At IBM, work is more than a job - it's a calling: To build. To design. To code. To consult. To think along with clients and sell. To make markets. To invent. To collaborate. Not just to do something better, but to attempt things you've never thought possible. Are you ready to lead in this new era of technology and solve some of the world's most challenging problems? If so, let's talk.
- Lead the design and implementation of security architecture for Enterprise System( cloud-based/Infrastructure), ensuring the confidentiality, integrity, and availability of critical data and resources.
- Collaborate with cross-functional teams to assess, design, and integrate security controls into applications, infrastructure, and platforms across the organization.
- Guide secure network design, infrastructure, and cloud configurations.
- Develop risk management strategies for the organization by engaging with cross—platform units and understanding organizational risk appetite
- Develop and maintain security policies, standards, and guidelines that align with industry best practices and compliance requirements.
- Develop Monitoring for analyzing security logs and alerts to identify potential security incidents or breaches and respond promptly to mitigate risks.
- Design and implement automated security checks and controls throughout the software development lifecycle.
- Facilitate security training and awareness programs for development and operations teams.
- Evaluate new technologies, tools, and frameworks to enhance security capabilities and ensure they meet the organization's security standards.
- Participate in security audits and assessments, providing documentation and evidence as needed to demonstrate compliance with regulatory requirements.
- Stay up to date with the latest security trends, threats, and vulnerabilities, and proactively adapt security strategies to address emerging risks.
- Bachelor’s degree in computer science, Information Technology, or a related field. Master's degree preferred.
- At least 10 years of experience with proven expertise in security architecture (7+ Years in a Security Architecting role), focusing on cloud security and application security in complex, multi-cloud environments.
- Understanding of Application Security and DevSecOps.
- In-depth knowledge of cloud platforms such as AWS, Azure, or Google Cloud, and experience implementing security controls and best practices within these environments.
- Strong understanding of application security principles, including secure coding practices, vulnerability management, and threat modelling.
- Familiarity with industry security frameworks and standards (e.g., NIST, ISO 27001, CIS), Cloud Security posture management (CSPM) and DevSecOps.
- Relevant certifications such as Certified Cloud Security Professional (CCSP), Certified Information Systems Security Professional (CISSP), Certified Secure Software Lifecycle Professional(CSSLP) or Certified Application Security Engineer (CASE) are a plus.
- Excellent communication and collaboration skills, with the ability to work effectively with technical and non-technical stakeholders.