20h ago
New

Senior Security Lead

VietnamVietnam·Ho Chi Minh Citysenior
EngineeringSecurity
0 views0 saves0 applied

Quick Summary

Overview

ZALORA is Asia’s leading online fashion, beauty and lifestyle destination, part of Global Fashion Group. As one of the region’s pioneer large scale e-commerce platforms,

Technical Tools
EngineeringSecurity

ZALORA is Asia’s leading online fashion, beauty and lifestyle destination, part of Global Fashion Group. As one of the region’s pioneer large scale e-commerce platforms, ZALORA has established a strong presence throughout the region, particularly in Singapore, Indonesia, Malaysia, Brunei, the Philippines, and Hong Kong, enjoying over 50 million visits per month.

About the Role

~1 min read

Zalora, one of GFG’s e-commerce platforms, is hiring a security leader to build and run day-to-day security for Zalora — leading, staffing, and prioritizing the work of a small security team, in close collaboration with GFG’s group-level security function. This is a “player-coach” role: you align with the Group CISO’s overall security strategy, but you own how that strategy gets executed for Zalora, staying hands-on where it matters — reviewing architectures, hardening cloud environments, and acting as the senior technical escalation point when incidents happen.

You’ll work closely with Zalora engineering and business stakeholders to keep secure-by-design practices in place, including for AI/LLM features, while managing Zalora’s security team and coordinating external specialist consultants when needed.

  • Lead, mentor, and grow Zalora’s security team — set priorities, review work, and develop team members’ skills.
  • Own hiring and resourcing input for the team, including when to bring in external specialist consultants versus building in-house capability.
  • Act as the primary point of contact between security and Zalora business/engineering leadership, translating security risk into business terms and negotiating trade-offs.
  • Represent Zalora’s security posture and priorities in group-level conversations with the Global CISO organization.
  • Execute security architecture reviews for new and existing systems, and validate cloud security posture (primarily AWS, also GCP).
  • Implement and maintain IAM strategies, zero trus t controls, and infrastructure-as-code security.
  • Integrate security automation into CI/CD pipelines and DevSecOps workflows.
  • Secure containerized environments (Docker, Kubernetes).
  • Run threat modeling, SAST/DAST, and mobile application security testing on key systems.
  • Review AI-driven features and LLM integrations for risks such as prompt injection, data leakage, and supply chain vulnerabilities, and recommend concrete mitigations.
  • Apply existing AI/LLM security standards (e.g., OWASP Top 10 for LLM Applications) to real reviews, rather than authoring group-wide policy.
  • Act as the senior technical escalation point during active incidents, leading technical response and remediation.
  • Run penetration testing and red-team exercises (internally or via external consultants), and track findings through to fix.
  • Manage relationships with external vendors and specialist consultants for pentesting, AI security, and peak-demand coverage.

Requirements

~1 min read
  • 7–10+ years of hands-on experience in security engineering, product security, or infrastructure security (not purely strategy/GRC roles).
  • Comfortable being the technical decision-maker under pressure — e.g., during a live incident or a contested architecture review.
  • Able to explain a technical finding (e.g., a vulnerability or misconfiguration) clearly to a non-technical stakeholder.
  • Experience leading or building a security team — direct people-management experience preferred, technical/task leadership of a team at minimum.
  • Experience in fashion or retail e-commerce is a plus, not required.
  • Strong, hands-on AWS security experience (IAM, network security, security services); working knowledge of GCP.
  • Practical experience with SAST/DAST tooling, threat modeling, and mobile application security testing.
  • Working knowledge of AI/ML security risks and frameworks (OWASP Top 10 for LLM Applications, NIST AI RMF), with real experience reviewing LLM-integrated features or third-party AI tools.
  • Experience securing containerized environments (Docker, Kubernetes) and CI/CD pipelines.
  • Comfortable running or supporting penetration tests and red-team exercises, including remediation follow-through.
  • Track record of giving technical guidance and unblocking engineers day-to-day, as well as managing team performance and development — not just high-level mentorship.
  • Able to work with engineering and business stakeholders, including senior leadership, to get security fixes prioritized, shipped, and communicated in business terms.
  • Comfortable balancing GFG group-level security standards with Zalora’s local regulatory needs across its markets.

ZALORA exists for the millions of fashion consumers in Asia seeking a shopping experience focused on their unique styles, trends and fit. As Asia’s leading online fashion destination, ZALORA was founded in 2012 and has a presence in Singapore, Indonesia, Malaysia & Brunei, the Philippines, Hong Kong and Taiwan. ZALORA’s localised sites offer an extensive collection of top international and local brands as well as our own in-house labels across apparel, shoes and accessories for men and women. ZALORA is part of Global Fashion Group, the world's leader in online fashion for emerging markets.

ZALORA is not obligated to accept resumes from any third parties on behalf of potential candidates for any position (advertised or otherwise) by any means, unless ZALORA has executed a written agreement with such third party and has expressly requested such third party for candidate referrals. Third parties who provide unsolicited resumes of candidate(s) shall waive and forfeit all rights to claim for any placement fees or referral fees in the event that such candidate is eventually engaged or employed by ZALORA or Global Fashion Group.

Location & Eligibility

Where is the job
Ho Chi Minh City, Vietnam
On-site at the office
Who can apply
VN

Listing Details

Posted
September 28, 2026
First seen
September 28, 2026
Last seen
September 28, 2026

Posting Health

Days active
0
Repost count
0
Trust Level
56%
Scored at
September 28, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

Senior Security Lead