Cybersecurity Solution Architect

IDEMIA Public Security

Osny

Sur place

EUR 90 000 - 130 000

Plein temps

Il y a 22 heures
Soyez parmi les premiers à postuler
Générateur de candidature

Transformez ce poste en entretien — un CV et une lettre de motivation conçus selon ce que cet employeur recherche.

Passez les filtres ATS

Résumé du poste

IDEMIA Public Security is seeking a Senior Security Architect to design and govern security architectures for complex on-premises, hybrid or cloud-connected solutions. You will lead security assessments, write testable controls, and guide engineers across international teams to ensure robust protection of data and operations.

The role requires delivering security documentation in English, conducting threat modelling, and coordinating vulnerability testing with stakeholders.

Qualifications

  • At least 5 years in cybersecurity architecture, security engineering or equivalent.
  • Experience designing or securing medium to large IT solutions across multiple domains (system, network, identity, data, cloud or monitoring).
  • Solid understanding of TCP/IP, routing, DNS, HTTP/S, TLS, certificates and authentication.
  • Ability to translate security risks and customer expectations into pragmatic, documented controls.
  • Experience producing architecture and project security documentation in English.
  • Fluent in English; additional languages welcome.

Responsabilités

  • Act as security focal point for project managers, architects, engineers and customers.
  • Provide technical guidance and review security designs, hardening guides and firewall rules.
  • Lead or support security workshops and design reviews, communicating risks clearly.
  • Prepare and maintain project security documentation and risk records.
  • Support proposals and technical evaluation of providers.
  • Define security verification strategy and acceptance criteria.
  • Coordinate vulnerability scans, penetration tests and remediation plans.
  • Assist during integration, handover and early-life support.

Connaissances

Security architecture
Security engineering
Infrastructure security
Threat modelling
Risk assessments
Technical leadership
Documentation in English

Formation

BSc in CS or related
CISSP/CISM/CCSP

Outils

F5 BIG-IP
Web Application Firewall (WAF)
VPN
SIEM
Active Directory / LDAP

Description du poste

Job description:
Security architecture and requirements
  • Analyse customer, contractual and high-level security requirements, then derive clear and testable requirements for infrastructure, networks, applications, identity, data protection, logging and monitoring
  • Design and document security architectures for medium to large on-premises, hybrid or cloud-connected solutions, including trust zones, network segmentation, secure interfaces, administrative access and protection of data in transit and at rest
  • Perform threat modelling and proportionate risk assessments, identify security gaps, propose treatment options and support formal risk acceptance when required
  • Define security controls and hardening principles for Windows, Linux, virtualisation, directories, databases, middleware, applications and security appliances
  • Contribute to solution sizing, technical choices, bills of materials, effort estimates and security-related cost estimates
Project delivery and technical leadership
  • Act as the security focal point for project managers, solution architects, engineering teams, customers, partners and subcontractors
  • Provide technical guidance to implementation resources and review low-level designs, configuration plans, hardening guides, firewall rules, WAF policies and other security deliverables
  • Lead or support technical workshops, design reviews and security decision meetings, explaining risks and trade-offs to both technical and non-technical stakeholders
  • Prepare and maintain project security documentation, including security architecture documents, requirements traceability, risk records, security plans, test strategies, operating guidelines and handover material
  • Support requests for proposals and the technical evaluation of internal or external solution providers
Security verification and handover
  • Define the security verification strategy and acceptance criteria for the solution
  • Coordinate or review vulnerability scans, configuration reviews, penetration tests, static or dynamic application security testing and remediation plans
  • Validate security test evidence and confirm that residual risks, deviations and operational recommendations are documented before handover
  • Support complex troubleshooting, security incidents and major changes during integration or early-life support
  • Capture lessons learned and contribute reusable patterns, standards, templates and reference architectures for other projects
Scope of hands‑on implementation

The architect may configure or prototype security technologies when this is necessary to validate a design, remove a technical blocker or establish a reference configuration. Routine installation, detailed configuration, repetitive rule implementation, patching and operational administration should normally be assigned to Network and Security Engineers, integrators or qualified partners

Examples of technologies that may require close architectural oversight include firewalls, WAF, application delivery controllers and load balancers such as F5 BIG‑IP, reverse proxies, VPN, IDS/IPS, IAM/PAM components, PKI, certificates, SIEM integration and operating system hardening. Direct expertise in every product is not required

