Security Architect

Santalucía·Madrid, Spain

What they ask for

  • Have the right to work in Spain

    No sponsorship mentioned, and this kind of work is rarely sponsored in Spain.

  • Speak native-level Spanish

    Listed as a requirement in the ad.

  • Work in English

    English is required, per the ad.

  • Work on-site in Madrid

    No relocation package mentioned.

  • Have 10+ years of experience

    Senior-level role.

Pulled from the advert automatically — the full ad is what counts.

Added 27 days ago
Read the full advert

Nice to have

  • Certification in integration platforms or architectures.
  • Security certifications (CISSP, CISM, CCSP).
  • Enterprise and security architecture certifications: TOGAF, SABSA.
  • Advanced cloud certifications in Azure, AWS, or Google Cloud (e.g., Solutions Architect, Security Specialty).
  • Experience with enterprise architecture modeling tools, especially ARIS.
  • Enterprise architecture capabilities, enhancing the value of IT to the business.
  • Functional knowledge and experience in the healthcare sector.
  • Insurance reference models, such as ACORD.
  • Architecture frameworks, such as TOGAF.
  • Experience in project management.
  • Knowledge of agile methodologies.
  • Knowledge of corporate management tools, especially SAP products.
  • Knowledge of cloud technology stacks, in SaaS, PaaS models, etc. (AWS, Azure, Google Cloud)
  • Experience in IT management and governance models.
  • Experience in managing relationships with suppliers.

Education & certifications

  • Bachelor's degree in Computer Science, Telecommunications, or equivalent.
  • English proficiency required at a minimum B2 level (C1 desirable).

About the company & team

  • Demand Management: receiving business requirements, early identification of security needs, and determining the level of domain involvement.
  • Business: support in defining needs and ensuring compliance with regulatory and corporate security requirements.
  • IT Governance: coordination to align with corporate governance processes, prioritization of initiatives, and traceability of architecture decisions.
  • Information Security: key liaison to ensure the security architecture aligns with corporate cybersecurity policies and regulatory requirements.
  • Development and QA Departments: application of secure design guides, patterns, and criteria in development and quality testing of technology projects.
  • Infrastructures and Operations: implementation of security components across different environments and operational support for production.
  • Enterprise Architecture and Technology Subdomains: coordination with other architecture domains to ensure overall coherence of the technology and security strategy.
  • Security Solution Providers and Vendors: collaboration in the deployment of services, integration of new technologies, and evaluation of their applicability within the corporate ecosystem.

MISSION

As a Security Architect, you will be responsible for the implementation, and subsequent management and coordination of the Security Architecture domain, leading the definition and maintenance of the corporate security framework, as well as overseeing the integration of security requirements across all IT projects and operations. Your role is to coordinate, supervise, and ensure that corporate projects, infrastructures, and services comply with established security standards and principles, aligned with both the company strategy and applicable regulatory frameworks.

The main mission of the role will be to ensure that security is incorporated from solution design through to operations. Likewise, you will lead communication with other architecture, technology, and security areas to ensure overall coherence of the enterprise architecture and provide support in change management, auditing, compliance, and governance processes. To this end, you will act as the primary security liaison, representing the domain in committees, decision-making forums, and strategic planning processes.

Coordination of the Security Architecture domain

  • You will be responsible for the domain, reporting to the Technology Architecture lead.
  • Responsible for the management of capacity and resources of the security team, including external providers associated with security services.
  • Preparation and monitoring of domain budgets, as well as participation in estimating the annual project portfolio.
  • Planning and coordination of domain activities, defining work plans, prioritization mechanisms, and overseeing their follow-up.

Liaison with other areas and departments

  • Main point of contact with IT Governance, Information Security, Infrastructure and Operations, QA, and Development.
  • Coordination with the rest of the Technology Architecture subdomains and with the Enterprise Architecture area to ensure strategic alignment.
  • Active participation in committees and forums with different teams: security, strategic, operational, management, implementation, etc.

Management and technological evolution of the security framework

  • Define and maintain the corporate security reference framework, including standards, design patterns, good practice guides, and reference architectures.
  • Promote technological evolution in security, evaluating new trends and solutions, and applying them to the corporate context.

Designand implementation of security architectures

  • Development and validation of secure designs in collaboration with project teams.
  • Supervision to ensure that developments, tests, and deployments incorporate the required security controls.
  • Review and approval of changes relevant from a security perspective.
  • Maintenance of a security asset governance model (documentation, inventories, guides).

