
Je suis
IT ou Finance
Je cherche
Freelance ou CDI
A propos
Recrutement IT
Recrutement Finance
Hub- Portage
Ressources
FR
Our client is building the EDP (Engineering Developer Platform), an internal cloud-native platform that enables software development teams across our client to accelerate the development, deployment, and operation of digital products addressing the major challenges of the energy sector. The EDP Platform is a service-oriented, hybrid cloud platform providing self-service capabilities for application teams. It delivers services covering: *Application infrastructure *Data services *Service lifecycle management *CI/CD and application delivery *Operational services The platform is deployed across private cloud and selected public cloud environments, providing a scalable and secure foundation for engineering teams. As a Senior Security Architect, you will join the Architecture Group within the Infrastructure Product Line (Infra PL). The Infra PL is responsible for designing and evolving the distributed infrastructure that powers the EDP Platform, providing foundational services such as: *Virtual machines *Object storage *Core networking *Storage platforms *Bare-metal infrastructure *Internal APIs and software services Working in this highly complex and distributed environment, you will play a key role in strengthening the security posture of the platform by defining security architecture, governance, standards, and strategic direction.
MissionYour Mission Your primary objective will be to improve the security posture of the Infrastructure Product Line by defining and driving security architecture,vgovernance, and engineering standards aligned with program requirements and non-functional requirements (NFRs). You will act as a trusted technical leader, partnering with architects, engineering teams, product owners, and security stakeholders across multiple product lines. Key Responsibilities *Translate threats, organizational security policies, and NFRs into practical engineering requirements, security patterns, and guardrails. *Lead and coordinate security architecture reviews for software platforms and core infrastructure. *Develop and maintain security documentation, including: - Security standards - Risk statements - Architecture principles - Architecture Decision Records (ADRs) - Security control definitions - Governance documentation *Build and maintain the Infrastructure Product Line security roadmap based on risk assessments, findings, product priorities, and delivery timelines. *Clearly communicate technical risks, mitigation strategies, and architectural trade-offs to senior leadership. *Facilitate architectural discussions across multiple stakeholders and drive technical consensus in complex environments. *Conduct structured threat modelling using formal methodologies. *Collaborate closely with architects and security experts across product lines to ensure end-to-end security alignment throughout the EDP program. *Make informed architectural decisions by distinguishing critical security controls from lower-priority improvements.
Profil recherchéWe are looking for a highly experienced Security Architect with a strong background in both infrastructure and software security. Required Experience *15+ years of experience in Security Architecture and Infrastructure Architecture. *Proven experience designing the security architecture of complex distributed systems. *Strong expertise in identity and access management (authentication, authorization, identity providers). *Expert knowledge of secrets, certificates, and cryptographic keymanagement. *Hands-on experience securing Kubernetes and containerized environments. *Proven experience leading threat modelling and security architecture reviews. *Ability to communicate technical risks and influence architecture decisions across multiple stakeholders. *Fluent English (C1 minimum). Nice to Have *Experience with virtualization, software-defined networking and distributed storage. *Experience with bare-metal infrastructure. *Experience with SPIFFE/SPIRE or similar workload identity platforms. *Experience working in highly regulated or sovereign environments. *Hands-on experience with Python, FastAPI, PostgreSQL and authentication/authorization frameworks. *CISSP, CCSP, SABSA or CNCF CKS certifications.
AvantagesDaily Rate: Depending on experience/profile + €150/day for on-site travel Start Date: September 7 Duration: Long-term assignment Location: Remote, with 3–4 days on-site in Berlin (travel required)