Profile description:
Essential experience and capabilities
  • At least 5 years of relevant experience in cybersecurity architecture, security engineering, infrastructure security or a comparable technical role. Strong candidates with a different career path but equivalent capability will also be considered.
  • Demonstrated experience designing or securing medium to large IT solutions across at least two of the following areas: system and platform security, network security, identity and access management, application security, data security, cloud security or security monitoring.
  • Solid understanding of enterprise infrastructure and network fundamentals, including TCP/IP, routing, segmentation, DNS, HTTP/S, TLS, certificates, authentication and high availability.
  • Ability to convert security risks and customer expectations into pragmatic, documented and testable controls.
  • Experience producing architecture and project security documentation in English.
  • Ability to guide engineers, challenge suppliers constructively and work autonomously in international, multidisciplinary project teams.
  • Professional fluency in English. Mastering further languages (Spanish, Arabic, …) is very welcome.
Desirable experience
  • Hands‑on exposure to one or more security or application delivery technologies, for example F5 BIG‑IP LTM or Advanced WAF, another WAF or reverse proxy, next‑generation firewalls, VPN, IDS/IPS, IAM/PAM, PKI or SIEM.
  • Experience with security hardening of Windows, Linux, Active Directory or LDAP‑based environments.
  • Experience with secure software development practices, OWASP guidance, vulnerability management and application security testing.
  • Experience securing highly sensitive, regulated, public‑sector or mission‑critical systems.
  • Knowledge of cloud or container security in Azure, AWS, Kubernetes or OpenShift environments.
  • Experience coordinating penetration tests and driving remediation to closure.
Standards and methods
  • Practical knowledge of one or more recognized approaches is expected. Candidates are not required to be specialists in every framework.
  • ISO/IEC 27001 and ISO/IEC 27002 security controls
  • ISO/IEC 27005, EBIOS Risk Manager or an equivalent risk assessment method
  • NIST Cybersecurity Framework or NIST security guidance
  • CIS Benchmarks, vendor hardening guides and security‑by‑design principles
  • OWASP guidance for web applications and APIs
Education and certifications

A degree in computer science, cybersecurity, engineering or a related field is welcome. Equivalent professional experience and demonstrable expertise are equally valuable.

Relevant certifications such as CISSP, CCSP, SABSA, CISM, GIAC, ISO 27001, cloud security, network security or vendor certifications are advantageous but are not mandatory. Certification evidence may be requested where a certification is claimed.

Ways of working
  • Clear, structured and pragmatic communication with customers and delivery teams.
  • Ability to balance security, delivery constraints, cost, performance and operability.
  • Comfort working across design, integration, testing and handover phases.
  • Willingness to travel occasionally for customer workshops, integration, acceptance or project support when required.
  • Curiosity and commitment to maintaining current knowledge of threats, security practices and relevant technologies.
Obtenez votre examen gratuit et confidentiel de votre CV.
ou faites glisser et déposez votre fichier ici.
Similar jobs

Postes similaires à comparer

Cybersecurity Solution Architect
Cybersecurity Solution Architect

IDEMIA • Osny

Sur place
EUR 90 000 - 140 000
Network Engineer
Network Engineer

Ampstek • Lyon

Sur place
EUR 85 000 - 110 000
Architecte cybersécurité
Architecte cybersécurité

CYCLAD FRANCE • Paris

Hybride
EUR 60 000 - 90 000
Cybersecurity Architecture 2
Cybersecurity Architecture 2

IDEMIA Public Security • Osny

Sur place
EUR 90 000 - 130 000
Security Architect Specialist
Security Architect Specialist

Unisys • Strasbourg

Sur place
EUR 90 000 - 120 000
Network Architect
Network Architect

Ampstek • Lyon

Sur place
EUR 90 000 - 130 000
Product Development Cyber Risk Specialist
Product Development Cyber Risk Specialist

Marlink • France

Hybride
EUR 70 000 - 110 000
Cloud & Mobility Cybersecurity Engineer
Cloud & Mobility Cybersecurity Engineer

Jobtailor • Le Haillan

Sur place
EUR 90 000 - 120 000
Cybersecurity Engineer, Service Platforms
Cybersecurity Engineer, Service Platforms

Jobtailor • Saclay

Sur place
EUR 60 000 - 90 000
Head of Solutions Engineering
Head of Solutions Engineering

GALILEO RH • Paris

Sur place
EUR 80 000 - 110 000