Leadership of security projects and initiatives

  • Ensure domain participation in all project phases (definition, design, construction, deployment, and operations).
  • Coordinate the integration of security requirements from the demand stage and throughout the full lifecycle of applications and services.
  • Manage the resolution of security issues and the tracking of exceptions, ensuring effective mitigation plans.

Production support and compliance

  • Ensure the organization has a secure and agile technology architecture, capable of meeting business and regulatory needs.
  • Provide support for internal and external audits, coordinating the preparation of evidence and ensuring the resolution of findings.
  • Cross-functional support to all teams on security matters.
  • Measure and report on domain performance, as well as the effectiveness of implemented security controls.

Required experience

  • Minimum 10 years in the IT sector, with at least 5 years in roles related to security, architecture, and governance.
  • Experience in defining standards and security architecture patterns.
  • Experience in audit and regulatory compliance processes in regulated environments (financial, insurance, telecom, public sector).
  • Experience in team leadership and vendor coordination.
  • Experience in executing transformation processes in large companies will be valued.

Required Knowledge

Demonstrable experience in:

  • Security governance and regulations: knowledge of frameworks such as ISO 27001, NIST CSF, GDPR, DORA, EBA, and ENS, with experience in risk management, compliance, audits, and exception management processes.
  • Networks and communications: secure design of corporate networks, segmentation and microsegmentation, firewalls, WAF, IDS/IPS, VPN, SD-WAN, as well as experience with advanced models such as Zero Trust Network Access (ZTNA) and SASE.
  • Identity and access management (IAM / PAM): experience in identity federation, SSO, and MFA, knowledge of protocols (SAML, OAuth2, OpenID Connect, LDAP), use of identity platforms (Azure AD, Okta, Ping Identity, Red Hat IdM), and privileged access management (PAM).
  • Data and information protection: data classification and labeling, encryption in transit and at rest (TLS, AES, KMS, HSM), DLP solutions, as well as secrets and key management (HashiCorp Vault, Azure Key Vault, AWS KMS).
  • Infrastructure, systems, and virtualization: experience in hardening Linux and Windows systems, secure virtualization (VMware, Hyper-V, KVM), security in containers and orchestrators (Docker, Kubernetes, OpenShift), and design of multi-platform architectures (cloud + on-prem).
  • Availability and continuity: design of resilient and fault-tolerant architectures, high availability (HA) strategies, and disaster recovery.
  • Logging, monitoring, and response: definition of centralized logging and continuous monitoring strategies, use of SIEM/SOAR (e.g., Splunk, Sentinel, QRadar), incident management and coordination with SOC/CSIRT, and configuration of security alerts.
  • Vulnerability and threat management: experience in designing integration with vulnerability detection mechanisms.
  • Applications and secure development: integration of security into CI/CD pipelines (DevSecOps), mitigation of common vulnerabilities, secure coding practices, and security testing of applications and APIs.
  • Security architecture governance: experience in defining and overseeing governance models, including the creation of reference frameworks, approval procedures, exception management, and traceability of decisions.
  • Team and vendor management: leadership of multidisciplinary teams and management of external vendors, ensuring alignment with security policies and proper allocation of responsibilities and capabilities.
  • Strategic planning and prioritization: knowledge of planning and prioritization methodologies for initiatives, balancing business demands with security risks and resource availability.
  • KPI management and executive reporting: definition and tracking of security and governance metrics, and the ability to synthesize results into executive reports for decision-making.
  • Security project and program management: experience in coordinating complex initiatives, applying project management methodologies (traditional or agile) and ensuring alignment with strategic objectives.

Skills

  • Cross-functional leadership and influence, managing multidisciplinary teams.
  • Planning, prioritization, and budget management skills.
  • Executive communication, adapting messages for management, business, and technical teams.
  • Rigor in applying governance processes and traceability.
  • Results-oriented, balancing security with deadlines and costs.
  • Strong analytical skills and ability to solve complex problems.
  • Innovative mindset and continuous updating on security and architecture trends.

At SANTA LUCIA S.A, CªSEGUROS we are committed to ensuring real and effective equal opportunities that allow us to promote professional development and workforce diversity, in line with our commitment to SDG 5 (Gender Equality) of the United Nations 2030 Agenda.

This job was automatically translated to English, .

About the company

Santalucía

Santalucía

Insurance

View company profile
Spanish company
9000 employees