Enterprise Security Architect - Data Security

Novartis
Barcelona, Spain
30 days ago
Apply on www.buscojobs.com.es
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Microsoft Windows Control Objectives for Information and Related Technology (COBIT) Collaborative Software Data Security Desktop Virtualization Identity and Access Management Key Management Network Security Public Key Infrastructure Security Information and Event Management Software Vulnerability Management Information Technology
+1 more
GXP

Job description

Experteer Overview In this role you will design, implement and maintain data security controls across Novartis’ IT landscape, aligning with the ISC policy framework.You will work closely with Enterprise Architects and functional security leaders to secure EUC, Microsoft 365, and collaboration platforms within the Digital Workspace.You’ll lead PQC readiness and oversee policy enforcement, standards, and strategic security initiatives with vendor partners.The role requires strong collaboration and clear communication with senior stakeholders to drive secure, compliant digital transformation.Compensaciones / Beneficios * Develop and enforce Data Security policies across the business to meet regulatory and business needs * Design Data Security architecture for the IT landscape aligned with ISC framework * Technical lead for PQC readiness program * Review and support technology standards, controls, and IT strategies related to Data Security * Identify design issues within the Data Security domain and propose solutions * Support projects from evaluation to implementation and operational model delivery * Audit security policies and procedures and report to management * Maintain strategic plans and relationships with stakeholders and vendors to ensure Data Security effectiveness * Create architecture diagrams and documentation for Data Security processes * Translate strategy into concrete requirements for the solution portfolio and target architecture * Contribute to product, service, or infrastructure strategies requiring complex conceptualization * Research and evaluate new Data Security technologies and supervise design/implementation quality * Improve architectural principles, processes, and standards through ongoing participation * Assist in vendor engagement and leverage external capabilities to support security goals Responsabilidades * 15+ years in Security with at least 5 years in an architecture capacity * 5+ years in IT services to a large enterprise * Strong knowledge of Digital Workspace, Data Protection, AI Security, Network Security, IAM, SIEM, Vulnerability Management * PKI expertise including certificate lifecycle management and enterprise PKI * Understanding of Post-Quantum Cryptography (PQC) and crypto?agility * Experience designing data encryption architectures (data at rest/in transit) * Knowledge of key management and HSM/KMS solutions * Familiarity with cryptographic standards and regulatory requirements (e.g., NIST) * Solid understanding of IT infrastructure, management processes, and vendor collaboration * Experience with IT project management and cross-division collaboration * Experience with compliance standards (SOX, GxP/CSV, E?compliance, Records Management, Privacy) and risk management frameworks (COSO, ISO **x, CobiT, ISO **, BS ****, NIST, ISF) * Strong leadership, and ability to communicate with senior management and diverse stakeholders Requisitos principales *

Requirements

evaluate new Data Security technologies and supervise design/implementation quality * Improve architectural principles, processes, and standards through ongoing participation * Assist in vendor engagement and leverage external capabilities to support security goals Responsabilidades * 15+ years in Security with at least 5 years in an architecture capacity * 5+ years in IT services to a large enterprise * Strong knowledge of Digital Workspace, Data Protection, AI Security, Network Security, IAM, SIEM, Vulnerability Management * PKI expertise including certificate lifecycle management and enterprise PKI * Understanding of Post-Quantum Cryptography (PQC) and crypto?agility * Experience designing data encryption architectures (data at rest/in transit) * Knowledge of key management and HSM/KMS solutions * Familiarity with cryptographic standards and regulatory requirements (e.g., NIST) * Solid understanding of IT infrastructure, management processes, and vendor collaboration * Experience with IT project management and cross-division collaboration * Experience with compliance standards (SOX, GxP/CSV, E?compliance, Records Management, Privacy) and risk management frameworks (COSO, ISO **x, CobiT, ISO **, BS ****, NIST, ISF) * Strong leadership, and ability to communicate with senior management and diverse stakeholders Requisitos principales *

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:41 min

Protecting etcd databases using Key Management System plugins

Alex Soto Alex Soto · LIVE

4:04 min

Embedding data security and applied ethics into developer education

Daniel Tao +3 · World Congress 2024

3:13 min

Core components of the internal Optimize ecosystem

Dominik Schneider Dominik Schneider · World Congress 2025

5:21 min

Protecting infrastructure with the shared responsibility model

Mustafa Toroman · World Congress 2023

3:03 min

Balancing robust code verification with user liability paradigms

John Woods John Woods · LIVE

41 sec

Massive client data loss and bio-digital storage

Chris Heilmann +1 · LIVE

Videos

See all

Related articles

See all