Cloud Security Architect shaping security architecture for scalable cloud solutions at GRAYOAK. Collaborating with cross-functional teams to ensure secure software development and architecture.
Responsibilities
Define and evolve security standards, architecture baselines, and reference architectures for our platforms, applications, and cloud environments (Azure)
Ensure compliance with security policies through reviews of architecture decisions, code, and Infrastructure-as-Code
Implement and integrate security gates, policy-as-code, and automated validations into our CI/CD pipelines
Perform threat modeling as well as security reviews and audits for applications, web applications, and platform components
Define and review security standards for web applications and APIs (e.g., OWASP Top 10, OAuth2/OIDC, API Security)
Secure our AI-based applications and data flows against risks such as prompt injection or data exfiltration
Advise and enable our development teams in secure coding, application security, and secure architectural decisions
Requirements
Degree in (business) computer science, IT security, or a comparable qualification
Several years of experience in security architecture, application security, cloud security, or DevSecOps in modern software and cloud environments
Strong understanding of web application security and modern authentication and API security concepts (e.g., OWASP Top 10, OAuth2/OIDC, API Security)
Experience with application security and DevSecOps practices, such as security reviews, vulnerability management, security testing, or CI/CD security
Experience with cloud security architectures and relevant security services, ideally in the Azure ecosystem (e.g., Entra ID, Defender for Cloud, Key Vault, Azure Policy)
Experience with Infrastructure-as-Code (e.g., Bicep or Terraform) and assessing its security implications
Knowledge of policy-as-code and automated security checks within modern development and deployment processes
Preferably experience with cloud or security compliance frameworks or relevant certifications (e.g., AZ-500, SC-100, ISO 27001, SOC 2)
Structured, pragmatic, and communicative working style, with an understanding of security as an enabler for secure and fast product development
Excellent written and spoken English; German language skills are a plus.
Benefits
Flexible work: Work hybrid — in the office or from home — and adapt your working hours to your life situation
Comfortable locations: Modern offices in central locations in Frankfurt am Main or Berlin, well connected and conveniently designed
Learning and growth: Take the opportunity to gain hands-on experience in exciting projects and further develop your skills
Team spirit: Enjoy regular team events, afterworks, and networking opportunities to become part of our lively company culture
Your start: Ready from day one with IT equipment and a cool GRAYOAK merch package
Business Development Representative at xorlab driving proactive lead generation in cybersecurity market. Collaborating closely with sales and marketing team to optimize lead development processes.
Cyber Security Architect responsible for IT security compliance and cyber - risk management at a Swiss utility firm. Engaging with cross - functional teams to implement 'Secure - by - design' strategies.
Information Security Officer ensuring cybersecurity at an IT service provider for food and beverage sector. Developing strategies and overseeing security protocols while reporting to management.
Head of Information Security at Aurora shaping security strategy and governance in a software - focused global business. Leading security efforts to ensure resilience and compliance across operations.
Senior Security Engineer specializing in penetration testing and security strategies for fintech. Collaborating with teams to enhance security for AI applications and financial systems.
Principal Cyber Security Engineer for Identity Access Management at MSK managing identity solutions and advanced identity platforms. Partnering with stakeholders to align identity strategy and lead IAM initiatives.
Join The Missing Link as a Security Engineer, leveraging 3 - 4 years of IT Security experience. Lead projects in a collaborative environment with a focus on innovation and impact.
Engineer in Health, Safety and Environment for ArianeGroup focusing on industrial risk management. Involves audits, assessments, and safety training participation.
Senior Product Security Engineer at Red Hat focusing on security and compliance for digital sovereign products while collaborating across global teams and enhancing automation.
Security Engineer safeguarding K - 12 student data in several locations for EduTech startup. Designing secure software systems and ensuring data protection to comply with privacy standards.