Назад
Company hidden
4 дня назад

Cybersecurity Solution Architect (Secure SDLC)

Формат работы
remote (только Poland)/onsite
Тип работы
fulltime
Грейд
senior/lead
Английский
c1
Страна
Poland
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Cybersecurity Solution Architect (Secure SDLC): Designing and overseeing enterprise Secure SDLC programs with an accent on application security, DevSecOps, threat modeling, and cloud-native security. Focus on embedding security into CI/CD workflows, defining risk-based governance and KPIs, and leading security transformation initiatives across client environments.

Location: Poland; remote or office work

Company

hirify.global delivers technology consulting and engineering services, including cybersecurity solutions for enterprise clients.

What you will do

  • Lead and grow the Cybersecurity Practice team, serving as Practice Lead for Secure SDLC and Application Security engagements.
  • Architect and oversee Secure SDLC programs for enterprise clients.
  • Assess security maturity and define strategic improvement roadmaps, KPIs, reporting frameworks, and risk-based vulnerability management practices.
  • Embed security into CI/CD pipelines and engineering workflows across multiple projects.
  • Lead threat modeling, secure architecture reviews, and security standards and guardrails across teams.
  • Advise clients on cloud and AI security, regulatory requirements, and security transformation initiatives while mentoring team members.

Requirements

  • 8+ years of experience in Application Security, DevSecOps, or Secure SDLC implementation, including team leadership or mentoring.
  • Expertise in designing and implementing Secure SDLC frameworks at enterprise scale.
  • Advanced skills in threat modeling, secure architecture reviews, design-level security validation, and security metrics.
  • Hands-on experience with SAST, DAST, SCA, secrets scanning, container and Kubernetes security, Infrastructure-as-Code security, and CI/CD security integration.
  • Experience defining security gates, risk-based policies, governance workflows, and exception and risk acceptance processes.
  • Fluent spoken and written English; ability to review source code in at least one of Java, .NET, Node, Python, or Go.

Nice to have

  • OSCP, OSWE, OSEP, OSCE, CREST, eCPPT, eCPTX, eWPT, or eWPT certification.

Culture & Benefits

  • Work in a collaborative team of cybersecurity experts.
  • Exposure to diverse industries, technologies, and complex security challenges.
  • Opportunity to work with modern cloud-native and AI security practices.
  • Focus on professional mentoring, team development, and cybersecurity thought leadership.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →