Snapshot of Your Day
The IT Security Architect (technical and operational) will implement the Cybersecurity Governance rules and requirements within the Infrastructure End‑User services, encompassing Virtual Desktop Infrastructure, Printing and Scanning. You will collaborate heavily with the Virtual Client and Print service teams, with the Endpoint Architects and Cybersecurity teams, and be a key contributor to service and technology design choices.
How You’ll Make an Impact
- Analyze and define the interaction of the organization’s processes, tools, data, and technologies to develop a secure architecture for the above services, taking into account risk and best industry practices.
- Support the evaluation of business demands and prepare architecture decisions with deep consideration for security.
- Apply methods from the SE architecture framework and Security guidelines to support the evolution of the SE target architecture in virtualization, printing and scanning.
- Define and provide SE technology constraints, guardrails and reference security architectures. Facilitate IT solution architecture reviews in close collaboration with Cybersecurity Teams and Governance topic leads.
- Report regularly to the head of End User Solutions and the head of Digital Workplace, supporting the shaping of new security practices and influence within the department.
What You Bring
- Bachelor’s degree in computer science, Information Technology or Cyber Security. Postgraduate qualification in a related field.
- Minimum 5‑7 years of experience in IT security, with at least 3 years of direct experience in Workplace solutions’ security architecture. Proven experience with Endpoint Management platforms such as Microsoft Intune, Microsoft Defender, Microsoft Purview, and good knowledge of Identity platforms such as EntraID.
- Strong understanding of security principles surrounding device hardening, CIS benchmarks, risk assessment and mitigation. Previous experience implementing security best practices (ISO 27001, NIST, etc.). Demonstrated experience in maintaining security compliance during migrations, carve‑outs, mergers and acquisitions.
- Proven experience working on securing virtualization platforms, on‑premise and on cloud, utilizing management platforms such as Omnissa Horizon, Workspot, Azure Virtual Devices, Windows 365 and Openshift.
- Strong knowledge of technology platforms and architectural concepts surrounding Entra ID and Active Directory authentication, LAN, WAN, inbound and outbound network connectivity and associated security concepts (TLS, AES, HTTPS, IPSEC and other encryption technologies specific to virtualization, printing and scanning).
- Knowledge of secure printing and scanning technologies. Technical proficiency in the protocols: SAML, OAuth 2.0, OpenID Connect, SCIM, LDAP, Kerberos. Good understanding of cloud platforms: AWS, Azure, Google Cloud deployment models.
- Knowledge of identity and access management system architecture concepts and their influence on application security. Secure system design and secure service design knowledge of latest security recommendations and industry best practices.
Rewards and Benefits
- An attractive remuneration package in line with the market and an employer‑financed company pension scheme.
- The opportunity to become a Siemens Energy shareholder.
- The possibility to work flexibly and remotely, with inspiring offices that provide space for collaboration and creativity.
- Professional and personal development opportunities, including self‑determined learning and various attractive programmes and learning materials.
- Flexible working time models, childcare places at many locations, the possibility to trial part‑time work or take a sabbatical to support work‑family compatibility.