Security Architect, hibrido

Michael Page
Spain
3 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
2 years minimum
Working hours
Regular working hours

Tech stack

Software System Penetration Testing Architectural Patterns Cloud Computing Security Control Objectives for Information and Related Technology (COBIT) Cyber Security Information Security Management Information Systems Security Architecture Professional Network Security Software Maintenance Togaf CIS Benchmarks

Job description

Security Architect Responsibilities: Support the development of security architectures, including target states, transition plans and roadmaps aligned to business objectives, IT strategy and security risk appetite. Provide risk-based security architecture guidance to engineering, infrastructure, application, architecture, project and business teams. Review solution, application, infrastructure and integration designs to ensure secure-by-design principles, appropriate technology selection and alignment with PageGroup security policies and standards. Support security architecture activities across BAU services, projects, programmes and material change initiatives, ensuring security requirements are identified, designed, implemented and governed. Perform threat modelling, threat analysis and architecture risk assessments to identify threats, attack paths, vulnerabilities, security weaknesses and appropriate mitigating controls. Define, document and maintain security requirements, control specifications, architectural patterns, standards, baselines and implementation guidance, ensuring alignment with business risk appetite and applicable security standards. Conduct security architecture reviews and implementation assurance activities to validate that agreed security controls and requirements have been effectively implemented. Review remediation plans and support the closure of security findings, defects and design issues. Participate in architecture governance forums, change reviews and security assurance activities, providing advice on security risks and compliance with security standards. Conduct independent security reviews and produce technical reports, recommendations and supporting documentation, including working with third parties where required. Maintain awareness of emerging technologies, threats and security trends, recommending updates to standards, controls and guidance where appropriate. Support continuous improvement activities that strengthen the security

Requirements

posture of existing technology platforms and services. High visibility and business impact Opportunity to grow as a strategic Security Architect Required experience: 5+ years of experience working in a specialist IT/technical/architect role. 3+ years of experience in an information security-focused role. Experience working in a multi-vendor environment. Experience securing and working with enterprise-grade systems and applications. Good IT security background, including knowledge of security architectures, cloud security, network security, information security best practices, and best-practice operating models and processes. Preferred experience: 2+ years delivering security risk assessments in a global IT environment. Detailed technical knowledge relating to hardware and software. Experience performing threat modelling using recognised methodologies (e.g. STRIDE). Experience conducting architecture risk assessments and security design reviews. Experience supporting security assurance activities, including penetration testing and findings remediation. Familiarity with NIST Cybersecurity Framework, CIS Controls and ISO 27001. Experience operating within formal architecture governance processes. Knowledge of principles and practices involved in the development and maintenance of software solutions, architectures and service delivery. Experience with regulatory compliance and information security management frameworks (e.g., ISO 27001, NIST, GDPR). Experience deploying and operating information security risk management processes. Familiarity with standard IT process and control frameworks, such as ITIL, IT4IT, COBIT and TOGAF. Skills: Great communication skills, capable of engaging effectively from engineering levels to C-Level executives. Analytical thinking and problem-solving abilities, including troubleshooting and adapting to significant project cha

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.empleate.gob.es

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:15 min

Auditing container configurations against CIS benchmark security standards

Madhu Akula · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

3:39 min

Validating data queries and infrastructure security configurations

Philipp Krenn · WWC 2023

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all