Eurofins Scientific is an international life sciences company, providing a unique range of analytical testing services to clients across multiple industries, to make life and our environment safer, healthier and more sustainable. From the food you eat, to the water you drink, to the medicines you rely on, Eurofins laboratories work with the biggest companies in the world to ensure the products they supply are safe, their ingredients are authentic, and labelling is accurate.
Eurofins is dedicated to delivering testing services that contribute to the health and safety of society and the planet, and to its corporate responsibility to protect the environment and ensure diversity, equity, and inclusion across the entire network of Eurofins companies.
Job Description
Eurofins' Group Architecture Office offers consultancy enterprise and solution architecture services both at Group IT Solutions level and across the wider business areas of activity and supports numerous infrastructure and application related projects. We are looking for a talented Security Architect to join us as a trusted security advisor in multiple projects across a variety of business areas and geographies.
In the role, you willidentify major security deficiencies and definepragmatic approaches on how to remediate them at scale. It is your responsibility to ensure thatGroup Architecture, DevOps and Cloud Engineeringplatforms and solutions are securely architected, designed, built, configured, tested, and deployed as defined per security policies defined byEurofins IT Securityor standards and good practices.
As aSecurity Architectwithin our GSC Architecture Office, you will:
- Establish close relationships and collaborations withEurofins IT Security, operations, infrastructure, development, andGroup Architectureto ensure visibility and exchanges;
- Establish best practices forDevOps Teamssecurity practices and security testing;
- Contribute and follow-up on development and evolution of security strategies and roadmap and projects together withEnterprise, Solution and DevOps architectureand alsoEurofins IT Security;
- Drive new technologies or productevaluationthrough Proof-of-Concepts together with ProgramDevelopers andEurofins IT Security;
- Take the technical security leadership for platform and solution implementation and transformation together withEurofins IT SecurityandProgram Application Architects;
- Replace with Collaborate closely withEurofins IT Securityon architecture reviews, security assessments and vulnerability management. Ensure the adoption of secure application design and architecture techniques based on industry standards and well architecture frameworks;
- Developsecurity architecture design and blueprints for the target state and ensure their elaboration, validation, and communication withEurofins IT SecurityandSolution Architects;
- Convert and promote Security culture across allDevOps, Cloud and GSC IT Solutions Programs.
Qualifications
- Bachelor’s degree in IT, engineering or related;
- Active entry level security certification such as CompTIA Security+, Microsoft SC-900 (Security, Compliance, and Identity Fundamentals) or similar.
- Active entry level Cloud certification such as AZ-900: Microsoft Azure Fundamentals, AWS Certified Cloud Practitioner or similar.
- Minimum of 2 years of experience in security around any of the following areas: Cloud security, infrastructure security, software architecture design and application security;
- General knowledge of on-prem hosting technologies and Microsoft Azure hosting technologies;
- Knowledge of identity management, PKI solutions, log management and multifactor authentication tools;
- Knowledge of vulnerability management process and security assessment methodologies including penetration testing, SAST, DAST and SCA;
- Working knowledge of security standards and remediation of common vulnerabilities on software and infrastructure;
- Previous experiencein solution design principles, system development methodologies, and software lifecycles in a combination of system and application architectures;
- Good understanding of server management, virtualization, networking andsystems management;
- Working knowledge with CNAAP solutions.
- Good understanding of automated security tooling in DevOps environment;
- Ability to review new IT solutions from a security perspective and document outcomes, exceptions and mitigations;
- StrongEnglishcommunicationskills (written/oral) required.
Additional Information
- Bachelor’s degree in IT, engineering or related;
- Active entry level security certification such as CompTIA Security+, Microsoft SC-900 (Security, Compliance, and Identity Fundamentals) or similar.
- Active entry level Cloud certification such as AZ-900: Microsoft Azure Fundamentals, AWS Certified Cloud Practitioner or similar.
- Minimum of 2 years of experience in security around any of the following areas: Cloud security, infrastructure security, software architecture design and application security;
- General knowledge of on-prem hosting technologies and Microsoft Azure hosting technologies;
- Knowledge of identity management, PKI solutions, log management and multifactor authentication tools;
- Knowledge of vulnerability management process and security assessment methodologies including penetration testing, SAST, DAST and SCA;
- Working knowledge of security standards and remediation of common vulnerabilities on software and infrastructure;
- Previous experiencein solution design principles, system development methodologies, and software lifecycles in a combination of system and application architectures;
- Good understanding of server management, virtualization, networking andsystems management;
- Working knowledge with CNAAP solutions.
- Good understanding of automated security tooling in DevOps environment;
- Ability to review new IT solutions from a security perspective and document outcomes, exceptions and mitigations;
- StrongEnglishcommunicationskills (written/oral) required.
By clicking the link above or any third-party link within this posting, you are leaving this site and going to a third-party website where the third-party website's terms and privacy policy apply