Enterprise Security Architect - Data Security

Novartis
Madrid, Spain
7 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Microsoft Windows Control Objectives for Information and Related Technology (COBIT) Collaborative Software Cyber Security Data Security Desktop Virtualization Digital Signature Enterprise Architecture Framework Identity and Access Management Key Management Network Security Public Key Infrastructure
+5 more
Security Information and Event Management User Environment Management Software Vulnerability Management Togaf Information Technology

Job description

Summary Location: Barcelona, Spain; Tel Aviv, IsraelAbout The RoleThe Enterprise Security Architecture team is looking for an Enterprise Security Architect - Data Security, who will work across information security & risk management, with all information technology functions to ensure Novartis ‘Digital Workspace’ is designed and implemented as per defined policies, standards and industry good practices.They will be responsible for designing, implementing, and maintaining security controls for End User Computing (EUC), Microsoft 365, Voice and Video Collaboration platforms.This role requires close collaboration with Enterprise Architects and Functional Security Architects to ensure a holistic approach to security across the organization.The successful candidate will be a strong communicator with deep technical skills and, more importantly, a pragmatist who can think outside the box.The individual must be highly collaborative as they will need to influence functional leadership, project and application managers, architects, engineers and developers.Key ResponsibilitiesDevelop and enforce security policies and procedures related Data Security across Novartis businesses to meet business and regulatory requirementsDesign security measures and overall Data Security architecture for the IT landscape in line with the ISC policy frameworkTechnical lead for PQC readiness programSupport and continually review technology standards and controls related to Data Security and recommend information technology strategies, policies, and proceduresIdentify design problems within the Data Security domainSupport projects to evolve Data Security solutions from evaluation to implementation and assist the delivery of the operational modelSupport the auditing of security policies and proceduresManagement communication with key stakeholders and provide reports to managementProvide ongoing support to maintain the Data Security domain’s effectiveness and efficiency by defining, delivering, and supporting strategic plans for implementing information technologiesDevelop and maintain relationships with key stakeholders and vendorsSupport the direction of technological research by learning the organizational goals, strategies and business driversDevelop and maintain architecture diagrams and documentation related to Data Security processes and proceduresBreak down the strategic objectives to requirements on the solution portfolio and target architectureKey contributor on products, services and/or infrastructure strategies that require complex or advanced conceptualizationResearch and evaluate new Data Security technologies and make strategic security technology choices, directly supervising the quality of designs and implementation inside and between componentsWork with improvements, by participation in the development, of the architectural principles, processes, and standardsEssential RequirementsUniversity working and thinking level, degree in business/technical area or comparable education/experience15+ years of working experience in Security domain; minimum 5 years in architecture capacity5+ years of experience of working in or providing IT services to a large enterprise like NovartisExceptional understanding security domains like Digital Workspace, Data Protection, AI Security as well as good knowledge of Network Security, Identity and Access Management, SIEM, Vulnerability ManagementStrong understanding of core cryptography concepts (encryption, key exchange, hashing, digital signatures)Solid PKI expertise, including certificate lifecycle management, trust models, and enterprise PKI architecturesClear understanding of Post?Quantum Cryptography (PQC) concepts, quantum risks to current algorithms, and crypto?agility principlesAbility to assess quantum?vulnerable cryptographic usage and data protection controlsExperience designing data encryption architectures for data at rest and in transitKnowledge of key management and HSM/KMS solutionsFamiliarity with cryptographic standards and regulatory requirements (e.g., NIST)Exceptional understanding and knowledge of general IT infrastructure technology, systems and management processes, and experience of sourcing complex IT services, working closely with vendors and making full use of their capabilitiesGood knowledge of IT Project Management: Proven experience to initiate and manage projects that will affect other divisions, departments and functions, as well as the corporate environmentExperience with compliance requirements (e.g. SOX, GxQ / CSV, E?compliance, Records Management, Privacy), and knowledge of (information) risk management related standards or frameworks such as COSO, ISO **x, CobiT, ISO **, BS ***, NIST, ISF Standard of Good Practice and ITILStrong leadership experience, with excellent written and verbal communication and presentation skills at all levels of the organisation and experience in reporting to and communicating with senior level management (with and without IT background, with and without in-depth risk management background) on information risk topics; interpersonal and collaborative skills, as well as good mediation and facilitation skillsDesirableGood understanding and experience with Enterprise Architecture Frameworks like TOGAF will be an added advantageCommitment To Diversity & InclusionWe are committed to building an outstanding, inclusive work environment and diverse teams representative of the patients and communities we serve.Accessibility And AccommodationNovartis is committed to working with and providing reasonable accommodation to all individuals.If, because of a medical condition or disability, you need a reasonable accommodation for any part of the recruitment process, or in order to receive more detailed information about the essential functions of a position, please send an e?mail to and let us know the nature of your request and your contact information.Please include the job requisition number in your message.Benefits and RewardsAll the ways we’ll help you thrive personally and professionally.#J-**-Ljbffr

Requirements

University working and thinking level, degree in business/technical area or comparable education/experience 15+ years of working experience in Security domain; minimum 5 years in architecture capacity 5+ years of experience of working in or providing IT services to a large enterprise like Novartis Exceptional understanding security domains like Digital Workspace, Data Protection, AI Security as well as good knowledge of Network Security, Identity and Access Management, SIEM, Vulnerability Management Strong understanding of core cryptography concepts (encryption, key exchange, hashing, digital signatures) Solid PKI expertise, including certificate lifecycle management, trust models, and enterprise PKI architectures Clear understanding of Post?Quantum Cryptography (PQC) concepts, quantum risks to current algorithms, and crypto?agility principles Ability to assess quantum?vulnerable cryptographic usage and data protection controls Experience designing data encryption architectures for data at rest and in transit Knowledge of key management and HSM/KMS solutions Familiarity with cryptographic standards and regulatory requirements (e.g., NIST) Exceptional understanding and knowledge of general IT infrastructure technology, systems and management processes, and experience of sourcing complex IT services, working closely with vendors and making full use of their capabilities Good knowledge of IT Project Management: Proven experience to initiate and manage projects that will affect other divisions, departments and functions, as well as the corporate environment Experience with compliance requirements (e.g. SOX, GxQ / CSV, E?compliance, Records Management, Privacy), and knowledge of (information) risk management related standards or frameworks such as COSO, ISO **x, CobiT, ISO **, BS ****, NIST, ISF Standard of Good Practice and ITIL Strong leadership experience, with excellent written and verbal communication and presentation skills at all levels of the organisation and experience in reporting to and communicating with senior level management (with and without IT background, with and without in-depth risk management background) on information risk topics; interpersonal and collaborative skills, as well as good mediation and facilitation skills Desirable Good understanding and experience with Enterprise Architecture Frameworks like TOGAF will be an added advantage Commitment To Diversity & Inclusion

Benefits & conditions

We are committed to building an outstanding, inclusive work environment and diverse teams representative of the patients and communities we serve. Accessibility And Accommodation Novartis is committed to working with and providing reasonable accommodation to all individuals. If, because of a medical condition or disability, you need a reasonable accommodation for any part of the recruitment process, or in order to receive more detailed information about the essential functions of a position, please send an e?mail to and let us know the nature of your request and your contact information. Please include the job requisition number in your message. Benefits and Rewards All the ways we’ll help you thrive personally and professionally. #J-*****-Ljbffr

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

4:04 min

Embedding data security and applied ethics into developer education

Daniel Tao +3 · WWC 2024

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

41 sec

Massive client data loss and bio-digital storage

Chris Heilmann +1 · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

Videos

See all

Related articles

See all