bank is seeking a Senior Information Security Architect with expertise in security architecture, risk management, network and platform security, and the secure adoption of AI, supported by strong financial services experience.</p><p><br /></p><p>Based within the Bank's second-line Information Security function, this role is responsible for defining, maintaining, and assuring the security architecture that protects customer and financial data, as well as critical banking services across ABA's on-premises, cloud, third-party, and AI-enabled environments.
  • The role establishes security standards and design patterns, provides independent assurance and challenge to technology teams, and ensures emerging technologies, especially generative and agentic AI, are adopted securely, resiliently, and in compliance with regulatory requirements.</p><p><br /></p><p>As a strategic and advisory role, it enables ABA's digital and AI transformation by embedding security from the outset and ensuring alignment with the National Bank of Cambodia's Technology and Cyber Risk Management Guidelines (TCRMG), PCI DSS, the SWIFT Customer Security Programme, ISO/IEC 27001, and parent group expectations.</p><p><strong>1.
  • Security architecture and design authority</strong></p><ul><li>Define, maintain and communicate ABA's target security architecture, reference architectures, security design patterns and architectural standards spanning infrastructure, networks, applications, data, cloud and AI platforms.</li><li>Provide independent security design review and formal assurance for new systems, major changes, integrations and third-party services before they proceed through change approval, recording residual gaps as accepted risks with named owners.</li><li>Own and maintain the security architecture roadmap, aligning it to the Information Security strategy, the IT strategy and the Bank's business objectives, and identifying architectural debt for planned remediation.</li></ul><p><strong>2.
  • Threat modelling and security risk assessment</strong></p><ul><li>Lead structured threat modelling for new and existing systems, prioritising internet-facing services, payment and core banking systems, privileged access paths and AI-enabled services.</li><li>Apply recognised methodologies (for example STRIDE, attack trees, and MITRE ATT&amp;CK-informed adversary modelling) and translate technical findings into business risk statements with costed, proportionate treatment options.</li><li>Provide architectural input to risk assessments, control design and the Bank's information security risk register, and validate that agreed controls are actually effective in the deployed design.</li></ul><p><strong>3.
  • AI security architecture and governance</strong></p><ul><li>Define the security architecture, control patterns and guardrails for the Bank's adoption of AI, covering model hosting and inference, data flows and residency, retrieval-augmented generation, prompt and output handling, tool and connector access, agentic autonomy limits, logging and human oversight points.</li><li>Assess AI use cases and platforms against recognised references including the OWASP Top 10 for LLM Applications (2026), the OWASP Top 10 for Agentic Applications, the NIST AI Risk Management Framework, MITRE ATLAS and ISO/IEC 42001.</li><li>Design architectural mitigations for AI-specific risk classes: prompt injection, sensitive information disclosure, excessive agency, data and model poisoning, supply chain compromise, improper output handling and unbounded consumption.
  • Apply a containment-first principle: assume the model can be manipulated and constrain the blast radius accordingly.</li><li>Assure the AI supply chain, including model and dataset provenance, embedded AI features in third-party and SaaS products, plugins and connectors, and contractual controls over data use, retention and training.</li><li>Assess and advise on adversarial use of AI against the Bank and its customers, including deepfake-enabled fraud, AI-assisted social engineering and AI-accelerated malware development.</li><li>Support the secure and effective use of AI within the security function itself, and work with Data Governance, Legal, Compliance and Operational Risk to ensure AI deployments meet data protection and regulatory expectations.</li></ul><p><strong>4.
  • Cloud, network and platform security architecture</strong></p><ul><li>Define secure architecture for hybrid and cloud environments, including identity-centric and zero trust design, network segmentation and micro-segmentation, secure connectivity, and workload and container security.</li><li>Set architectural standards for edge protection (WAF, DDoS mitigation, bot management, API security), remote access, and secure exposure of digital banking channels and APIs.</li><li>Set hardening baselines and secure configuration standards for Windows and Linux platforms, and define cryptographic standards, key and certificate management, and the Bank's roadmap towards post-quantum readiness.</li></ul><p><strong>5.
  • Security technology evaluation and control selection</strong></p><ul><li>Evaluate, pilot and recommend security technologies and controls, assessing control efficacy, integration cost, operational burden and total cost of ownership, and avoiding duplication across the existing toolset.</li><li>Provide technical input to vendor due diligence, third-party risk assessment and concentration risk analysis, including assessment of vendors' own AI and security practices.</li></ul><p><strong>6.
