Security Architect
Location: 28906, Getafe
What to expect:
We are looking for an experienced Security Architect to work on a project for a global leading manufacturing components company. The person who joins will be responsible for detecting threats in end‑to‑end security architecture for IoT and industrial ecosystems, ensuring that technical decisions, security controls, and threat and risk assessment (TRA) results are coherently, scalable and aligned with business needs and reference standards.
Responsibilities:
- Define and maintain threat modeling and TRA for certain components, ensuring that attack models, attack trees and risk scenarios translate into design requirements and concrete controls.
- Propose security controls (identity, authentication, cryptography, segmentation, logging, monitoring) integrated into the target architecture.
- Align security architecture with standards and frameworks such as IEC 62443, ETSI EN 303 645, NISTIR 8259, NIST CSF and ISO 27001.
- Review and validate technical designs and architecture changes, identifying security gaps and proposing mitigation measures.
- Collaborate with engineering, development and operations teams to ensure that security architecture is implementable and efficient.
- Support in defining reusable secure architecture patterns and reference blueprints for new projects and products.
- Act as technical security reference point in architecture and key project committees, providing risk vision and regulatory compliance.
- Participate in selection and evaluation of technology security solutions (HSM, IAM, EDR, monitoring tools, etc.).
Requirements:
- Bachelor in Computer Science, Telecommunications, Industrial Engineering or similar.
- At least 5 years of cybersecurity experience, with a significant part in security architecture or design of secure solutions.
- Demonstrable experience designing secure architectures in IoT, OT or industrial environments (manufacturing, energy, automotive, aerospace, etc.).
- Familiarity with threat modeling (e.g. STRIDE) and use of TRA results to define security requirements.
- Experience working with frameworks such as IEC 62443, NIST CSF, ISO 27001 and IoT security standards.
- High level of English.
Desirable Requirements:
- Experience integrating security solutions in OT environments (SCADA, PLCs, industrial networks).
- Knowledge of MITRE ATT&CK (including matrices for ICs) and its application in design of defenses.
- Relevant certifications (e.g. CISSP, CCSP, SABSA, TOGAF, ISA/IEC 62443).
- Experience in international projects and multi‑stakeholder environments.
Benefits:
- Competitive salary and benefits package based on seniority.
- Flexible working hours, hybrid modal.
- Dynamically multidisciplinary work environment with continuous learning opportunities.
Contact:
Miriam Llorente García
Phone: