Senior Global IT Security Specialist
3 days ago
Job Description
Senior Security Specialist IAM
The security architect provides expert guidance for addressing current security issues but has the foresight to see where the industry is headed and proactively deliver optimal secure solutions. The architect is expected to think like an adversary and identify how solutions should evolve as the threat landscape changes. A senior tech-level role, the architect possesses strong communication and organizational skills, and the ability to guide less experienced coworkers. The architect provides technical leadership to delivery and solution design team members and advises executive leadership regarding matters of significant importance to the organization.
Task And Accountabilities
- Remain current with new security threats and assess systems to ensure they can defend the business.
- Conduct threat modelling and architectural assessments of applications to encompass all aspects of information security, ensuring security by design.
- Document identified threats and provide corresponding mitigation strategies.
- Evaluate technologies and solutions to enhance security capabilities.
- Identify security gaps and communicate associated business risks to relevant stakeholders.
- Provide solutions aligned with business needs, considering security and compliance requirements.
- Verify the effectiveness of security controls in mitigating identified risks.
- Assist engineering projects throughout the Secure Software Development Life Cycle (SSDLC) and collaborate to effectively prioritize product security elements.
Technical Skill
- 5-10 years of experience in IT or IT Security
- Strong knowledge of information security principles, security architectures, frameworks, standards, and emerging threats, with the ability to implement effective mitigation strategies.
- Deep understanding of network protocols, operating systems, databases, applied cryptography, least privilege, zero trust principles, identity & access management, and other core information security concepts.
- Familiarity with regulatory requirements and compliance standards (NIST, ISO 27001, GDPR, SOC2).
- Expertise in cloud computing and its associated best security practices, covering applications, infrastructure, storage, platforms, and data security.
- Hands-on experience in performing threat modelling for applications, identifying threats, and suggesting optimal mitigation strategies.
- Strong understanding of threat modelling methodologies (e.g., STRIDE, DREAD, PASTA).
- Proficiency in using threat modelling tools (e.g., Microsoft Threat Modelling Tool, Threat Modeler, OWASP Threat Dragon).
- In-depth knowledge of common security vulnerabilities (e.g., OWASP Top Ten, CVEs) and attack vectors.
- Must have experience in architecting and securing Cloud Computing Platforms such as Azure or AWS.
- Demonstrate a deep understanding of Google Cloud Platform(GCP) concepts and architectures, with a focus for how security controls are applied to cloud-based technologies. Architecture & Networking , Identity & Access Management, Securing the CI/CD Pipeline, Secrets and Data Protection, logging and monitoring and Security controls for Containers(e.g., Dockers, Kubernetes).
- Excellent communication and interpersonal skills, with the ability to interact with stakeholders at all levels and explain complex security concepts in an easily understandable manner.
- Constantly research capabilities of current and new disruptive solutions on the market and make recommendations to security leadership.
- Drive security efficiencies, enabling security team members to work on more advanced tasks.
- Perform engineering performance testing to stress the limitations of security solutions while at the same time ensuring business innovation and day-to-day processes are not negatively impacted.
- Experience in cloud computing technologies, including software-, infrastructure and platform-as-a-service, as well as public, private and hybrid environments.
Other Qualifications
- Extensive knowledge of traditional security controls and technologies, such as Security Information and Event Management (SIEM) systems, intrusion detection/prevention systems (IDS/IPS), public key infrastructure (PKI), identity and access management (IDAM) systems, antivirus and firewalls, in addition to newer offerings such as endpoint detection and response (EDR), threat intelligence platforms, security automation and orchestration, deception technologies and application controls.
Competences Required
- Analytical and problem-solving skills
- Ability to work in cross functional teams, including remote and external resources
- Ability to effectively communicate with technical resources
- Works with minimal guidance and recognitions when guidance needed
- Ability to understand and develop enterprise policy and technical standards with specific regard to data loss protection and secure configuration
- Ability and willingness to learn new things about dat
If you are a current CANPACK employee, please apply through your Workday account.
CANPACK Group is an Equal Opportunity Employer and all qualified applicants will receive consideration for employment without regard to race, colour, religion, age, sex, sexual orientation, gender identity, national origin, disability, or any other characteristic protected by law or not related to job requirements, unless such distinction is required by law.
-
Senior Global IT Security Specialist
19 hours ago
ROU - Bucharest - Aluminium Can, Romania CANPACK Full time 40,000 - 80,000 per yearSenior Global IT Security Specialist - OTPosition of broad specialization, with main area focusing on Operational Technology (OT) with a strong foundation in IT and Cybersecurity. In this role employee will ensure continuous operating and management on OT and IT Security across GGH global environment. Person will be responsible for creating, implementing and...
-
Senior Global IT Security Specialist
19 hours ago
ROU - Bucharest - Aluminium Can, Romania CANPACK Group Full timeSenior Global IT Security Specialist The security architect provides expert guidance for addressing current security issues but has the foresight to see where the industry is headed and proactively deliver optimal secure solutions. The architect is expected to think like an adversary and identify how solutions should evolve as the threat landscape changes. A...
-
Senior Global IT Security Specialist
6 days ago
Bucharest, Bucureşti, Romania CANPACK România Full time €90,000 - €120,000 per yearPosition of broad specialization, with main area focusing on Operational Technology (OT) with a strong foundation in IT and Cybersecurity. In this role employee will ensure continuous operating and management on OT and IT Security across GGH global environment. Person will be responsible for creating, implementing and maintaining of best practises for...
-
Senior Security Specialist IAM
1 week ago
Bucharest, Bucureşti, Romania CANPACK România Full time 40,000 - 80,000 per yearSenior Security Specialist IAMThe security architect provides expert guidance for addressing current security issues but has the foresight to see where the industry is headed and proactively deliver optimal secure solutions. The architect is expected to think like an adversary and identify how solutions should evolve as the threat landscape changes. A senior...
-
Application Security Engineer
1 week ago
Bucharest, Bucureşti, Romania Nord Security Full time 40,000 - 80,000 per yearThe world's most advanced VPN, and a whole lot more. If you're a curious problem-solver who carves their own path, join the team behind Threat Protection Pro, the NordLynx protocol, and the fastest VPN on the planet—tools that put privacy, security, and control back in people's hands.Your impact? Helping millions take back control of their online...
-
Application Security Engineer
19 hours ago
Bucharest, Bucureşti, Romania Nord Security Full time 120,000 - 180,000 per yearThe world's most advanced VPN, and a whole lot more. If you're a curious problem-solver who carves their own path, join the team behind Threat Protection Pro, the NordLynx protocol, and the fastest VPN on the planet—tools that put privacy, security, and control back in people's hands. Your impact? Helping millions take back control of their online...
-
Senior Security Systems Engineer
6 days ago
Bucharest, Bucureşti, Romania Randstad Digital Romania Full time €40,000 - €80,000 per yearProject overviewWe are looking for a Senior Security Systems Engineer to join our Randstad Digital Romanian Team in a new challenging project in the automotive field.Meet our clientOur client is a world leader in secure connectivity solutions for embedded applications, driving innovation in the secure connected vehicle, end-to-end security & privacy and...
-
Senior Linux Engineer
1 week ago
Timisoara Metropolitan Area, Romania Infosys Full time 40,000 - 120,000 per yearWe are seeking (inTimisoara and Bucharest) a highly skilled and experiencedSenior Linux Engineerto join a mission-critical infrastructure team within the banking sector.The ideal candidate will have expert-level proficiency inRed Hat Enterprise Linux (RHEL), strong experience withVeritas Cluster Server (VCS)and, ideally, hands-on knowledge ofIBM Tivoli...
-
Information Security Specialist
6 days ago
Bucharest Metropolitan Area, Romania Luxoft Full time €30,000 - €60,000 per yearProject descriptionJoin our Development Centre in Bucharest and become a member of our open-minded, progressive and professional team. In this role you will be working for one of our world-famous clients.The Chief Security Office (CSO) of our client comprises the Chief Information Security Office (CISO) and the Corporate Security unit. The CISO organization...
-
Security Specialist
1 week ago
Bucharest, Bucureşti, Romania eJobs Romania Full time 30,000 - 60,000 per yearAbout the RoleWe are looking for a skilled and proactive Security Specialist to join our team. In this role, you will work closely with the Group Security Team to ensure the integrity, confidentiality, and availability of our infrastructure and systems. Your primary focus will be on implementing security standards, monitoring system and network security, and...