We are looking for an Infrastructure & Identity Security Architect to define and drive our enterprise security architecture across cloud, infrastructure, networks, endpoints, and identity platforms. You will establish zero-trust security standards, develop reference architectures, and partner with engineering teams to build secure and scalable technology solutions.
+ ' ' +
- Strong infrastructure and network security experience
- Strong experience with firewall, WAF, network segmentation and secure connectivity
- On-prem/datacenter infrastructure security experience
- Strong experience with enterprise security controls: DLP, PAM, MDM/MAM and Email Security
- Good understanding of AWS/Azure security concepts and hybrid infrastructure
- Good understanding of enterprise IAM/IDM: SSO, IdP, PAM, federation and identity lifecycle
- Familiarity with identity protocols: OAuth2/OIDC, SAML, SCIM
- Knowledge of NIST CSF/800-53/800-207, CIS and PCI-DSS security principles
- 8+ years of experience, senior/principal level
- Working proficiency in English or Russian
- Nice-to-have: banking/payments security and enterprise security architecture experience
- Relevant security, cloud or architecture certifications are an advantage
+ ' ' +
- Opportunity to learn through working
- Familiarity with a real banking environment
- Gaining practical knowledge and experience
- Development of communication and customer service skills
- Improving teamwork abilities
- Support from a professional mentor
- Chance to build a future career at Bir Ecosysem
+ ' ' +
- Define infrastructure security architecture and security baselines across on-prem, datacenter and cloud environments
- Define network security architecture and patterns: segmentation, secure connectivity, firewall/WAF standards, remote access
- Define security architecture for enterprise controls including DLP, PAM, MDM/MAM, Email Security Gateway, Firewall and WAF
- Define on-prem and bare-metal infrastructure security architecture, partnering with infrastructure and network teams
- Architect hybrid on-prem-to-cloud connectivity security
- Define enterprise identity and privileged access architecture: IDM/SSO, IdP, PAM, federation and access lifecycle
- Define endpoint and mobile access security patterns using MDM/MAM and conditional access controls
- Define data protection architecture across endpoint, email, web and cloud channels
- Recommend infrastructure, network, identity and security solutions and replacements; represent them in the Architecture CoE
Kapital Bank iş mühiti, əlavə fürsətlər və digər vakansiyaları görüntüləmək üçün Kapital Bank Life səhifəsinə keçid edin.
Elanlar birbaşa Whatsapp-a gəlsin: Whatsapp kanalımıza abunə olun!
Vakansiyalardan daha tez xəbərdar olmaq üçün Telegram kanalımıza abunə olun!