Senior Security Architect

Verimatrix

Ismaning

Vor Ort

EUR 110.000 - 150.000

Vollzeit

Vor 5 Tagen
Sei unter den ersten Bewerbenden
Bewerbungsgenerator

Erhalte eine Antwort von diesem Arbeitgeber — ein Lebenslauf und ein Anschreiben, die genau auf die Eigenschaften eingehen, die gesucht werden.

Schaffe es an den ATS-Filtern vorbei

Zusammenfassung

Verimatrix in Ismaning, Germany, seeks a Senior Security Architect to own the security of our cloud infrastructure. Reporting to the CTO, you will define the technical direction for cloud security across our AWS estate and set the standard that engineering teams build to.

This hands-on role works close to the platform, guiding secure design, automation, incident response, and governance. You will mentor engineers, drive threat modelling, implement guardrails, and partner with product management

Qualifikationen

  • 8+ years in security engineering, incl. 5+ years on cloud.
  • Deep, practical expertise with AWS security services: IAM, KMS, Config, GuardDuty, CloudTrail, Security Hub, Inspector, WAF and Shield Advanced.
  • Strong infrastructure-as-code skills (Terraform) and scripting/automation (Python, Go).
  • Kubernetes and container security experience.
  • Working knowledge of identity protocols (OIDC, OAuth 2.0, SAML) and applied cryptography and PKI: key hierarchies, certificate lifecycle, secure key storage.
  • Experience with secure SDLC practices: threat modeling, secure design review, SAST/DAST, and penetration testing.
  • Experience leading incident response.
  • Strong communication skills: influence engineers and explain risk to non-security stakeholders in business terms.

Aufgaben

  • Design and own security controls across AWS estate: IAM, network segmentation, encryption, logging, secrets management.
  • Lead threat modelling and security architecture reviews with development teams.
  • Set cloud security policy and roadmap with security and platform leadership.
  • Partner with Product Management to define security requirements.
  • Build security into CI/CD: IaC scanning, container/base-image scanning, SBOM checks, policy-as-code, guardrails.
  • Maintain Terraform modules and golden patterns for secure paths.
  • Drive automated security tooling adoption, including vulnerability scanning and security agents.
  • Evaluate secure development tooling and IDE guardrails.
  • Improve detection coverage for cloud-native attack paths.
  • Lead incident response: runbooks and post-incident reviews.
  • Manage CSPM/CNAPP tooling and drive remediation.
  • Coordinate DAST and penetration testing programs across products.
  • Support ISO 27001 and EU Cyber Resilience Act compliance.
  • Mentor engineers on secure cloud design and act as security partner to platform, product, and operations teams.

Kenntnisse

Cloud security
AWS security
IaC Terraform
Python/Go scripting
Kubernetes security
Identity protocols
Secure SDLC
Incident response
Communication

Tools

Terraform
AWS Inspector
SAST/DAST

Jobbeschreibung

Role Overview

The Senior Security Architect will be accountable for the security of the cloud infrastructure behind those services: reporting to the CTO, he/she sets the technical direction for cloud security across our AWS estate and define the standard that engineering teams build to. This is a hands-on senior role, positioned close to the platform and influential rather than supervisory.

