Senior Security Architect - HYBRID ATIZAPAN
Mexico City, Mexico
Diebold Nixdorf
Diebold Nixdorf offers world-leading banking solutions and retail technology systems that help banks, credit unions and retailers meet the needs of connected consumers.Diebold Nixdorf automates, digitizes and transforms the way people bank and shop. As a partner to the majority of the World's top 100 financial institutions and top 25 global retailers, our integrated solutions connect digital and physical channels conveniently, securely and efficiently for millions of consumers each day. We are seeking a Senior Security Architect.
The Information Security Architect provides industry recognized expert guidance for addressing current security issues but has the foresight to see where the industry is headed and proactively deliver optimal secure solutions. The architect is expected to think like an adversary and identify how solutions should evolve as the threat landscape changes. A senior-level role, the architect possesses strong communication and organizational skills, and the ability to guide less experienced coworkers. The architect possesses a great understanding of computer systems and network architectures and provides technical leadership to delivery and solution design team members.
- Delivers strategic thought leadership to the team that extends the Information Security strategy into the broader business, IT and Enterprise Architecture functions.
- Defines and takes ownership of a multiyear roadmap detailing capability, coverage, maturity, and effectiveness model that is used to measure the progress toward a desired target state for security
- Evaluate and monitor emerging security architectural trends in the industry and develop a robust reporting methodology for delivering the results of this analysis to Management
- Evaluate, analyze, and provide direction on the current domestic and international enterprise Information Security Infrastructure to ensure security best practices are implemented and identify areas for improvement
- Evaluates the current state and provides future state cloud security reference architecture. Architects friction-less preventative and detective security controls to be built into multi-cloud environments for Azure and AWS and works to provide guidance on continuous improvement
- Provides Cybersecurity integration and automation architectures for the next gen cloud native security stack that is identity and API driven. Provides guidance on reducing/mitigating the attack surface on the identity stack and designing for Zero-Trust Identity Protections
- Deeply understands the threat landscape and emerging threats (i.e. Ransomware) that may impact Diebold Nixdorf and knows how to architect leading strategies to mitigate risk
- Leverages threat intelligence for strategic architectural decisions to recommend security enhancement projects to improve the posture of the organization. Utilizes threat models and countermeasures to prioritize risk remediation and security enhancements
- In depth understanding of vulnerability management best security practices for Mobile, App, and Infrastructure security and embedding of toolsets within a Continuous Integration/Continuous Delivery (CI/CD) pipeline
- Evaluate the current state and develop secure reference architectures and/or patterns for company applications, DevSecOps (CI/CD) for containerized and virtualized systems, infrastructural components, and application and system patching and hardening capabilities
- For ongoing cloud, network, system, application and telephony projects, work with the respective technology teams to design a robust, reliable, and integrated IT security architecture covering the entire enterprise and addressing issues as prioritized by Information Security
- Provide architectural leadership and design capabilities to ensure Network Architecture is properly implemented and maintained.
- Act as an Advisor on technology solutions and IT processes
- Assist Risk Management & Compliance team with development of domestic and international security policies, standards and reference models to be implemented in the appropriate areas of the networks
- Build security reference architectures and patterns that can be implemented by engineering teams to address common security threats
- Maintain and update the security model, technologies and standards for system architects and designers
- Provide Security Architecture design services to portfolio teams during their engagement within the established solutions development lifecycle (SDLC)
- Serve as the Security Architecture domain expert for the SDLC by reviewing, developing architectural plans, and preparing architecture documentation and associated artifacts for internal projects through-out the SDLC
- Review and contribute to the incident management process to provide architectural solutions to address root cause of incidents
- Influence the planning and execution of incident response and postmortem exercises, with a focus on creating measurable benchmarks to show progress (or deficiencies requiring additional attention).
- Minimum of 8 – 10 years’ experience in the information security industry or demonstrable experience as an Information Security Architect with an additional 4 - 5 years’ experience with information security
- Experience with Microsoft Azure and/or Amazon Web Services (AWS)
- Demonstrated security platform design and implementation experience
- Proven experience with cloud security in AWS/Azure/, application/API security, firewalls, IDS/IPS, sandboxing, threat intelligence, vulnerability assessment and mitigation, SIEM, auditing, encryption, data loss prevention, threat intelligence, SASE, Zero-trust network access solutions, mobile application/system security
- Experience driving measurable improvement in monitoring and response capabilities at scale.
- Security frameworks (NIST, MITRE ATT&CK, Kill Chain)
- Expert Visio documentation experience
- Excellent verbal communication, organizational, presentation and planning skills
- Experience translating business direction into required security controls and collaborating from SME to C-Level
- Experience with PCI and GDPR compliance
- Demonstrated experience assessing risk and developing security controls at a business-appropriate level
- BS/BA degree or equivalent experience is required
- One or more certifications: CRTSA, CNDA, GDSA, CISSP-ISSAP, CISM, CISA, CCSP, SANS certs or other Security certifications is required
- Demonstrates long-term strategic impact over teams, projects or problems
- Recognized throughout the company as having authoritative technical or functional expertise.
- Serves as a key technical, process or functional consultant.
- Leverages expertise in existing and emerging technologies, processes and functional methodologies to resolve critical and complex issues.
- Recognized as an expert within the company and among client / customer groups.
- Coaches team members to help balance current areas of focus with long-term objectives.
- Manages and simplifies complex issues.
Why should you join Diebold Nixdorf?
Brightest minds + technology and innovation + business transformation The people of Diebold Nixdorf are 23,000+ teammates of diverse talents and expertise in more than 130 countries, harnessing future technologies to deliver personalized, secure consumer experiences that connect people to commerce. Our culture is fueled by our values of collaboration, decisiveness, urgency, willingness to change, and accountability.
–Diebold Nixdorf is an equal opportunity employer and we value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.
** To all recruitment agencies: Diebold Nixdorf does not accept agency resumes. Please do not forward resumes to our jobs alias, Diebold Nixdorf employees or any other organization location. Diebold Nixdorf is not responsible for any fees related to unsolicited resumes**
#LI-RR1
Why should you join Diebold Nixdorf?
Brightest minds + technology and innovation + business transformation The people of Diebold Nixdorf are 23,000+ teammates of diverse talents and expertise in more than 130 countries, harnessing future technologies to deliver personalized, secure consumer experiences that connect people to commerce. Our culture is fueled by our values of collaboration, decisiveness, urgency, willingness to change, and accountability.
–Diebold Nixdorf is an equal opportunity employer and we value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, gender identity, age, marital status, veteran status, or disability status.
** To all recruitment agencies: Diebold Nixdorf does not accept agency resumes. Please do not forward resumes to our jobs alias, Diebold Nixdorf employees or any other organization location. Diebold Nixdorf is not responsible for any fees related to unsolicited resumes**
We are a global Company operating in multiple Locations and Entities. As we are keen to find the best solution for our candidates several legal entities might be applicable for a Job offer. A List of our operating entities can be found here - https://www.dieboldnixdorf.com/en-us/about-us/global-locations
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: APIs Audits Automation AWS Azure C CCSP CI/CD CISA CISM CISSP Cloud Compliance DevSecOps Encryption Firewalls GDPR IDS Incident response IPS MITRE ATT&CK Monitoring NIST Risk management SANS SASE SDLC Security strategy SIEM Strategy Threat intelligence Vulnerability management
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.