The world's trusted engineering network
Cybersecurity Architect
Location
Ireland
Posted
34 days ago
Salary
0
Seniority
Senior
Job Description
Cybersecurity Architect
Castillians
• Own the end-to-end security architecture for our AWS/Azure cloud environments, including networking, IAM, data encryption, and logging. • Embed security controls into CI/CD pipelines, including automated SAST/DAST scanning, software composition analysis (SCA), and container image scanning in Kubernetes. • Design and implement a Zero Trust architecture, including micro-segmentation, least-privilege access, and continuous device posture validation. • Conduct threat modeling for new product features and microservices using the STRIDE or OWASP threat modeling frameworks. • Build and maintain security-as-code using Terraform, CloudFormation, or Pulumi, ensuring all cloud resources are deployed with hardened baselines. • Select, deploy, and manage security tooling such as CSPM, CWPP, SIEM, and SOAR platforms, integrating them with existing DevOps workflows. • Lead the response to security incidents by performing forensic analysis on cloud workloads and recommending architectural fixes to prevent recurrence. • Partner with legal and compliance teams to map technical controls to requirements for SOC 2, HIPAA, PCI-DSS, and GDPR. • Design secrets management solutions using HashiCorp Vault or cloud-native key management services (KMS). • Create and maintain architecture diagrams, runbooks, and threat models for all critical systems. • Mentor software engineers on secure coding practices and conduct regular architecture review sessions. • Participate in an on-call rotation for security emergencies and critical patch deployments.
Job Requirements
- Experience in cybersecurity roles, with at least 4 years specifically architecting security solutions in a cloud-native environment.
- Strong programming or scripting experience in Python, Go, TypeScript, or Bash.
- Hands-on experience with container orchestration (Kubernetes, EKS, AKS, or GKE) and service mesh technologies (Istio, Linkerd).
- Deep expertise in at least one major cloud provider (AWS, Azure, or GCP), including native security services (Security Hub, GuardDuty, Sentinel, Policy as Code).
- Infrastructure as Code: Terraform, CloudFormation, or ARM templates.
- CI/CD Tools: GitHub Actions, GitLab CI, Jenkins, or ArgoCD.
- Container Security: Docker, Kubernetes security contexts, admission controllers (OPA/Gatekeeper), and image scanning (Trivy, Clair).
- Identity & Access: OIDC, OAuth 2.0, workload identity, and conditional access policies.
- Monitoring & Logging: Prometheus, OpenTelemetry, ELK Stack, or Datadog.
- Certifications (Nice to have, not required): Certified Kubernetes Security Specialist (CKS), AWS Certified Security – Specialty or Azure Security Engineer Associate, GIAC Cloud Security Essentials (GCLD), Certified DevSecOps Professional (CDP)
Benefits
- Clear scope with no ambiguity over deliverables
- Opportunity for repeat engagements based on performance
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Analyze and document current and future business processes and workflows • Facilitate meetings with business and technical teams to gather requirements • Prepare BRDs, functional documents, use cases, and user stories • Identify system integration points and document data flows between applications • Support PMO activities including task tracking, documentation, and coordination • Collaborate with stakeholders to ensure clear understanding of project goals • Assist in User Acceptance Testing (UAT), test plans, and test cases • Identify process improvements, automation opportunities, and efficiency gaps • Maintain project documentation and ensure alignment with business needs • Support implementation and ensure solutions meet requirements
Enterprise Account Executive, Google Cloud Security
Foresite CybersecurityTransform security from a barrier to a Catalyst
• Operate at the intersection of Foresite’s cybersecurity expertise and Google’s security technology. • Partner closely with Google Cloud field sellers, Google Security specialists, and Foresite’s solution architects and delivery teams to identify opportunities, shape solutions, and close business. • Measured on new logo acquisition, annual recurring revenue (ARR), and the expansion of existing customer relationships. • Execute a strategic territory plan to achieve and exceed quarterly and annual bookings quotas for Foresite’s Google Security-aligned services. • Build and maintain a qualified pipeline through direct prospecting, account-based outreach, and co-selling with Google Cloud field teams and channel partners. • Lead negotiations and drive deals to completion, ensuring accurate forecasting and disciplined use of CRM (HubSpot/Salesforce) and deal-desk processes. • Collaborate with Google Cloud account teams on joint account planning, opportunity registration, and leveraging partner funding programs (MDF, POC funding) to accelerate cycles. • Partner with Foresite solution architects and Google specialists to design compelling, outcome-focused proposals and Statements of Work (SOWs). • Represent Foresite at industry events, Google Cloud partner forums, and customer briefings as a credible voice for our Google Security practice. • Develop deep relationships with CISOs, CIOs, and security leaders to understand their business drivers, compliance requirements, and SOC maturity. • Provide structured insights into Foresite’s product and marketing leadership regarding customer needs and competitive dynamics to enhance our service portfolio.
Enterprise Account Executive, Cloud Security
Foresite CybersecurityTransform security from a barrier to a Catalyst
• Operate at the intersection of Foresite’s cybersecurity expertise and Google’s security technology. • Partner closely with Google Cloud field sellers and Google Security specialists to identify opportunities, shape solutions, and close business. • Execute a strategic territory plan to achieve and exceed quarterly and annual bookings quotas. • Build and maintain a qualified pipeline through direct prospecting and co-selling with Google Cloud field teams. • Lead negotiations and drive deals to completion, ensuring accurate forecasting and CRM processes. • Collaborate with Google Cloud account teams on joint account planning and leverage partner funding programs. • Develop deep relationships with CISOs, CIOs, and security leaders to understand their business drivers and compliance requirements. • Provide structured insights into Foresite’s product and marketing leadership regarding customer needs.
• Develop and maintain Tetragon runtime security policies to ensure customers have good visibility of suspicious activity on their infrastructure and are protected against the latest emerging threats • Help design frameworks and architectures that allow customers to easily consume policies and understand their overall security posture • Monitor vulnerability disclosures (CVEs) and the latest threat intelligence to develop Tetragon runtime security policies • Work with software engineers at Isovalent and Cisco to improve and enhance the capabilities of Tetragon security policies • Interact with solution architects and customers as necessary to support and deploy Tetragon security policies in production • Publish content and give talks based on your work



