Senior Security Architect

Verimatrix

München

Vor Ort

EUR 120.000 - 170.000

Vollzeit

Vor 11 Tagen
Bewerbungsgenerator

Mach aus dieser Rolle ein Vorstellungsgespräch — ein Lebenslauf und ein Anschreiben, die darauf ausgerichtet sind, was dieser Arbeitgeber sucht.

Schaffe es an den ATS-Filtern vorbei

Zusammenfassung

Verimatrix is seeking a Senior Security Architect to own security for our AWS-based cloud infrastructure. You will shape security controls, drive threat modelling, and partner with product and platform teams to embed security-by-default across services.

You will lead incident response, manage CSPM/CNAPP tooling, and mentor engineers on secure cloud design while advancing a robust security roadmap in a fast-moving environment.

Qualifikationen

  • 8+ years in security engineering, including at least 5 focused on cloud.
  • Deep, practical expertise with the AWS security suite: IAM, KMS, Config, GuardDuty, CloudTrail, Security Hub, Inspector, WAF, Shield Advanced.
  • Strong infrastructure-as-code skills (Terraform) and scripting (Python, Go).
  • Kubernetes and container security experience.
  • Working knowledge of identity protocols (OIDC, OAuth 2.0, SAML) and cryptography/PKI.
  • Experience with secure SDLC practices: threat modelling, secure design reviews, SAST/DAST, and pentesting.
  • Experience leading incident response.
  • Strong communication: influence engineers and explain risk to non-security stakeholders.

Aufgaben

  • Design and own security controls across our AWS estate.
  • Lead threat modelling and security architecture reviews with development teams.
  • Set cloud security policy and the security roadmap with leadership.
  • Partner with Product Management to define security requirements.
  • Build security into CI/CD: IaC scanning, container/base-image scanning, SBOM checks.
  • Write and maintain Terraform modules and secure patterns for engineers.
  • Drive adoption of automated security tooling and vulnerability scanning.
  • Act as senior responder for cloud security incidents and run post-incident reviews.
  • Manage CSPM/CNAPP tooling and coordinate remediation with owning teams.
  • Mentor engineers on secure cloud design and act as security partner to platform, product, and operations teams.

Kenntnisse

Cloud security
AWS security
Threat modelling
CI/CD security
Terraform
Scripting
Kubernetes security
Incident response
Security governance
Communication

Ausbildung

Bachelor's degree in CS/Engineering

Tools

AWS
Terraform
WAF/Cloud tooling
AWS Inspector
KMS
CI/CD tooling

Jobbeschreibung

Role Overview

The Senior Security Architect will be accountable for the security of the cloud infrastructure behind those services: reporting to the CTO, he/she sets the technical direction for cloud security across our AWS estate and define the standard that engineering teams build to. This is a hands-on senior role, positioned close to the platform and influential rather than supervisory.

Key Responsibilities
Architecture and design
  • Design and own security controls across our AWS estate: IAM, network segmentation, encryption, logging, and secrets management.
  • Lead threat modelling and security architecture reviews for new services and major changes, working one-to-one with development teams on secure design.
  • Set cloud security policy and the security roadmap jointly with security and platform leadership.
  • Partner with Product Management to define and clarify security requirements.
Automation and secure-by-default engineering
  • Build security into CI/CD: IaC scanning, container and base-image scanning, dependency and SBOM checks, policy-as-code, and automated guardrails.
  • Write and maintain Terraform modules and golden patterns so that the secure path is the easy path for product engineers.
  • Drive adoption of automated security tooling, including cloud-native vulnerability scanning and security agents (e.g. AWS Inspector).
  • Evaluate and recommend secure development tooling, including IDE-integrated security and AI coding-assistant guardrails.
Detection and incident response
  • Improve detection coverage for cloud-native attack paths.
  • Act as senior responder for cloud security incidents: build and maintain runbooks, and run post-incident reviews that produce durable fixes.
  • Assess the impact of vulnerabilities and exploits, and own the incident response process end to end.
Vulnerability and exposure management
  • Manage CSPM/CNAPP tooling: triage findings and drive remediation with the owning teams.
  • Analyze the impact of WAF rules on our products.
  • Coordinate DAST and penetration testing programs across products.
Governance, compliance, and enablement
  • Support ISO 27001 with evidence and control implementation.
  • Support regulatory security obligations, including the EU Cyber Resilience Act (CRA).
  • Lead security reviews of new third-party tools.
  • Mentor engineers on secure cloud design and act as security partner to the platform, product, and operations teams.
Qualifications
  • 8+ years in security engineering, including at least 5 focused on cloud.
  • Deep, practical expertise with the AWS security suite: Organizations and SCPs, KMS, Config, GuardDuty, CloudTrail, Security Hub, Inspector, WAF, and Shield Advanced.
  • Strong infrastructure-as-code skills (Terraform) and scripting and automation (Python, Go).
  • Kubernetes and container security experience.
  • Working knowledge of identity protocols (OIDC, OAuth 2.0, SAML) and of applied cryptography and PKI: key hierarchies, certificate lifecycle, and secure key storage.
  • Experience with secure SDLC practices: threat modeling, secure design review, SAST/DAST, and penetration testing.
  • Experience leading incident response.
  • Strong communication skills: you can influence engineering teams you do not manage and explain risk to non-security stakeholders in terms of business impact.
Nice to have
  • Certifications such as AWS Certified Security - Specialty, AWS Certified Advanced Networking - Specialty, AWS Certified Solutions Architect - Professional, CISSP, or CCSP.
  • Experience with media security, DRM, conditional access, or anti-piracy technologies.
  • Knowledge of the EU Cyber Resilience Act and related product security regulations.
  • Experience with HSMs and cryptographic key management.
  • Familiarity with on-premises and cloud security tooling supporting the SDLC.
Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Senior Security Architect
Senior Security Architect

Verimatrix • Ismaning

Vor Ort
EUR 110.000 - 150.000
Security Architect - FinTech
Security Architect - FinTech

SES • Deutschland

Remote
EUR 90.000 - 120.000
Security Architect, Strong Financial Experience, MST OR CST Time Zone - ZL
Security Architect, Strong Financial Experience, MST OR CST Time Zone - ZL

SES • Deutschland

Remote
EUR 90.000 - 130.000
Cybersecurity Engineer - Cloud, Ops (human)
Cybersecurity Engineer - Cloud, Ops (human)

NEURA Robotics • Riederich

Vor Ort
EUR 80.000 - 120.000
Principal Info Sec Technologist – Virtual
Principal Info Sec Technologist – Virtual

Jobtailor • Deutschland

Remote
EUR 130.000 - 170.000
Senior Security Assurance Solutions Architect, AWS Security Assurance Services
Senior Security Assurance Solutions Architect, AWS Security Assurance Services

Amazon Web Services (AWS) • Berlin

Vor Ort
EUR 120.000 - 180.000
Lead Cloud Security Architect, GCP
Lead Cloud Security Architect, GCP

Jobtailor • Deutschland

Vor Ort
EUR 110.000 - 150.000
Assoc. Security Engineer, AWS Customer Incident Response Team (CIRT)
Assoc. Security Engineer, AWS Customer Incident Response Team (CIRT)

Amazon Web Services (AWS) • München

Vor Ort
EUR 90.000 - 130.000
Cloud & Security Architect (w/m/d)
Cloud & Security Architect (w/m/d)

Jenoptik AG • Monheim am Rhein

Hybrid
EUR 120.000 - 160.000
Software Development Engineer, AWS Security
Software Development Engineer, AWS Security

RxREVU, Inc. • Berlin

Vor Ort
EUR 90.000 - 130.000