Key Responsibilities
Architecture and design
  • Design and own security controls across our AWS estate: IAM, network segmentation, encryption, logging, and secrets management.
  • Lead threat modelling and security architecture reviews for new services and major changes, working one-to-one with development teams on secure design.
  • Set cloud security policy and the security roadmap jointly with security and platform leadership.
  • Partner with Product Management to define and clarify security requirements.
Automation and secure-by-default engineering
  • Build security into CI/CD: IaC scanning, container and base-image scanning, dependency and SBOM checks, policy-as-code, and automated guardrails.
  • Write and maintain Terraform modules and golden patterns so that the secure path is the easy path for product engineers.
  • Drive adoption of automated security tooling, including cloud-native vulnerability scanning and security agents (e.g. AWS Inspector).
  • Evaluate and recommend secure development tooling, including IDE-integrated security and AI coding-assistant guardrails.
Detection and incident response
  • Improve detection coverage for cloud-native attack paths.
  • Act as senior responder for cloud security incidents: build and maintain runbooks, and run post-incident reviews that produce durable fixes.
  • Assess the impact of vulnerabilities and exploits, and own the incident response process end to end.
Vulnerability and exposure management
  • Manage CSPM/CNAPP tooling: triage findings and drive remediation with the owning teams.
  • Analyze the impact of WAF rules on our products.
  • Coordinate DAST and penetration testing programs across products.
Governance, compliance, and enablement
  • Support ISO 27001 with evidence and control implementation.
  • Support regulatory security obligations, including the EU Cyber Resilience Act (CRA).
  • Lead security reviews of new third-party tools.
  • Mentor engineers on secure cloud design and act as security partner to the platform, product, and operations teams.
Qualifications
  • 8+ years in security engineering, including at least 5 focused on cloud.
  • Deep, practical expertise with the AWS security suite: Organizations and SCPs, KMS, Config, GuardDuty, CloudTrail, Security Hub, Inspector, WAF, and Shield Advanced.
  • Strong infrastructure-as-code skills (Terraform) and scripting and automation (Python, Go).
  • Kubernetes and container security experience.
  • Working knowledge of identity protocols (OIDC, OAuth 2.0, SAML) and of applied cryptography and PKI: key hierarchies, certificate lifecycle, and secure key storage.
  • Experience with secure SDLC practices: threat modeling, secure design review, SAST/DAST, and penetration testing.
  • Experience leading incident response.
  • Strong communication skills: you can influence engineering teams you do not manage and explain risk to non-security stakeholders in terms of business impact.
Nice to have
  • Certifications such as AWS Certified Security - Specialty, AWS Certified Advanced Networking - Specialty, AWS Certified Solutions Architect - Professional, CISSP, or CCSP.
  • Experience with media security, DRM, conditional access, or anti-piracy technologies.
  • Knowledge of the EU Cyber Resilience Act and related product security regulations.
  • Experience with HSMs and cryptographic key management.
  • Familiarity with on-premises and cloud security tooling supporting the SDLC.
Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Security Architect
Security Architect

Coltech • Deutschland

Vor Ort
EUR 110.000 - 170.000
Security Architect - FinTech
Security Architect - FinTech

SES • Deutschland

Remote
EUR 90.000 - 120.000
Security Architect, Strong Financial Experience, MST OR CST Time Zone - ZL
Security Architect, Strong Financial Experience, MST OR CST Time Zone - ZL

SES • Deutschland

Remote
EUR 90.000 - 130.000
Cyber Security Engineer
Cyber Security Engineer

Apollo Solutions • Deutschland

Vor Ort
EUR 70.000 - 120.000
Cybersecurity Engineer - Cloud, Ops (human)
Cybersecurity Engineer - Cloud, Ops (human)

NEURA Robotics • Riederich

Vor Ort
EUR 80.000 - 120.000
Senior Security Assurance Solutions Architect, AWS Security Assurance Services
Senior Security Assurance Solutions Architect, AWS Security Assurance Services

Amazon Web Services (AWS) • München

Vor Ort
EUR 110.000 - 160.000
Principal Info Sec Technologist – Virtual
Principal Info Sec Technologist – Virtual

Jobtailor • Deutschland

Remote
EUR 130.000 - 170.000
Senior Security Assurance Solutions Architect, AWS Security Assurance Services
Senior Security Assurance Solutions Architect, AWS Security Assurance Services

Amazon Web Services (AWS) • Berlin

Vor Ort
EUR 120.000 - 180.000
Lead Cloud Security Architect, GCP
Lead Cloud Security Architect, GCP

Jobtailor • Deutschland

Remote
EUR 110.000 - 150.000
Senior Security Engineer – Sec Ops
Senior Security Engineer – Sec Ops

Jobtailor • Deutschland

Remote
EUR 120.000 - 180.000