  • Regulatory compliance, audit and assurance</strong></p><ul><li>Ensure architectural compliance with NBC TCRMG, PCI DSS, SWIFT CSP, ISO/IEC 27001 and applicable parent-group standards, and interpret new or revised regulatory requirements into concrete architectural change.</li><li>Support internal audit, external audit, regulatory examinations and parent-company reviews with technical expertise, evidence and architecture documentation, and own remediation of architecture-related findings.</li><li>Maintain current, audit-ready architecture documentation, including data flow diagrams, trust boundaries and control mappings.</li></ul><p><strong>7.
  • Advisory, enablement and stakeholder engagement</strong></p><ul><li>Act as trusted security adviser to IT, Digital, Data, Operations, Compliance and business stakeholders, engaging early in initiatives to shape design rather than block delivery.</li><li>Mentor development and infrastructure teams on secure design, secure coding and secure use of AI coding assistants, and contribute to security champion and community-of-practice activity.</li><li>Prepare and present architecture positions, risk decisions and technology recommendations to senior management and relevant governance committees.</li></ul><p><strong>8.
  • Incident response, resilience and continuous improvement</strong></p><ul><li>Provide architectural input to incident response planning, playbooks and tabletop exercises, and act as an escalation point for architecture and design questions during major incidents.</li><li>Lead post-incident architectural root cause analysis and drive structural remediation rather than point fixes.</li><li>Interpret penetration test, red and purple team, threat intelligence and vulnerability findings for systemic architectural weakness, and feed conclusions back into standards and reference architectures.</li></ul><ul><li>Bachelor's degree in Computer Science, Information Technology, Engineering or a related discipline.
  • A postgraduate qualification in information security or a related field is an advantage.
  • Equivalent demonstrable experience will be considered.</li><li>Minimum 8 years in cybersecurity, infrastructure or software engineering, including at least 4 years in a dedicated security architecture role.</li><li>Demonstrable experience in banking, financial services or another regulated industry, with working knowledge of the sector's threat landscape and supervisory expectations.</li><li>Track record of producing security architecture artefacts that were adopted in production: reference architectures, design patterns, standards, threat models and design review outcomes.</li><li>Experience operating in a second-line or assurance capacity, exercising design authority and constructive challenge over teams the role holder does not manage.</li><li>Strong foundation in networking protocols, firewalls, VPNs, IDS/IPS, network segmentation and zero trust architecture.</li><li>Deep understanding of Windows and Linux operating systems, directory services, privileged access and platform hardening.</li><li>Practical experience with security architecture in cloud environments (AWS, Azure or Google Cloud), including identity, workload and data protection controls.</li><li>Working knowledge of SIEM, EDR, IAM and PAM, NAC, DLP, email and web security, and edge security platforms providing WAF, DDoS and bot protection (for example Cloudflare).</li><li>Sound grasp of application security, secure SDLC, API security and cryptography, including key and certificate management.</li><li>Expertise in risk management and control frameworks, for example NIST CSF and SP 800-53, ISO/IEC 27001 and 27002, ISO 31000, and governance frameworks such as COBIT.</li><li>Familiarity with financial sector regulatory requirements, including NBC TCRMG, PCI DSS and SWIFT CSP.</li><li>Demonstrable understanding of the security risks introduced by generative and agentic AI, and of the architectural controls that mitigate them.</li><li>Familiarity with AI security and governance references such as the OWASP Top 10 for LLM Applications, the OWASP Top 10 for Agentic Applications, the NIST AI Risk Management Framework, MITRE ATLAS and ISO/IEC 42001.</li><li>Understanding of how AI is embedded in enterprise and SaaS products, and of the data protection, residency and vendor-contractual questions this raises for a bank.</li><li>Evidence of continuous learning in this area, given the pace of change.
  • Candidates without direct AI security experience but with strong architecture fundamentals and demonstrable capacity to build the capability will be considered.</li><li>Fluent written and spoken English, with the ability to produce clear, professional architecture documentation, standards and reports to audit-ready quality.</li></ul>.

About ABA Bank

Visit Website

More at ABA Bank

Other open roles at this company

5 open

Loan Recovery Supervisor

Prey Veng Provincial BranchINTERNSHIP

Senior Mortgage Loan Officer

Chraoy Changvar BranchCONTRACT

Mortgage Loan Officer

Mao Tse Toung BranchCONTRACT

Small Business Loan Supervisor

Mondul Kiri Provincial BranchCONTRACT

Accounting and Administrative Intern

Ou Baek K Am BranchINTERNSHIP

Similar openings

Related jobs

Similar openings in CONTRACT

View all jobs
  • Senior Mortgage Loan OfficerABA Bank - Head Office
  • Loan Recovery Operations OfficerABA Bank - Head Office
  • Merchant Support OfficerABA Bank - Head Office
  • Information Security AnalystABA Bank - Head Office
  • Inbound Sales Performance Management SpecialistABA Bank - Head Office
  • QR Merchant Acquisition ConsultantABA Bank - Head Office
  • Cash Operations Branch Support OfficerABA Bank - Head Office
  • P-File Management InternABA Bank - Head Office