Secure Software Development Architect
hace 9 horas
Madrid
NTT DATA strives to hire exceptional, innovative and passionate individuals who want to grow with us. If you want to be part of an inclusive, adaptable, and forward-thinking organization, apply now. About the Role: We are looking for a Secure Software Development Architect with 2 to 5 years of experience in Secure Software Development Life Cycle (SSDLC) and/or DevSecOps to join our team in Europe. The successful candidate will be responsible for ensuring that security is embedded throughout the entire software development lifecycle, from initial design and requirements to deployment, operation, and continuous improvement. This role requires close collaboration with development, cloud, operations, and security teams in international environments. 🛠️ Key Responsibilities: • Design secure software architectures and environments from scratch, following security-by-design and security-by-default principles., • Define, analyze, and validate security requirements aligned with business needs, regulations, and industry best practices., • Perform threat modeling (e.g. STRIDE, OWASP methodologies), identify risks, and propose appropriate security controls and mitigation measures., • Support development teams in the implementation of security controls across applications, infrastructure, and CI/CD pipelines., • Integrate and maintain DevSecOps practices, including automated security testing and controls (SAST, DAST, SCA, IaC scanning, secrets management, etc.)., • Contribute to the operation and maintenance of systems, ensuring ongoing compliance with SSDLC and DevSecOps security principles., • Participate in the continuous improvement of secure development frameworks, processes, and standards. ☁️ Technical Skills & Knowledge: • Certain knowledge in cloud platforms (AWS, Azure and/or GCP), with a focus on secure architectures., • Knowledge of modern software architectures such as microservices, APIs, containers, and Kubernetes., • Understanding of application security, identity and access management (IAM), encryption, vulnerability management, and system hardening., • Familiarity with security standards and frameworks such as OWASP, NIST, ISO/IEC 27001, and CSA. 👤 Requirements: • 2–5 years of professional experience in secure software development, SSDLC, and/or DevSecOps., • English proficiency at C1 level (spoken and written)., • European nationality and residency within Europe., • Strong analytical skills, proactive attitude, and ability to communicate effectively with technical and non-technical stakeholders., • Team player with a quality-driven and security-oriented mindset. 🎓 Nice to Have: • Relevant certifications in security, cloud, or DevSecOps, such as:, • CSSLP, CEH, Security+, GWAPT, • AWS / Azure / GCP Security certifications, • CKAD / CKS, • OWASP-related certifications We Offer: • Opportunities for professional development and continuous training., • An inclusive and multicultural work environment., • Participation in innovative and challenging projects at an international level., • Competitive benefits package. If you are passionate about cybersecurity and ready to start your career in an international environment, we invite you to apply and join our team!