NextRaiseNextRaiseFind jobs
Sign inSign up free
Jobs / Architect in Germany
10 days ago
Apply with autofill
Apply with autofill
Verimatrix·10 days ago
10 days ago

Senior Security Architect

Ismaning (Munich), GermanySenior · 5-8 yearsArchitect

Sign up free to see how well your resume matches this role.

Boost your chances at verimatrix

How you compare FREE

?
Your scoreYour score: not yet known
→
19
Top 10%Top 10%: 19 out of 100

Top 10% of NextRaise users matched against Architect roles in Germany.

Must-have skills for this role

  • aws
  • terraform
  • iam
  • python

PDF or DOCX · no account needed

Apply faster with autofill FREEThe NextRaise extension autofills your application in one click.careers.example.com/applyAutofillingFull namePriya SharmaEmailpriya.sharma@example.comPhone+49 30 1234567LocationBerlGet the extension

What you'll do

  • Architecture and design Design and own security controls across our AWS estate: IAM, network segmentation, encryption, logging, and secrets management.
  • Lead threat modelling and security architecture reviews for new services and major changes, working one-to-one with development teams on secure design.
  • Set cloud security policy and the security roadmap jointly with security and platform leadership.
  • Partner with Product Management to define and clarify security requirements.
  • Automation and secure-by-default engineering Build security into CI/CD: IaC scanning, container and base-image scanning, dependency and SBOM checks, policy-as-code, and automated guardrails.
  • Write and maintain Terraform modules and golden patterns so that the secure path is the easy path for product engineers.
  • Drive adoption of automated security tooling, including cloud-native vulnerability scanning and security agents (e.g. AWS Inspector).
  • Evaluate and recommend secure development tooling, including IDE-integrated security and AI coding-assistant guardrails.
  • Detection and incident response Improve detection coverage for cloud-native attack paths.
  • Act as senior responder for cloud security incidents: build and maintain runbooks, and run post-incident reviews that produce durable fixes.
  • Assess the impact of vulnerabilities and exploits, and own the incident response process end to end.
  • Vulnerability and exposure management Manage CSPM/CNAPP tooling: triage findings and drive remediation with the owning teams.

What they're looking for

  • 8+ years in security engineering, including at least 5 focused on cloud.
  • Deep, practical expertise with the AWS security suite: Organizations and SCPs, KMS, Config, GuardDuty, CloudTrail, Security Hub, Inspector, WAF, and Shield Advanced.
  • Strong infrastructure-as-code skills (Terraform) and scripting and automation (Python, Go).
  • Kubernetes and container security experience.
  • Working knowledge of identity protocols (OIDC, OAuth 2.0, SAML) and of applied cryptography and PKI: key hierarchies, certificate lifecycle, and secure key storage.
  • Experience with secure SDLC practices: threat modeling, secure design review, SAST/DAST, and penetration testing.
  • Experience leading incident response.
  • Strong communication skills: you can influence engineering teams you do not manage and explain risk to non-security stakeholders in terms of business impact.

Nice to have

  • Certifications such as AWS Certified Security – Specialty, AWS Certified Advanced Networking – Specialty, AWS Certified Solutions Architect – Professional, CISSP, or CCSP.
  • Experience with media security, DRM, conditional access, or anti-piracy technologies.
  • Knowledge of the EU Cyber Resilience Act and related product security regulations.
  • Experience with HSMs and cryptographic key management.
  • Familiarity with on-premises and cloud security tooling supporting the SDLC.

Summarised by NextRaise from the employer’s description, which follows in full below.

Full description from employer

Role Overview
The Senior Security Architect will be accountable for the security of the cloud infrastructure behind those services: reporting to the CTO, he/she sets the technical direction for cloud security across our AWS estate and define the standard that engineering teams build to. This is a hands-on senior role, positioned close to the platform and influential rather than supervisory.

