At a Glance
- Tasks: Lead the design of secure architecture patterns and controls for innovative technology solutions.
- Company: Join a leading firm in the financial services sector focused on security excellence.
- Benefits: Competitive salary, flexible working options, and opportunities for professional growth.
- Other info: Collaborative environment with a focus on innovation and career advancement.
- Why this job: Make a real impact by shaping security practices in cutting-edge technology projects.
- Qualifications: 7+ years in security roles, with expertise in architecture and threat modelling.
The predicted salary is between 80000 - 100000 € per year.
Requirements
- 7+ years of increasing responsibility in technical engineering or information security roles, security architecture preferred
- Experience of enterprise architecture frameworks and their application
- Experience in threat modelling / design pattern development
- Proven experience in designing and applying security controls into distributed systems (on premises and cloud)
- Thorough understanding of the latest security principles, techniques and protocols
- Critical, independent thinking
- Problem solving skills, ability to work under pressure and self-starter
- Deep understanding of both common and emerging vulnerabilities including their manifestation in different architectures (web applications, thick clients, APIs, networked infrastructure etc)
- Familiarity with industry standard guidance OWASP Top 10, SANS Top 25, NIST / CSC, CIS, NCSC etc
- Applied understanding of topics such as authentication, access control, encryption, cloud security, operating system security, network security, database security
- Experience of writing succinct, reader oriented, visually compelling documentation
- Familiarity with common Developer Tools (GitLab/Azure DevOps etc) and some experience with using YAML/Markdown/Terraform
- Preferred prior experience in the financial services and / or technology sector
- Preferred prior experience in a heavily regulated environment
- Experience in supervising and supporting specialist individual contributors in technology domains; inspiring others to delivery of outcomes
- Experience in working collaboratively with remote and offshore team members
- Must have a collaborative work style ensuring that stakeholders are engaged in decision making processes
- Highly adaptable and able to approach challenges differently in order to achieve goals
What the job involves
- The Security Architecture Design team is responsible for developing Security Architecture patterns, developing security controls needed for new technology, promoting the use of the architectural patterns into development projects, leading the Security Architecture Design Forum, evaluating architectural security risks in existing systems, consulting with system development teams and architects on building security into their design.
- This key task of this role is accelerating the delivery of secure design artefacts and leading secure design interventions - by adding capacity and capability to the team.
- Reports to: Senior Manager – Secure Design
- Develop Security Architecture Design Patterns and Standards to comply with group security requirements, industry standards, customer requirements, regulatory requirements and good practices.
- Assist the development of and champion a Security Architecture control framework.
- Research, design and document the security posture requirements and controls of new technology introduced into the Group.
- Engage with technology acquisition processes to ensure all new technology introduced is evaluated.
- Research industry trends and regulatory requirements.
- Lead the Security Architecture evaluation of risks identified in systems, including reviewing, and proposing tactical and strategic remediation plans, and evaluation of the cost / risk benefits of remediations.
- Actively contribute to the adoption of secure by design practices, with technical delivery teams for both existing systems and new systems, e.g. use of internal or external guidance, leading Threat Modelling activity.
- Nurture the use of secure technical practices to deliver technical excellence.
- Support experimentation and innovation in solving problems.
- Supervise third parties in their deliveries related to the domain area.
- Provide company representation, internally and externally, related to information security, as needed.
- Contributes to the development of metrics and their monitoring to report the effectiveness and efficiency of the Security Architecture function.
- Contributes to the content and management of the Security Architecture intranet presence.
- Guiding and mentoring other team members as required.
- Deputising for Senior Manager - Secure Design when required.
- Developing and prioritising the security design pattern library.
- Developing and delivering the security design patterns – individually or in conjunction with other teams, as necessary.
- Working with the neighbouring security teams and delivery projects to address emerging areas of secure design guidance and interventions.
- Developing security architecture interventions in business specific process for acquiring and developing new technology.
- Contributing to the development and reporting of metrics for the Secure Design team, within the broader Security Architecture function.
- This is a group-wide role which is key to effective and efficient management of security risks associated with business technology systems.
