Liebherr Group

Application Security Architect

Liebherr Group

full-time

Posted on:

Origin:  • 🇪🇸 Spain

Visit company website
AI Apply
Manual Apply

Job Level

Mid-LevelSenior

Tech Stack

AWSAzureCloudCyber SecurityDockerGoogle Cloud PlatformJenkinsKubernetesMicroservicesSDLC

About the role

  • Develop and enforce application security architecture frameworks, policies, standards, and best practices (e.g. OWASP, NIST, ISO 27001)
  • Review and approve application security designs while ensuring secure software development and architecture
  • Integrate security into the software development lifecycle (SDLC) by collaborating with development teams and enabling DevSecOps practices
  • Adopt and promote a security-by-design approach with different stakeholders
  • Conduct threat modeling, security reviews, and risk assessments to proactively identify and mitigate vulnerabilities
  • Evaluate, recommend, and oversee security tools and testing solutions (SAST, DAST, IAST)
  • Define security strategies for applications (e.g. IAM) and implement security principles such as Zero Trust
  • Actively contribute to the Corporate Information Security architecture community, sharing insights and best practices
  • Collaborate with IT, EA, DevOps and Engineering teams to align security objectives

Requirements

  • Bachelor’s/Master’s in Cybersecurity, Computer Science, or related field
  • 3+ years in cybersecurity, preferably in application security architecture role
  • Preferred certifications: CISSP, SABSA, Cloud certifications (AWS, Azure, or GCP)
  • English is a must; German and French are a plus
  • Good understanding of cybersecurity frameworks and standards (ISO 27001, NIST)
  • Expertise in OWASP, SSDLC, and DevSecOps
  • Strong knowledge of secure software architecture
  • Strong understanding of microservices security, API security, and IAM (OAuth, SAML, JWT)
  • Knowledge of cloud-native security and CI/CD integration (e.g. Jenkins, GitHub Actions)
  • Experience with container security and cloud platforms (e.g. AWS, Azure, GCP, Docker, Kubernetes)