Tech Stack
AWSAzureCloudCyber SecurityDockerGoogle Cloud PlatformJenkinsKubernetesMicroservicesSDLC
About the role
- Develop and enforce application security architecture frameworks, policies, standards, and best practices (e.g. OWASP, NIST, ISO 27001)
- Review and approve application security designs while ensuring secure software development and architecture
- Integrate security into the software development lifecycle (SDLC) by collaborating with development teams and enabling DevSecOps practices
- Adopt and promote a security-by-design approach with different stakeholders
- Conduct threat modeling, security reviews, and risk assessments to proactively identify and mitigate vulnerabilities
- Evaluate, recommend, and oversee security tools and testing solutions (SAST, DAST, IAST)
- Define security strategies for applications (e.g. IAM) and implement security principles such as Zero Trust
- Actively contribute to the Corporate Information Security architecture community, sharing insights and best practices
- Collaborate with IT, EA, DevOps and Engineering teams to align security objectives
Requirements
- Bachelor’s/Master’s in Cybersecurity, Computer Science, or related field
- 3+ years in cybersecurity, preferably in application security architecture role
- Preferred certifications: CISSP, SABSA, Cloud certifications (AWS, Azure, or GCP)
- English is a must; German and French are a plus
- Good understanding of cybersecurity frameworks and standards (ISO 27001, NIST)
- Expertise in OWASP, SSDLC, and DevSecOps
- Strong knowledge of secure software architecture
- Strong understanding of microservices security, API security, and IAM (OAuth, SAML, JWT)
- Knowledge of cloud-native security and CI/CD integration (e.g. Jenkins, GitHub Actions)
- Experience with container security and cloud platforms (e.g. AWS, Azure, GCP, Docker, Kubernetes)