Senior Global IT Security Specialist
1 week ago
Senior Global IT Security Specialist
The security architect provides expert guidance for addressing current security issues but has the foresight to see where the industry is headed and proactively deliver optimal secure solutions. The architect is expected to think like an adversary and identify how solutions should evolve as the threat landscape changes. A senior tech-level role, the architect possesses strong communication and organizational skills, and the ability to guide less experienced coworkers. The architect provides technical leadership to delivery and solution design team members and advises executive leadership regarding matters of significant importance to the organization.
Task and accountabilities
Remain current with new security threats and assess systems to ensure they can defend the business.
• Conduct threat modelling and architectural assessments of applications to encompass all aspects of information security, ensuring security by design.
• Document identified threats and provide corresponding mitigation strategies.
• Evaluate technologies and solutions to enhance security capabilities.
• Identify security gaps and communicate associated business risks to relevant stakeholders.
• Provide solutions aligned with business needs, considering security and compliance requirements.
• Verify the effectiveness of security controls in mitigating identified risks.
• Assist engineering projects throughout the Secure Software Development Life Cycle (SSDLC) and collaborate to effectively prioritize product security elements.
Technical Skill:
Master Degree in IT or IT Security
5-10 years of similar experience
Experience in cloud computing technologies, including software-, infrastructure and platform-as-a-service, as well as public, private and hybrid environments.
Extensive knowledge of traditional security controls and technologies, such as Security Information and Event Management (SIEM) systems, intrusion detection/prevention systems (IDS/IPS), public key infrastructure (PKI), identity and access management (IDAM) systems, antivirus and firewalls, in addition to newer offerings such as endpoint detection and response (EDR), threat intelligence platforms, security automation and orchestration, deception technologies and application controls.
Strong knowledge of information security principles, security architectures, frameworks, standards, and emerging threats, with the ability to implement effective mitigation strategies.
Deep understanding of network protocols, operating systems, databases, applied cryptography, least privilege, zero trust principles, identity & access management, and other core information security concepts.
Familiarity with regulatory requirements and compliance standards (NIST, ISO 27001, GDPR, SOC2).
Expertise in cloud computing and its associated best security practices, covering applications, infrastructure, storage, platforms, and data security.
Hands-on experience in performing threat modelling for applications, identifying threats, and suggesting optimal mitigation strategies.
Strong understanding of threat modelling methodologies (e.g., STRIDE, DREAD, PASTA).
Proficiency in using threat modelling tools (e.g., Microsoft Threat Modelling Tool, Threat Modeler, OWASP Threat Dragon).
In-depth knowledge of common security vulnerabilities (e.g., OWASP Top Ten, CVEs) and attack vectors.
Must have experience in architecting and securing Cloud Computing Platforms such as Azure or AWS.
Demonstrate a deep understanding of Google Cloud Platform(GCP) concepts and architectures, with a focus for how security controls are applied to cloud-based technologies. Architecture & Networking , Identity & Access Management, Securing the CI/CD Pipeline, Secrets and Data Protection, logging and monitoring and Security controls for Containers(e.g., Dockers, Kubernetes).
Excellent communication and interpersonal skills, with the ability to interact with stakeholders at all levels and explain complex security concepts in an easily understandable manner.
Constantly research capabilities of current and new disruptive solutions on the market and make recommendations to security leadership.
Drive security efficiencies, enabling security team members to work on more advanced tasks.
Perform engineering performance testing to stress the limitations of security solutions while at the same time ensuring business innovation and day-to-day processes are not negatively impacted.
English: B2
Competences required:
Analytical and problem-solving skills
Ability to work in cross-functional teams, including remote and external resources
Ability to effectively communicate with technical resources
Works with minimal guidance and recognition when guidance is needed
Ability to understand and develop enterprise policy and technical standards with specific regard to data loss protection and secure configuration
Ability and willingness to learn new things about data loss protection management, exploits, hacker techniques, and overall security operations
If you are a current CANPACK employee, please apply through your Workday account.
CANPACK Group is an Equal Opportunity Employer and all qualified applicants will receive consideration for employment without regard to race, colour, religion, age, sex, sexual orientation, gender identity, national origin, disability, or any other characteristic protected by law or not related to job requirements, unless such distinction is required by law.
