 
						Lead Security Architect
1 day ago
WELCOME TO SITA
At SITA, we keep airports moving, airlines flying smoothly, and borders open. Our technology and communication innovations power the success of the global air travel industry.
You'll find us in 95% of international airports, working closely with over 2,500 transportation and government clients. Each partnership brings unique challenges, and we thrive on delivering fresh solutions and cutting-edge tech to keep operations running like clockwork. We don't just move the world forward-we're proud to be recognized as a Great Place to Work by 79% of our employees and certified in most of our growing locations. Here, we feel empowered, supported, and inspired to grow.
Are you ready to love your job?
The adventure begins right here, with you, at SITA.
PURPOSEThe Security Architecture & Standards Centre of Expertise is a team within the Enterprise Information Security Office (EISO) at SITA. The mission statement is to ensure the infrastructure supporting the SITA products and solutions is designed to meet defined corporate, market and regulatory compliance requirements so it can enable SITA's business objectives. The remit covers all the shared and dedicated infrastructure supporting SITA as a business, as well as that used to deliver our products and customer solutions.
As a Security Architect you will provide design governance for the creation of secure infrastructure and the technologies securing that infrastructure. You will interface with the other architecture disciplines, DevOps teams, product management and other stakeholders in achieving this.
KEY RESPONSIBILITIES- Provide approvals for enterprise and solution architects at key stage gates that the infrastructure has been designed in accordance with security architecture governance.
- Document governance and approval decisions in wikis, architecture documents, blueprints and other artefacts.
- Provide security architecture Guidance & Guardrails through the infrastructure lifecycle (technology acquisition, design, development, deployment, operations and disposal).
- For Guardrails, work with DevOps teams and Product Owners in development of policies, configurations, infrastructure as code and other automations of security controls as SITA implements DevSecOps ("shift left").
- Provide guidance & governance around the technologies that secure the SITA infrastructure: Architecture strategy and provide security architecture Guidance & Guardrails.
- Provide security input to Product Managers at ideation stage when assessing potential new technologies, products & solutions.
- Research emerging infrastructure security technologies and trends.
- Influence SITA security Policy & Standards and the overall infrastructure security strategy.
EXPERIENCE
- 8+ years experience in an IT environment.
Required:
- Systems and big-picture thinking.
- In-depth knowledge of technical cyber security controls and their applicability to complex infrastructure and application architectures, including but not limited to: Next-Generation Firewalls, Network IDS / IPS platforms, Web Application Firewalls, EDR, encryption technologies, identity & access management, logging & monitoring (SIEM), vulnerability management etc.
- Strong understanding of cloud-based architecture and development (Infrastructure as Cloud, CI/CD pipelines) and cloud-based security controls (SASE, CSPM, CASB).
- Strong understanding of security automation (Ansible, Terraform, Puppet).
- Strong understanding of operating system and IT infrastructure hardening (CIS Benchmarks).
- Knowledge and demonstrated application of key security principals to architecture: defence in depth, zero trust, least privilege, segregation of duties.
- Excellent understanding of software defined networking (SD WAN) and key networking technologies (IPv4 & v6, OSPF, BGP, IPSEC, MACSEC, DNSSEC)
- Experience with PCI DSS compliant designs and P2PE.
- Strong communication skills, especially in taking complex technical information and presenting it to a non-technical audience.
- Proven ability to work with operations teams to plan projects, deal with technical issues and provide knowledge transfer.
- Excellent interpersonal skills, including the ability to influence and work with teams with different reporting lines.
- Performing data analytics / correlation and root cause analysis.
Desirable:
- Design experience with complex distributed DNS infrastructure, including Anycast and RPZs.
- Sound understanding of PKI including certificate chains, policies, and automation through ACME or REST APIs.
- Knowledge of privileged access / identity management.
- Understanding of data privacy / security principals and experience working with Data Loss Prevention techniques and technologies.
- Exposure to working with global Internet, IP Transit, Metro-E, and MPLS providers
- Knowledge of the management of Windows, Linux, VMware, and KVM environments at scale.
- Previous experience of Agile and / or DevOps methodologies.
- Architecture Modeling
- Cloud Computing
- Commercial Acumen
- Configuration Management
- Contingency and Disaster Recovery
- Data Architecture
- Enterprise Architecture & Governance
- IT Industry: Trends & Directions
- Information Security Architecture
- Managing Risk
- Network Architecture
- Requirements Analysis
- Service Oriented Architecture (SOA)
- Solution Architecture
- Standards Procedures & Policies
- System and Technology Integration
- Technical Writing/Documentatio
- Degree in a technical discipline (e.g. Computer Science Engineering Mathematics etc.) or sufficient work experience to demonstrate proficiency at this level.
- CISSP, CISM or similar certification in security field
- Vendor certifications, particularly in cloud and network security (Azure, AWS, VMWare, Palo Alto, Fortinet, Cisco, Juniper, Versa Networks)
- Exposure to, or certification in at least one of the following: TOGAF, SABSA, SaFE, ITIL 4 Stategic Leader
We're all about diversity. We operate in 200 countries and speak 60 different languages and cultures. We're really proud of our inclusive environment. Our offices are comfortable and fun places to work, and we make sure you get to work from home too. Find out what it's like to join our team and take a step closer to your best life ever.
