Application Security Architect

Liebherr
Madrid, Spain
21 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English, French, German

Tech stack

Kubernetes Security Amazon Web Services Microsoft Azure Cloud Computing Security Cyber Security Continuous Integration DevOps Github Identity and Access Management OAuth Open Web Application Security Systems Development Life Cycle
+16 more
Zero Trust Network Access JSON Web Token Sherwood Applied Business Security Architecture Security Assertion Markup Language (SAML) Software Engineering Working Model 2D Google Cloud Software Security Kubernetes Information Technology Devsecops Docker Jenkins Static Application Security Testing Microservices Dynamic Application Security Testing

Job description

The Application Security Architect (m/f/d) designs and implements secure application architectures, defining security controls and policies to protect applications from threats.They provide strategic guidance to developers and security teams.The working location for this position will be in Madrid city where we are currently setting up a new office.We operate a hybrid model, requiring at least 40% of the working time on-site.Creating passion: your responsibilities Develop and enforce application security architecture frameworks, policies, standards, and best practices to align with compliance requirements (e.G. OWASP, NIST, ISO **) Review and approve application security designs while ensuring secure software development and architecture Integrate security into the software development lifecycle (SDLC) by collaborating with development teams and enabling DevSecOps practices Adopt and promote a security-by-design approach with the different stakeholders Conduct threat modeling, security reviews, and risk assessments to proactively identify and mitigate vulnerabilities Evaluate, recommend, and oversee security tools and testing solutions (SAST, DAST, IAST) to strengthen application security Define security strategies for applications (e.G. IAM) and Implement Security Principles such as Zero Trust Actively contribute to the Coporate Information Security architecture community, sharing insights and best practices Collaborate with IT, EA, DevOps amd Engineering Team to align security Objectives Contributing your strengths: your qualifications Bachelor’s/Master’s in Cybersecurity, Computer Science, or related field 3+ years in cybersecurity, preferably in application security architecture role Following certificates are preferred; CISSP, SABSA as well asCloud certifications (AWS, Azure, or GCP) English is a Must, German and French are a plus Good understanding of cybersecurity frameworks and standards (ISO **, NIST) Expertise in OWASP, SSDLC, and DevSecOps, with strong knowledge of secure software architecture Strong understanding of microservices security, API security, and IAM (e.G. OAuth, SAML, JWT) Knowledge of cloud-native security and CI/CD integration (e.G. Jenkins, GitHub Actions) Experience with container security and cloud platforms (e.G. AWS, Azure, GCP, Docker, Kubernetes) Our commitment to you: your benefits At Liebherr, we believe people are at the heart of our success.As part of our international team, you’ll enjoy a secure role in a family-owned company that values innovation, collaboration, and long-term career growth: Competitive compensation and benefits package that recognizes your expertise Flexible and hybrid working model Creative freedom and responsibility to shape processes and solutions in our global transformation Continuous learning and development with tailored training and certification opportunities Meal vouchers Life and accident insurance Option to include a premium private health insurance package as part of the flexible remuneration A safe, stable and international workplace within a trusted family business that invests in people Please only use the online application option.Please note that we do not accept applications via recruitment agencies for this position.

Requirements

practices Collaborate with IT, EA, DevOps amd Engineering Team to align security Objectives Contributing your strengths: your qualifications Bachelor’s/Master’s in Cybersecurity, Computer Science, or related field 3+ years in cybersecurity, preferably in application security architecture role Following certificates are preferred; CISSP, SABSA as well asCloud certifications (AWS, Azure, or GCP) English is a Must, German and French are a plus Good understanding of cybersecurity frameworks and standards (ISO *****, NIST) Expertise in OWASP, SSDLC, and DevSecOps, with strong knowledge of secure software architecture Strong understanding of microservices security, API security, and IAM (e.G. OAuth, SAML, JWT) Knowledge of cloud-native security and CI/CD integration (e.G. Jenkins, GitHub Actions) Experience with container security and cloud platforms (e.G. AWS, Azure, GCP, Docker, Kubernetes) Our commitment to you: your benefits At Liebherr, we believe people are at the heart of our success.

Benefits & conditions

As part of our international team, you’ll enjoy a secure role in a family-owned company that values innovation, collaboration, and long-term career growth: Competitive compensation and benefits package that recognizes your expertise Flexible and hybrid working model Creative freedom and responsibility to shape processes and solutions in our global transformation Continuous learning and development with tailored training and certification opportunities Meal vouchers Life and accident insurance Option to include a premium private health insurance package as part of the flexible remuneration A safe, stable and international workplace within a trusted family business that invests in people Please only use the online application option.Please note that we do not accept applications via recruitment agencies for this position.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · WWC 2025

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · WWC Europe 2026

2:47 min

Exploring career opportunities and recruitment open positions

Kurt Eder · LIVE

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

Videos

See all

Related articles

See all