Cybersecurity Solution Architect
At IDEMIA, we aim to offer our employees, a dynamic and exciting environment where you have opportunities for career growth and professional development.
Internal mobility is a great way for you to energize your career and to build your personal brand. It’s also a great way to explore other functions, professions or countries as IDEMIA operates in different businesses and in 50+ locations around the world.
Purpose
Purpose of the role
The Cybersecurity Solution Architect ensures that security is designed into complex customer solutions from bid and project inception through deployment and handover to operations. Working within international project teams, the role translates customer, contractual and regulatory expectations into practical security architectures, requirements, controls, verification plans and project deliverables.
This is primarily an architecture and technical leadership position. The successful candidate remains close to implementation, can review configurations and troubleshoot complex issues, but is not expected to perform all routine build and administration activities personally. He is expected to strongly contribute to the standardization of the cybersecurity architecture and processes on an ongoing basis.
Role positioning
On the vast majority of programs : 100% architecture, security engineering and project assurance with strong reuse in connection with product and architecture standardization;
On most complex programs : approximately 80% architecture, security engineering and project assurance; approximately 20% hands-on validation, prototyping and support to implementation teams. The exact balance may vary by project phase.
Success in the role
- Security requirements are clear, proportionate, traceable and understood by delivery teams.
- Architectural decisions and residual risks are documented early enough to avoid late project rework.
- Implementation teams receive actionable guidance and reference configurations where needed.
- Security verification evidence is complete and accepted before operational handover.
- Reusable security patterns and lessons learned improve the efficiency and consistency of future projects.
Key Missions
Key responsibilities
Security architecture and requirements
- Analyse customer, contractual and high-level security requirements, then derive clear and testable requirements for infrastructure, networks, applications, identity, data protection, logging and monitoring
- Design and document security architectures for medium to large on-premises, hybrid or cloud-connected solutions, including trust zones, network segmentation, secure interfaces, administrative access and protection of data in transit and at rest
- Perform threat modelling and proportionate risk assessments, identify security gaps, propose treatment options and support formal risk acceptance when required
- Define security controls and hardening principles for Windows, Linux, virtualisation, directories, databases, middleware, applications and security appliances
- Contribute to solution sizing, technical choices, bills of materials, effort estimates and security-related cost estimates
Project delivery and technical leadership
- Act as the security focal point for project managers, solution architects, engineering teams, customers, partners and subcontractors
- Provide technical guidance to implementation resources and review low-level designs, configuration plans, hardening guides, firewall rules, WAF policies and other security deliverables
- Lead or support technical workshops, design reviews and security decision meetings, explaining risks and trade-offs to both technical and non-technical stakeholders
- Prepare and maintain project security documentation, including security architecture documents, requirements traceability, risk records, security plans, test strategies, operating guidelines and handover material.
- Support requests for proposals and the technical evaluation of internal or external solution providers
Security verification and handover
- Define the security verification strategy and acceptance criteria for the solution
- Coordinate or review vulnerability scans, configuration reviews, penetration tests, static or dynamic application security testing and remediation plans
- Validate security test evidence and confirm that residual risks, deviations and operational recommendations are documented before handover
- Support complex troubleshooting, security incidents and major changes during integration or early-life support
- Capture lessons learned and contribute reusable patterns, standards, templates and reference architectures for other projects
Scope of hands-on implementation
The architect may configure or prototype security technologies when this is necessary to validate a design, remove a technical blocker or establish a reference configuration. Routine installation, detailed configuration, repetitive rule implementation, patching and operational administration should normally be assigned to Network and Security Engineers, integrators or qualified partners
Examples of technologies that may require close architectural oversight include firewalls, WAF, application delivery controllers and load balancers such as F5 BIG-IP, reverse proxies, VPN, IDS/IPS, IAM/PAM components, PKI, certificates, SIEM integration and operating system hardening. Direct expertise in every product is not required
Profile & Other Information
Candidate profile
Essential experience and capabilities
- At least 5 years of relevant experience in cybersecurity architecture, security engineering, infrastructure security or a comparable technical role. Strong candidates with a different career path but equivalent capability will also be considered.
- Demonstrated experience designing or securing medium to large IT solutions across at least two of the following areas: system and platform security, network security, identity and access management, application security, data security, cloud security or security monitoring.
- Solid understanding of enterprise infrastructure and network fundamentals, including TCP/IP, routing, segmentation, DNS, HTTP/S, TLS, certificates, authentication and high availability.
- Ability to convert security risks and customer expectations into pragmatic, documented and testable controls.
- Experience producing architecture and project security documentation in English.
- Ability to guide engineers, challenge suppliers constructively and work autonomously in international, multidisciplinary project teams.
- Professional fluency in English. Mastering further languages (Spanish, Arabic, …) is very welcome.
Desirable experience
- Hands-on exposure to one or more security or application delivery technologies, for example F5 BIG-IP LTM or Advanced WAF, another WAF or reverse proxy, next-generation firewalls, VPN, IDS/IPS, IAM/PAM, PKI or SIEM.
- Experience with security hardening of Windows, Linux, Active Directory or LDAP-based environments.
- Experience with secure software development practices, OWASP guidance, vulnerability management and application security testing.
- Experience securing highly sensitive, regulated, public-sector or mission-critical systems.
- Knowledge of cloud or container security in Azure, AWS, Kubernetes or OpenShift environments.
- Experience coordinating penetration tests and driving remediation to closure.
Standards and methods
- Practical knowledge of one or more recognized approaches is expected. Candidates are not required to be specialists in every framework.
- ISO/IEC 27001 and ISO/IEC 27002 security controls
- ISO/IEC 27005, EBIOS Risk Manager or an equivalent risk assessment method
- NIST Cybersecurity Framework or NIST security guidance
- CIS Benchmarks, vendor hardening guides and security-by-design principles
- OWASP guidance for web applications and APIs
Education and certifications
A degree in computer science, cybersecurity, engineering or a related field is welcome. Equivalent professional experience and demonstrable expertise are equally valuable.
Relevant certifications such as CISSP, CCSP, SABSA, CISM, GIAC, ISO 27001, cloud security, network security or vendor certifications are advantageous but are not mandatory. Certification evidence may be requested where a certification is claimed.
Ways of working
- Clear, structured and pragmatic communication with customers and delivery teams.
- Ability to balance security, delivery constraints, cost, performance and operability.
- Comfort working across design, integration, testing and handover phases.
- Willingness to travel occasionally for customer workshops, integration, acceptance or project support when required.
- Curiosity and commitment to maintaining current knowledge of threats, security practices and relevant technologies.
Seize all the opportunities of our fast-paced environment. Expect the unexpected.