- The success of the post holder will be in balancing the major aspects of the role: The ability to work effectively and pragmatically with project teams, to drive secure by design outcomes, while enabling projects to deliver.
- Develop or refresh security architectural collateral - based on the planned and emerging needs of the business.
- During project delivery, identifying gaps in security architecture collateral to be added to the security design pattern library.
Key Performance Indicators
- Delivery of design patterns (timeframe from development initiation to substantive draft, through to general availability).
- Successful outcomes from security architectural interventions with delivery projects.
Key Relationships:
- Business Aligned Principal Security Architects
- CyberSecurity Engineering
- CyberSecurity Testing and Vulnerability Management
- Cloud Security
- Identity Management
- Security Architecture Design Forum (member)
- Project teams
- BISOs
Manager / Principal Security Architect (Secure Design) employer: Deepstreamtech
As a leading employer in the technology sector, we pride ourselves on fostering a collaborative and innovative work culture that empowers our employees to excel. With a strong focus on professional development, we offer numerous growth opportunities and support for continuous learning, ensuring that our team members are well-equipped to tackle the evolving challenges of security architecture. Located in a vibrant area, our workplace promotes a healthy work-life balance and provides access to cutting-edge resources, making it an ideal environment for those seeking meaningful and rewarding careers.
StudySmarter Expert Advice🤫
We think this is how you could land Manager / Principal Security Architect (Secure Design)
✨Tip Number 1
Network like a pro! Get out there and connect with folks in the security architecture space. Attend industry events, webinars, or even local meetups. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Show off your skills! Create a portfolio that highlights your experience in designing security controls and threat modelling. Use real-world examples to demonstrate how you've tackled challenges in previous roles. This will make you stand out when chatting with potential employers.
✨Tip Number 3
Don’t just apply blindly! Tailor your approach for each role. Research the company’s security practices and be ready to discuss how your experience aligns with their needs. This shows you're genuinely interested and not just sending out cookie-cutter applications.
✨Tip Number 4
Leverage our website! We’ve got loads of resources and job listings that can help you land that dream role. Keep an eye on our updates and don’t hesitate to reach out if you need any guidance during your job search.
We think you need these skills to ace Manager / Principal Security Architect (Secure Design)
Some tips for your application 🫡
Tailor Your Application:Make sure to customise your CV and cover letter to highlight your experience in security architecture and technical engineering. We want to see how your skills align with the job description, so don’t hold back on showcasing your relevant achievements!
Showcase Your Documentation Skills:Since writing succinct and visually compelling documentation is key for this role, include examples of your past work. Whether it’s reports, design patterns, or any other relevant documents, let us see your ability to communicate complex ideas clearly.
Highlight Your Problem-Solving Abilities:We love critical thinkers! In your application, share specific examples of how you've tackled challenges in previous roles, especially in high-pressure situations. This will help us understand your approach to problem-solving and adaptability.
Apply Through Our Website:Don’t forget to submit your application through our website! It’s the best way for us to receive your details and ensures you’re considered for the role. Plus, it shows you’re keen on joining our team at StudySmarter!
How to prepare for a job interview at Deepstreamtech
✨Know Your Security Principles
Make sure you brush up on the latest security principles, techniques, and protocols. Familiarity with industry standards like OWASP Top 10 and NIST will not only impress your interviewers but also help you articulate how you can apply these in real-world scenarios.
✨Showcase Your Problem-Solving Skills
Prepare to discuss specific examples where you've tackled complex security challenges. Highlight your critical thinking and problem-solving abilities, especially under pressure. This will demonstrate your capability to handle the demands of the role.
✨Demonstrate Collaborative Spirit
Since this role involves working with various teams, be ready to share experiences where you've successfully collaborated with others. Emphasise your ability to engage stakeholders in decision-making processes and inspire team members to achieve outcomes.
✨Prepare for Technical Questions
Expect technical questions related to security architecture and threat modelling. Brush up on your knowledge of distributed systems, cloud security, and common vulnerabilities. Being able to discuss these topics confidently will set you apart from other candidates.