Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме
описание
Описания нет
задачи
Design and evolve enterprise security architecture across on-premise, cloud, and laboratory environments, aligning it with business needs and regulatory requirements
Define and maintain security architecture standards, reference designs, and technical guardrails for new and existing systems, applications, and infrastructure
Partner with Software Development and Product teams to embed security-by-design and privacy-by-design principles throughout the software development lifecycle
Evaluate and select security technologies and controls, and guide their integration into enterprise and cloud environments
Lead threat modeling and architecture-level risk assessments for new systems, applications, and major infrastructure changes
Provide technical leadership and mentorship to security engineers and analysts on architecture best practices and complex remediation efforts
Collaborate with compliance and QA/RA teams to ensure architecture decisions support audit readiness and alignment with frameworks such as ISO 27001, SOC 2, NIST, HIPAA, and FDA 21 CFR Part 11
требования
Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field, or equivalent practical experience
Significant professional experience in Security Architecture, Cloud Security, Information Security, or a related discipline, including hands-on design of enterprise or cloud security solutions
Deep understanding of security architecture principles, secure network and system design, identity and access management, and data protection strategies
Hands-on experience with cloud platforms (AWS, Azure, GCP) and their native security services
Experience designing security controls that satisfy regulatory and compliance requirements in enterprise environments
Strong verbal and written communication skills, with the ability to translate complex technical concepts for technical and nontechnical audiences and influence decisions across teams
Fluent in English and Russian, both written and spoken
Будет плюсом: experience in regulated industries such as biotechnology, healthcare, pharmaceutical, or life sciences; familiarity with cybersecurity frameworks and standards, including NIST, ISO 27001, SOC 2, HIPAA/HITECH, FDA 21 CFR Part 11, and GDPR; relevant information security or architecture certifications such as CISSP, SABSA, TOGAF, or similar