← Back to list
Job · Architect

Security Architect

Security Engineer • Architect • On-site • Full-time • European Union Newton, EU/EMEA

At Informa TechTarget's Newton, MA office you would define and drive the cloud and enterprise security architecture. You own the security architecture vision, establish governance frameworks, and partner with Product, Engineering and Infrastructure teams to embed security across the technology ecosystem.

Responsibilities

  • ▹Own and evolve the enterprise security architecture, including the long-term roadmap and reference architectures for cloud, hybrid and on-premises environments
  • ▹Define organizational security principles, frameworks and standards aligned with business objectives and regulatory requirements
  • ▹Develop and present security strategy, roadmaps and strategic initiatives to executive leadership and stakeholders
  • ▹Establish security metrics and KPIs to measure architecture effectiveness and communicate security posture to senior leadership
  • ▹Ensure compliance with industry regulations and standards including ISO 27001, SOC 2, GDPR and SOX
  • ▹Lead security audits and assessments, driving remediation plans and continuous improvement initiatives
  • ▹Own cloud security architecture across AWS and GCP, including Cloud Security Posture Management (CSPM), Cloud Infrastructure Entitlement Management (CIEM) and Wiz remediation strategies
  • ▹Design and implement Identity and Access Management (IAM) architecture based on least privilege principles and Zero Trust security models
  • ▹Architect secure network segmentation strategies and defense-in-depth controls across all infrastructure layers
  • ▹Own the architecture and strategic direction for key security platforms including SIEM, vulnerability management, endpoint security and threat detection systems
  • ▹Manage and optimize internal security platforms to ensure robust protection of organizational assets
  • ▹Design secure cloud infrastructures and hybrid environment protections that scale with business growth
  • ▹Conduct threat modeling and risk analyses to identify infrastructure vulnerabilities and recommend mitigation strategies
  • ▹Lead Secure Software Development Lifecycle (SDLC) and DevSecOps initiatives across the organization
  • ▹Integrate security controls into CI/CD pipelines, championing shift-left security practices in collaboration with DevOps leadership
  • ▹Ensure software architecture and applications are designed to mitigate vulnerabilities and prevent exploits
  • ▹Provide technical guidance and mentorship to development and DevOps teams on secure coding practices and emerging threats
  • ▹Collaborate with cross-functional teams to embed security throughout the system development lifecycle
  • ▹Define security requirements and controls that support agile development while maintaining a strong security posture
  • ▹Lead security architecture for emerging technologies including AI/LLM initiatives, ensuring responsible and secure implementation
  • ▹Serve as the technical authority on security architecture, advising on security-related technologies and assessing risks of proposed changes
  • ▹Stay current with emerging security threats, vulnerabilities and technologies to drive continuous innovation in security practices
  • ▹Inspire and influence engineering teams to execute security principles and adopt a security-first mindset
  • ▹Drive thought leadership through security documentation, architecture diagrams, design specifications and security control matrices
  • ▹Lead incident response management and develop security policies that protect organizational assets from cyber threats
  • ▹Identify organizational vulnerabilities and weaknesses through systematic security assessments
  • ▹Recommend and implement security controls and solutions that balance security requirements with business enablement

Requirements

  • ▹Bachelor's or master's degree in computer science, information technology or a related field
  • ▹7+ years of cybersecurity experience with deep cloud security expertise
  • ▹Proven track record leading enterprise security architecture in multi-cloud environments
  • ▹Deep understanding of cloud provider (AWS, GCP) security best practices: Organization Policies, automated threat detection tools, central logging / SIEM practices, least privilege architecture, VPC design and perimeter controls, data exfiltration prevention, encryption and key management design, IAM best practices
  • ▹Web application security testing: expertise in identifying and mitigating vulnerabilities in web applications using tools and methodologies like OWASP
  • ▹Network vulnerability scanning: skilled in detecting and addressing vulnerabilities in network configurations and infrastructure
  • ▹Container and Kubernetes security: proficiency in securing containerized environments, including Docker and Kubernetes, using best practices and tools like Trivy or Aqua Security
  • ▹Experience with security testing tools and platforms: familiarity with industry-standard tools for vulnerability scanning, penetration testing and security auditing
  • ▹Ability to lead security discussions with system architects and business leaders
  • ▹Strong analytical and computer skills
  • ▹Expert-level understanding of cybersecurity and how it affects the modern business world
  • ▹Thorough understanding of Unix operating systems
  • ▹Awareness of frameworks such as NIST, COBIT, ISO and SOC 2
  • ▹Certifications: CISSP, CCSP, AWS Security Specialty or Google Professional Cloud Security Engineer

Soft skills

Ability to inspire and influence engineering teamsStrategic partnership with Product, Engineering and Infrastructure leadersGood communication towards executives and technical staff

What we offer

  • ▹Salary range: $175K-$200K per year, based on experience
  • ▹Open Vacation plus 10 national holidays, and the chance to work from almost anywhere for up to four weeks a year
  • ▹Up to four days per year to volunteer with a philanthropic organization
  • ▹Career opportunity: bespoke training, mentoring platforms, on-demand access to thousands of LinkedIn Learning courses, support for internal moves
  • ▹Competitive benefits: 401k match, health, vision and dental insurance, parental leave, ESPP with company shares at a minimum 15% discount
  • ▹Wellbeing support: EAP, mental health first aiders, free access to a wellness app
  • ▹Recognition for great work with global awards and kudos programs
  • ▹Chance to collaborate with teams around the world
  • ▹Community culture: in-person and online social events, Walk the World charity day, colleague groups and networks

About the company

Informa TechTarget (Nasdaq: TTGT) informs, influences and connects the world's technology buyers and sellers, with over 220 targeted technology websites and more than 50 million permissioned audience members. It is part of Informa PLC and has over 2000 colleagues in 19 locations worldwide.

Education: Számítástechnikai, informatikai vagy kapcsolódó területen szerzett alap- vagy mesterdiploma

Similar jobs