Senior Security Architect
The Senior Security Architect will be accountable for the security of the cloud infrastructure behind those services: reporting to the CTO, he/she sets the technical direction for cloud security across our AWS estate and define the standard that engineering teams build to. This is a hands-on senior role, positioned close to the platform and influential rather than supervisory.
Key Responsibilities
Architecture and design
- Design and own security controls across our AWS estate: IAM, network segmentation, encryption, logging, and secrets management.
- Lead threat modelling and security architecture reviews for new services and major changes, working one-to-one with development teams on secure design.
- Set cloud security policy and the security roadmap jointly with security and platform leadership.
- Partner with Product Management to define and clarify security requirements.
- Build security into CI/CD: IaC scanning, container and base-image scanning, dependency and SBOM checks, policy-as-code, and automated guardrails.
- Write and maintain Terraform modules and golden patterns so that the secure path is the easy path for product engineers.
- Drive adoption of automated security tooling, including cloud-native vulnerability scanning and security agents (e.g. AWS Inspector).
- Evaluate and recommend secure development tooling, including IDE-integrated security and AI coding-assistant guardrails.
- Improve detection coverage for cloud-native attack paths.
- Act as senior responder for cloud security incidents: build and maintain runbooks, and run post-incident reviews that produce durable fixes.
- Assess the impact of vulnerabilities and exploits, and own the incident response process end to end.
- Manage CSPM/CNAPP tooling: triage findings and drive remediation with the owning teams.
- Analyze the impact of WAF rules on our products.
- Coordinate DAST and penetration testing programs across products.
- Support ISO 27001 with evidence and control implementation.
- Support regulatory security obligations, including the EU Cyber Resilience Act (CRA).
- Lead security reviews of new third-party tools.
- Mentor engineers on secure cloud design and act as security partner to the platform, product, and operations teams.
Qualifications
- 8+ years in security engineering, including at least 5 focused on cloud.
- Deep, practical expertise with the AWS security suite: Organizations and SCPs, KMS, Config, GuardDuty, CloudTrail, Security Hub, Inspector, WAF, and Shield Advanced.
- Strong infrastructure-as-code skills (Terraform) and scripting and automation (Python, Go).
- Kubernetes and container security experience.
- Working knowledge of identity protocols (OIDC, OAuth 2.0, SAML) and of applied cryptography and PKI: key hierarchies, certificate lifecycle, and secure key storage.
- Experience with secure SDLC practices: threat modeling, secure design review, SAST/DAST, and penetration testing.
- Experience leading incident response.
- Strong communication skills: you can influence engineering teams you do not manage and explain risk to non-security stakeholders in terms of business impact.
- Certifications such as AWS Certified Security – Specialty, AWS Certified Advanced Networking – Specialty, AWS Certified Solutions Architect – Professional, CISSP, or CCSP.
- Experience with media security, DRM, conditional access, or anti-piracy technologies.
- Knowledge of the EU Cyber Resilience Act and related product security regulations.
- Experience with HSMs and cryptographic key management.
- Familiarity with on-premises and cloud security tooling supporting the SDLC.
By submitting this form, I agree to the processing of my personal data for the purpose of processing my job application and replying to my request,
in compliance with Verimatrix’s privacy notice