Cyber Security Architect (H/F) - NAVBLUE, INC.
AEROCONTACT
Date: 11 hours ago
City: Waterloo, Ontario
Contract type: Full time

Job Description: The Cyber Security Architect will work closely with the solution architects and enterprise architects to improve and maintain the cyber security of NAVBLUE’S products, services and infrastructure. The ideal candidate will play a critical role in designing and implementing cybersecurity frameworks to align with the business objectives and mitigate potential threats.Main Responsibilities:
- Perform Security Risk and Threat analysis during the initial design and the Software Development Life Cycle planning, analysis, and design phases. Providing recommendations and requirements for mitigating any security weaknesses identified while defining Non-Functional Requirements in coordination with Solutions Architects.
- Ensure Security by Design is embedded within the Software Development Life Cycle, while ensuring that all security requirements have been applied before product or function release.
- Analyse and interpret security scan results and vulnerability reports to develop prioritized remediation strategies, working closely with IT, Development and Hosting teams to address vulnerabilities effectively
- Engineer and implement security controls based on industry standards while continuously evaluating and enhancing our security infrastructure
- Collaborate with IT, DevOps and SecOps teams to architect, configure and implement security monitoring and defense tools (is. SIEM, IDS/IPS, ASM, WAF) to safeguard against security breaches, cyber threats and unauthorized access
- Report on and assist with all security events and incidents.
- Oversee Security testing, including penetration testing and vulnerability scanning
- Ensure products compliance with security standards and regulations
- Ensure NAVBLUE Security strategy deployment within technical operations
- Ensure effective synchronization and alignment with Airbus Security Organization
- Bachelor’s degree in technical discipline
- Training and education in cyber security principles
- 5+ years of Security Architecture/Engineering, and/or Network architecture, and/or Security Operations and/or Experience in software development; software architecture an asset.
- Industry certification (i.e. AWS CSA, ISC2 ISSAP, SABSA SCF or similar)
- Familiarity with various security certifications such as ISO2700, NIST, etc., sufficient to provide immediate leadership and guidance to individuals, teams and departments in meeting the organization’s security requirements
- Excellent management, analytical and problem-resolution skills
- Working knowledge of the SDLC and AWS network architecture
- Knowledge of the SAFe Agile method would be an asset
- Understanding of security testing in the software pipeline (SAST, DAST, SCA, RASP)
- Knowledge of STRIDE, DICE and other threat and risk frameworks
- Knowledge of AWS tools
- Proven experience managing multiple projects simultaneously
- Practical interpersonal skills; adaptable to all levels of the organization
- Ability to contribute in a collaborative environment
- Capable of influencing individuals at all levels of the organization to drive and implement change while identifying and minimizing the impact of risks
- Excellent communication skills in English (both written & verbal), including staff presentations
- Incident Management Systems
- Security Management Tools (email filtering, vulnerability scanning tools, security dashboards, etc.)
- Cloud security management tools like CNAPP, CSPM, CWPP, and CIEM.
- Security risk assessment methodology (EBIOS RM)
- Security Requirement Definition and Review
- 10-15% Domestic and International
See more jobs in Waterloo, ON