Security Architect, hibrido
Empresa
Michael Page
Provincia
Barcelona
Ciudad
Barcelona
Tipo de Contrato
Tiempo Completo
Descripción
Security Architect
Responsibilities:
Support the development of security architectures, including target states, transition plans and roadmaps aligned to business objectives, IT strategy and security risk appetite.
Provide risk-based security architecture guidance to engineering, infrastructure, application, architecture, project and business teams.
Review solution, application, infrastructure and integration designs to ensure secure-by-design principles, appropriate technology selection and alignment with PageGroup security policies and standards.
Support security architecture activities across BAU services, projects, programmes and material change initiatives, ensuring security requirements are identified, designed, implemented and governed.
Perform threat modelling, threat analysis and architecture risk assessments to identify threats, attack paths, vulnerabilities, security weaknesses and appropriate mitigating controls.
Define, document and maintain security requirements, control specifications, architectural patterns, standards, baselines and implementation guidance, ensuring alignment with business risk appetite and applicable security standards.
Conduct security architecture reviews and implementation assurance activities to validate that agreed security controls and requirements have been effectively implemented.
Review remediation plans and support the closure of security findings, defects and design issues.
Participate in architecture governance forums, change reviews and security assurance activities, providing advice on security risks and compliance with security standards.
Conduct independent security reviews and produce technical reports, recommendations and supporting documentation, including working with third parties where required.
Maintain awareness of emerging technologies, threats and security trends, recommending updates to standards, controls and guidance where appropriate.
Support continuous improvement activities that strengthen the security posture of existing technology platforms and services.
High visibility and business impact
Opportunity to grow as a strategic Security Architect
Required experience:
5+ years of experience working in a specialist IT/technical/architect role.
3+ years of experience in an information security-focused role.
Experience working in a multi-vendor environment.
Experience securing and working with enterprise-grade systems and applications.
Good IT security background, including knowledge of security architectures, cloud security, network security, information security best practices, and best-practice operating models and processes.
Preferred experience:
2+ years delivering security risk assessments in a global IT environment.
Detailed technical knowledge relating to hardware and software.
Experience performing threat modelling using recognised methodologies (e.g. STRIDE).
Experience conducting architecture risk assessments and security design reviews.
Experience supporting security assurance activities, including penetration testing and findings remediation.
Familiarity with NIST Cybersecurity Framework, CIS Controls and ISO 27001.
Experience operating within formal architecture governance processes.
Knowledge of principles and practices involved in the development and maintenance of software solutions, architectures and service delivery.
Experience with regulatory compliance and information security management frameworks (e.g., ISO 27001, NIST, GDPR).
Experience deploying and operating information security risk management processes.
Familiarity with standard IT process and control frameworks, such as ITIL, IT4IT, COBIT and TOGAF.
Skills:
Great communication skills, capable of engaging effectively from engineering levels to C-Level executives.
Analytical thinking and problem-solving abilities, including troubleshooting and adapting to significant project changes.
Proficiency in working under pressure and managing multiple priorities.
Proactive and forward-thinking attitude towards cybersecurity.
Risk assessment and risk management.
Knowledge of project and program management methodologies.
Basic understanding of corporate finance and commercial awareness.
Calm and assertive in challenging situations.
Creativity in formulating alternative approaches to problems.
Ability to work effectively on large, global projects in diverse and multi-cultural environments.
Commitment to achieving quality with a rational and organised approach to tasks.
Qualifications:
Current or working towards:
No formal qualifications are required.
Education to first-degree level or equivalent in a technology, cybersecurity or a related field is preferred.
A foundational security certification, such as CC, Security+, SSCP, CCSP, or equivalent, is desirable.
Strong knowledge of core Microsoft cloud technologies and services, including Azure IaaS and Microsoft 365.
Mandatory Attitudes and Behaviours:
Cohesive and supportive across all business groups.
Cultural awareness when working with global teams.
Collaborative approach to working across teams and the wider organisation.
Analytical and lateral thinker, with a very strong attention to detail.
Proactive and pragmatic - able to balance competing pressures and influences.
Customer focused and able to enthuse and motivate teams and individuals.
Persuasive and professional communication style, with the ability to influence business decisions.
A leading global professional services organisation with a strong international presence, operating in multiple countries and supporting a large-scale, enterprise technology environment.
The company is investing in its cybersecurity capabilities and digital transformation, offering the opportunity to work on complex global projects, modern cloud technologies, and strategic security initiatives within a collaborative and multicultural environment.
Opportunity to play a key role in shaping and improving cybersecurity architecture within a global enterprise environment.
Exposure to large-scale projects, cloud technologies, and complex security challenges across multiple regions and business functions.
Strong stakeholder visibility, working closely with architecture, engineering, infrastructure, and senior leadership teams.
A collaborative and international environment with opportunities for professional growth and continuous learning.
The chance to drive Secure-by-Design practices and influence strategic technology decisions with a direct business impact.