Flex Week: Work from home up to 2 days/week (depending on your team's needs)
Flex Day: Make your workday suit your life and plans.
Flex-Location: Take up to 30 days a year to work from any location in the world.
Employee Wellbeing: We have got you covered with our Employee Assistance Program (EAP), for you and your dependents 24/7, 365 days/year. We also offer Champion Health - a personalized platform that supports a range of wellbeing needs.
Professional Development: Level up your skills with our training platforms, including LinkedIn Learning
Competitive Benefits: Competitive benefits that make sense with both your local market and employment status.
SITA is an Equal Opportunity Employer. We value a diverse workforce. In support of our Employment Equity Program, we encourage women, aboriginal people, members of visible minorities, and/or persons with disabilities to apply and self-identify in the application process.
- 
					  OT Security Architect7 days ago 
 Prague, Hlavní město Praha, Czech Republic Sandoz Full time 120,000 - 240,000 per yearOT Security ArchitectSandoz continues to go through an exciting and transformative period as a global leader and pioneering provider of sustainable Biosimilar and Generic medicines. As we continue down this new and ambitious path, unique opportunities will present themselves, both professionally and personally. Join us, the future is ours to shapeJob... 
- 
					Security Architect1 day ago 
 Prague, Hlavní město Praha, Czech Republic Dentons Full time 120,000 - 180,000 per yearDentons is the world's largest law firm, renowned for its commitment to delivering innovative legal solutions to clients around the globe. With offices in over 160 countries and a team of legal professionals dedicated to excellence, Dentons offers a dynamic and inclusive work environment. Dentons DES: Dentons Europe Services (DES) in Prague is at the... 
- 
					Lead Solution Architect1 day ago 
 Prague, Hlavní město Praha, Czech Republic AEVI Full time €70,000 - €120,000 per yearAt Aevi, we're not just a team; we're a vibrant, global community, committed to shaking up the payments industry. Our culture is all about innovation, creativity, and a passion for pushing boundaries. We're thrilled to welcome new Aevi'ators who vibe with our values and mission and are ready to join us on our journey of transformation and growth.The Lead... 
- 
					Lead Solution Architect3 days ago 
 Prague, Hlavní město Praha, Czech Republic AEVI Full time €45,000 - €55,000 per yearAt Aevi, we're not just a team; we're a vibrant, global community, committed to shaking up the payments industry. Our culture is all about innovation, creativity, and a passion for pushing boundaries. We're thrilled to welcome new Aevi'ators who vibe with our values and mission and are ready to join us on our journey of transformation and growth.The Lead... 
- 
					  Security Research Team Lead2 weeks ago 
 Prague, Hlavní město Praha, Czech Republic Cato Networks Full time 900,000 - 1,200,000 per yearWelcome to the future of cloud networking and security Cato Networks is the first company to converge enterprise networking and security into one centralized and global service that is delivered by cloud. It is led by networking and security pioneer Shlomo Kramer (Check Point, Imperva) and early investor (Palo Alto Networks, Exabeem, Trusteer and more). ... 
- 
					  Application Security Engineer1 week ago 
 Prague, Hlavní město Praha, Czech Republic Nord Security Full time 80,000 - 180,000 per yearThe world's most advanced VPN, and a whole lot more. If you're a curious problem-solver who carves their own path, join the team behind Threat Protection Pro, the NordLynx protocol, and the fastest VPN on the planet—tools that put privacy, security, and control back in people's hands.Your impact? Helping millions take back control of their online... 
- 
					  Senior IT Security Engineer5 days ago 
 Prague, Hlavní město Praha, Czech Republic Deutsche Börse Group Full time 90,000 - 120,000 per yearYour area of work:Deutsche Börse Group is a leading financial services provider, covering the full value chain of trading, clearing, settlement, and market data for stocks and derivatives. Our global success relies on highly integrated and automated IT solutions, which are core to Deutsche Börse's operations and provide companies and investors with access... 
- 
					  Senior IT Security Engineer1 week ago 
 Prague, Hlavní město Praha, Czech Republic Deutsche Börse Group Full time 900,000 - 1,200,000 per yearYour area of workSecure the future of Deutsche Börse Group by building and maintaining our critical PKI infrastructure. As a key member of the Security IT - Engineering team, you'll be responsible for the design, implementation, and operation of our next-generation PKI solution. This includes ensuring the confidentiality, integrity, and availability of... 
- 
					  Solution Architect – Create3 days ago 
 Prague, Hlavní město Praha, Czech Republic Tietoevry Full timeJob DescriptionWe are seeking an experienced architect with strong integration knowledge and the ability to combine holistic thinking with detailed analysis. You should feel confident in both technical discussions and leadership settings, and thrive in international, agile environments. As a Solution Architect in the Cards Simplification program, you... 
- 
					  Junior Security Architect Intern1 day ago 
 Prague, Hlavní město Praha, Czech Republic Sandoz Full time 450,000 - 900,000 per yearSandoz continues to go through an exciting and transformative period as a global leader and pioneering provider of sustainable Biosimilar and Generic medicines. As we continue down this new and ambitious path, unique opportunities will present themselves, both professionally and personally. Join us, the future is ours to shapeWe are looking for a motivated...