-
Senior Information Security Specialist
3 days ago
Bucharest, Bucureşti, Romania Deutsche Bank Full time 40,000 - 80,000 per yearDB Global Technology is Deutsche Bank's technology center in Central and Eastern Europe. Since its set-up in 2013, Bucharest Technology Centre (BEX) has constantly proven its capacity to deliver global technology products and services, playing a dynamic role in the Bank's technology transformation.We have a robust, hands-on engineering culture dedicated to...
-
Information Security Senior Specialist
3 days ago
Bucharest, Bucureşti, Romania Deutsche Bank Full time €40,000 - €80,000 per yearPosition OverviewDB Global Technology is Deutsche Bank's technology center in Central and Eastern Europe. Since its set-up in 2013, Bucharest Technology Centre (BEX) has constantly proven its capacity to deliver global technology products and services, playing a dynamic role in the Bank's technology transformation.We have a robust, hands-on engineering...
-
Information Security Senior Specialist
3 days ago
Bucharest, Bucureşti, Romania Deutsche Bank Full time 80,000 - 120,000 per yearJob Description:DB Global Technology is Deutsche Bank's technology center in Central and Eastern Europe. Since its set-up in 2013, Bucharest Technology Centre (BEX) has constantly proven its capacity to deliver global technology products and services, playing a dynamic role in the Bank's technology transformation.We have a robust, hands-on engineering...
-
Aviation Security Agent
7 days ago
Bucharest Metropolitan Area, Romania MOON SECURITY Full time 20,000 - 25,000 per yearLocation:Bucharest BranchWhy Moon Security?This is your opportunity to step into the world's most prestigious aviation security system. AtMoon Security, we don't just hire guards — we develop Aviation Security Agents with purpose, professionalism, and pride.What You'll DoAs anAviation Security Agent, you'll play a critical role in ensuring passenger safety...
-
Cyber Security Specialist
2 weeks ago
Bucharest, Bucureşti, Romania Detack Group Full time €40,000 - €80,000 per yearCompany Overview:Detack Group is a German cybersecurity company dedicated to providing top-tier security services globally, with offices in Germany (Ludwigsburg), USA (Austin, TX), Singapore, and Australia (Brisbane). As part of our strategic expansion, we have opened an office in Bucharest, Romania, located in One Cotroceni Park. We are seeking talented...
-
GRC Specialist
2 weeks ago
Bucharest, Bucureşti, Romania Global-e Full time 40,000 - 60,000 per yearWe're looking for a GRC Specialist to join Global-e's cyber security department and manage Global-e's governance, risk and compliance (GRC) aspects from ground up. Build GRC processes, implement new producers and maintain technology systems to support GRC.Responsibilities:Lead our compliance operations and audit plans including ISO 27001, SOC2, SOC3 and...
-
Security Architect
2 weeks ago
Bucharest, Bucureşti, Romania Global-e Full time €104,000 - €130,878 per yearWe're looking for a security architect to join Global-e's cyber security department and participate in securing users, products and services.The security architect will be part of securing SSDLC, as well as securing IT and cloud services. In addition to securing new technologies and 3rd party integrations. Responsibilities:Develop and maintain the security...
-
Partner Support Operations Specialist
2 weeks ago
Bucharest, Bucureşti, Romania Armis Security Full time €104,000 - €130,878 per yearArmis, the cyber exposure management & security company, protects the entire attack surface and manages an organization's cyber risk exposure in real time. In a rapidly evolving, perimeter-less world, Armis ensures that organizations continuously see, protect and manage all critical assets - from the ground to the cloud. Armis secures Fortune 100, 200 and...
-
Cyber Security Specialist
1 week ago
Bucharest, Bucureşti, Romania Pluxee Full time 30,000 - 60,000 per yearWe are seeking a motivated and skilledCyber Security Specialist (Mid-Level)to join our Information Security team. In this role, you will be responsible for protecting the organization's IT infrastructure, data, and systems against cyber threats. Reporting directly to the Security Manager, you will support daily security operations, compliance activities, and...
-
Information Security GRC Specialist
5 days ago
Bucharest Metropolitan Area, Romania Reconomy Full time €40,000 - €80,000 per yearAbout ReconomyReconomy is a global leader in the circular economy — combining technology, expertise, and innovation to help businesses reduce waste, optimize supply chains, and embed sustainability into their operations.Operating in80+ countries, our work spans three strategic loops:Recycle– enabling smarter material recovery through data and...