Key Responsibilities
Architecture and design
  • Design and own security controls across our AWS estate: IAM, network segmentation, encryption, logging, and secrets management.
  • Lead threat modelling and security architecture reviews for new services and major changes, working one-to-one with development teams on secure design.
  • Set cloud security policy and the security roadmap jointly with security and platform leadership.
  • Partner with Product Management to define and clarify security requirements.
Automation and secure-by-default engineering
  • Build security into CI/CD: IaC scanning, container and base-image scanning, dependency and SBOM checks, policy-as-code, and automated guardrails.
  • Write and maintain Terraform modules and golden patterns so that the secure path is the easy path for product engineers.
  • Drive adoption of automated security tooling, including cloud-native vulnerability scanning and security agents (e.g. AWS Inspector).
  • Evaluate and recommend secure development tooling, including IDE-integrated security and AI coding-assistant guardrails.
Detection and incident response
  • Improve detection coverage for cloud-native attack paths.
  • Act as senior responder for cloud security incidents: build and maintain runbooks, and run post-incident reviews that produce durable fixes.
  • Assess the impact of vulnerabilities and exploits, and own the incident response process end to end.
Vulnerability and exposure management
  • Manage CSPM/CNAPP tooling: triage findings and drive remediation with the owning teams.
  • Analyze the impact of WAF rules on our products.
  • Coordinate DAST and penetration testing programs across products.
Governance, compliance, and enablement
  • Support ISO 27001 with evidence and control implementation.
  • Support regulatory security obligations, including the EU Cyber Resilience Act (CRA).
  • Lead security reviews of new third-party tools.
  • Mentor engineers on secure cloud design and act as security partner to the platform, product, and operations teams.

Qualifications
  • 8+ years in security engineering, including at least 5 focused on cloud.
  • Deep, practical expertise with the AWS security suite: Organizations and SCPs, KMS, Config, GuardDuty, CloudTrail, Security Hub, Inspector, WAF, and Shield Advanced.
  • Strong infrastructure-as-code skills (Terraform) and scripting and automation (Python, Go).
  • Kubernetes and container security experience.
  • Working knowledge of identity protocols (OIDC, OAuth 2.0, SAML) and of applied cryptography and PKI: key hierarchies, certificate lifecycle, and secure key storage.
  • Experience with secure SDLC practices: threat modeling, secure design review, SAST/DAST, and penetration testing.
  • Experience leading incident response.
  • Strong communication skills: you can influence engineering teams you do not manage and explain risk to non-security stakeholders in terms of business impact.
Nice to have
  • Certifications such as AWS Certified Security – Specialty, AWS Certified Advanced Networking – Specialty, AWS Certified Solutions Architect – Professional, CISSP, or CCSP.
  • Experience with media security, DRM, conditional access, or anti-piracy technologies.
  • Knowledge of the EU Cyber Resilience Act and related product security regulations.
  • Experience with HSMs and cryptographic key management.
  • Familiarity with on-premises and cloud security tooling supporting the SDLC.

By submitting this form, I agree to the processing of my personal data for the purpose of processing my job application and replying to my request,

in compliance with Verimatrix’s privacy notice

Company

Verimatrix
Ismaning (Munich), Germany

Company facts come from this company's own listings. We only show what the postings themselves carry.

Sourced from Verimatrix's careers site·first seen 11 Sept 2026·last verified 11 Sept 2026·How we source jobs

Similar jobs

  • Group Design Platform Software & AI Architect (m/f/d) at SGB-SMIT GroupRegensburg, Germany–match not yet calculated
  • Internship - Success Architect at telliBerlin, Germany–match not yet calculated
  • Sales Processes & Tools Architect (M-W-D) im Bereich M3-COM at pepperlfuchsMannheim, Germany–match not yet calculated
  • System Architect 5008 - 6008 product family (m/w/d) at freseniusmedicalcareDEU Schweinfurt, Germany–match not yet calculated
  • Function Architect (f/m/x) at zeissgroupJena, Germany–match not yet calculated

Browse more jobs

  • Architect jobs in Germany
  • Architectural Drafter jobs in Germany
  • BIM Manager jobs in Germany
  • Landscape Architect jobs in Germany
  • Architect jobs in United States
  • Architect jobs in India