Security/Sovereign Cloud Architect
MEA Security/Sovereign Cloud Architect
Xebia is a global AI-first, digital transformation, and engineering partner. With over 25 years of experience and a team of 5,000 professionals across 16 countries, we help organizations design and build scalable products, platforms, and data-driven solutions.
We specialize in Artificial Intelligence, Data and Cloud, Intelligent Automation, and Digital Products, combining deep technical expertise with a strong focus on engineering excellence and a people-first culture.
In the CEE region, we’re a team of nearly 1,000 experts delivering modern applications, data platforms, and AI solutions for clients such as McLaren, Aviva, Deloitte, Spotify, Disney, ING, UPS, Tesco, Truecaller, AllSaints, Volotea, Schmitz Cargobull, Allegro, InPost, and many, many more. We work with leading technologies including AWS, Azure, GCP, Databricks, and Snowflake, and combine strong engineering culture with a consulting mindset and a continuous focus on growth and knowledge sharing.
You will be:
- Defining and governing the programme's security architecture, including Zero Trust, IAM, network segmentation, and cryptographic controls.
- Designing sovereign cloud deployment models that meet national security, data residency, and compliance requirements.
- Leading security architecture reviews, threat modelling sessions, and security governance activities.
- Establishing security standards, architecture patterns, and guardrails across all programme workstreams.
- Advising on information classification, cross-domain data flows, and secure solution design.
- Working closely with government security authorities, auditors, and client information assurance teams.
- Assessing third-party vendor security posture and reviewing security documentation.
- Providing security approval during Architecture Review Boards and programme stage gates.
Your profile:
- 7–12 years of experience in cybersecurity or security architecture within large-scale programmes.
- Experience designing security architectures for government, defence, or classified environments.
- Strong expertise in Zero Trust Architecture and identity-centric security models.
- Hands-on knowledge of sovereign cloud platforms, data residency, encryption, BYOK/HYOK, and HSM integration.
- Strong background in IAM, federation technologies, RBAC, ABAC, PAM, and secrets management.
- Familiarity with cybersecurity frameworks including ISO 27001, NIST SP 800-53, NCSC CAF, or regional equivalents.
- Experience producing security architecture documentation, threat models, and risk assessments.
- Excellent communication skills with the ability to influence both technical and executive stakeholders.
Nice to have:
- Experience with Saudi NCA Essential Cybersecurity Controls or NDMO requirements.
- Knowledge of secure enclave technologies, Trusted Execution Environments (TEE), or enterprise PKI.
- Experience with defence-grade cryptographic standards such as FIPS 140-2/3.
- Active or recent SC, DV, or NATO SECRET clearance.
- GCC or KSA government security programme experience.
- CISSP, CCSP, AWS Security Specialty, Azure Security Engineer, SABSA, or ISO 27001 certifications.
Recruitment Process:
CV review – HR call – Interview – Client Interview – Decision
As published by greenhouse
First Name, Last Name, Email, Phone, Resume/CV, Cover Letter
- LinkedIn Profile optional
- Website optional
- Where did you find this job offer? choose one
- What is your notice period?
- What is your preferred form of cooperation?
- What are your financial expectations?
- Please specify if the salary expectation are provided hourly or monthly
- Please specify if the given salary is in net or gross value
- Currency of the salary expectations
- What country do you currently reside in? choose one
- Do you have documents entitling you to work in the European Union (valid work permits to work in the EU)? choose one
- Do you speak English at a minimum B2 level? choose one
- I declare that I agree to the processing of my Personal Data contained in the content of documents sent in response to the job/cooperation offer, and Personal Data collected during a possible recruitment interview, in order to participate in future recruitment processes conducted by the Administrator, i.e. Xebia sp. z o.o. with its registered office in Wrocław. choose one
- I declare that I agree to sending to my e-mail address indicated in the content of recruitment documents, any information about recruitment processes conducted by the Administrator, i.e. Xebia sp. z o.o. with its registered office in Wrocław. choose one
- The administrator of Personal Data is Xebia sp. z o.o. with its registered office in Wrocław, ul. Sucha 3, 50-086 Wrocław, KRS: 0000978067, NIP: 8971719181, REGON: 020363023 with a share capital of PLN 37 168 600.00. Your data contained in the CV will be processed only for recruitment purposes. The legal basis for the processing of your personal data is art. 221 cl. 1 of the Labour Code. If you provide separate consent, we will process your personal data also for future recruitment purposes. You have the right to access your personal data, to correct them, to remove them, to restrict their processing, to transfer your data, to submit an objection, to withdraw consent to data processing any time without affecting the lawfulness of processing carried out on the basis of the consent before it was withdrawn. In order to exercise the abovementioned rights, please send an e-mail with your request to: gdpr.pl@xebia.com. If you believe that your data are processed illegally, you can submit a complaint to the supervisory body with its registered office in ul. Stawki 2, Warsaw. We may only disclose your personal data if you provide consent thereto or to authorised bodies, when necessary. choose one