Azure, Microsoft 365, NIST, CIS, ISO 27001, ITIL,
Responsibilities:
Support the development of security architectures, including target states, transition plans and roadmaps aligned to business objectives, IT strategy and security risk appetite.
Provide risk-based security architecture guidance to engineering, infrastructure, application, architecture, project and business teams.
Review solution, application, infrastructure and integration designs to ensure secure-by-design principles, appropriate technology selection and alignment with PageGroup security policies and standards.
Support security architecture activities across BAU services, projects, programmes and material change initiatives, ensuring security requirements are identified, designed, implemented and governed.
Perform threat modelling, threat analysis and architecture risk assessments to identify threats, attack paths, vulnerabilities, security weaknesses and appropriate mitigating controls.
Define, document and maintain security requirements, control specifications, architectural patterns, standards, baselines and implementation guidance, ensuring alignment with business risk appetite and applicable security standards.
Conduct security architecture reviews and implementation assurance activities to validate that agreed security controls and requirements have been effectively implemented.
Review remediation plans and support the closure of security findings, defects and design issues.
Participate in architecture governance forums, change reviews and security assurance activities, providing advice on security risks and compliance with security standards.
Conduct independent security reviews and produce technical reports, recommendations and supporting documentation, including working with third parties where required.
Maintain awareness of emerging technologies, threats and security trends, recommending updates to standards, controls and guidance where appropriate.
Support continuous improvement activities that strengthen the security posture of existing technology platforms and services.
High visibility and business impact
Opportunity to grow as a strategic Security Architect
Required experience:
5+ years of experience working in a specialist IT/technical/architect role.
3+ years of experience in an information security-focused role.
Experience working in a multi-vendor environment.
Experience securing and working with enterprise-grade systems and applications.
Good IT security background, including knowledge of security architectures, cloud security, network security, information security best practices, and best-practice operating models and processes.
Preferred experience:
2+ years delivering security risk assessments in a global IT environment.
Detailed technical knowledge relating to hardware and software.
Experience performing threat modelling using recognised methodologies (e.g. STRIDE).
Experience conducting architecture risk assessments and security design reviews.
Experience supporting security assurance activities, including penetration testing and findings remediation.
Familiarity with NIST Cybersecurity Framework, CIS Controls and ISO 27001.
Experience operating within formal architecture governance processes.
Knowledge of principles and practices involved in the development and maintenance of software solutions, architectures and service delivery.
Experience with regulatory compliance and information security management frameworks (e.g., ISO 27001, NIST, GDPR).
Experience deploying and operating information security risk management processes.
Familiarity with standard IT process and control frameworks, such as ITIL, IT4IT, COBIT and TOGAF.
Skills:
Great communication skills, capable of engaging effectively from engineering levels to C-Level executives.
Analytical thinking and problem-solving abilities, including troubleshooting and adapting to significant project changes.
Proficiency in working under pressure and managing multiple priorities.
Proactive and forward-thinking attitude towards cybersecurity.
Risk assessment and risk management.
Knowledge of project and program management methodologies.
Basic understanding of corporate finance and commercial awareness.
Calm and assertive in challenging situations.
Creativity in formulating alternative approaches to problems.
Ability to work effectively on large, global projects in diverse and multi-cultural environments.
Commitment to achieving quality with a rational and organised approach to tasks.
Qualifications:
Current or working towards:
No formal qualifications are required.
Education to first-degree level or equivalent in a technology, cybersecurity or a related field is preferred.
A foundational security certification, such as CC, Security+, SSCP, CCSP, or equivalent, is desirable.
Strong knowledge of core Microsoft cloud technologies and services, including Azure IaaS and Microsoft 365.
Mandatory Attitudes and Behaviours:
Cohesive and supportive across all business groups.
Cultural awareness when working with global teams.
Collaborative approach to working across teams and the wider organisation.
Analytical and lateral thinker, with a very strong attention to detail.
Proactive and pragmatic - able to balance competing pressures and influences.
Customer focused and able to enthuse and motivate teams and individuals.
Persuasive and professional communication style, with the ability to influence business decisions.
A leading global professional services organisation with a strong international presence, operating in multiple countries and supporting a large-scale, enterprise technology environment.
The company is investing in its cybersecurity capabilities and digital transformation, offering the opportunity to work on complex global projects, modern cloud technologies, and strategic security initiatives within a collaborative and multicultural environment.
Opportunity to play a key role in shaping and improving cybersecurity architecture within a global enterprise environment.
Exposure to large-scale projects, cloud technologies, and complex security challenges across multiple regions and business functions.
Strong stakeholder visibility, working closely with architecture, engineering, infrastructure, and senior leadership teams.
A collaborative and international environment with opportunities for professional growth and continuous learning.
The chance to drive Secure-by-Design practices and influence strategic technology decisions with a direct business impact.
Azure, Microsoft 365, NIST, CIS, ISO 27001, ITIL,