Senior Security Specialist IAM
1 tydzień temu
Senior Security Specialist IAM
The security architect provides expert guidance for addressing current security issues but has the foresight to see where the industry is headed and proactively deliver optimal secure solutions. The architect is expected to think like an adversary and identify how solutions should evolve as the threat landscape changes. A senior tech-level role, the architect possesses strong communication and organizational skills, and the ability to guide less experienced coworkers. The architect provides technical leadership to delivery and solution design team members and advises executive leadership regarding matters of significant importance to the organization.
Task and accountabilitiesRemain current with new security threats and assess systems to ensure they can defend the business.
Conduct threat modelling and architectural assessments of applications to encompass all aspects of information security, ensuring security by design.
Document identified threats and provide corresponding mitigation strategies.
Evaluate technologies and solutions to enhance security capabilities.
Identify security gaps and communicate associated business risks to relevant stakeholders.
Provide solutions aligned with business needs, considering security and compliance requirements.
Verify the effectiveness of security controls in mitigating identified risks.
Assist engineering projects throughout the Secure Software Development Life Cycle (SSDLC) and collaborate to effectively prioritize product security elements.
5-10 years of experience in IT or IT Security
Strong knowledge of information security principles, security architectures, frameworks, standards, and emerging threats, with the ability to implement effective mitigation strategies.
Deep understanding of network protocols, operating systems, databases, applied cryptography, least privilege, zero trust principles, identity & access management, and other core information security concepts.
Familiarity with regulatory requirements and compliance standards (NIST, ISO 27001, GDPR, SOC2).
Expertise in cloud computing and its associated best security practices, covering applications, infrastructure, storage, platforms, and data security.
Hands-on experience in performing threat modelling for applications, identifying threats, and suggesting optimal mitigation strategies.
Strong understanding of threat modelling methodologies (e.g., STRIDE, DREAD, PASTA).
Proficiency in using threat modelling tools (e.g., Microsoft Threat Modelling Tool, Threat Modeler, OWASP Threat Dragon).
In-depth knowledge of common security vulnerabilities (e.g., OWASP Top Ten, CVEs) and attack vectors.
Must have experience in architecting and securing Cloud Computing Platforms such as Azure or AWS.
Demonstrate a deep understanding of Google Cloud Platform(GCP) concepts and architectures, with a focus for how security controls are applied to cloud-based technologies. Architecture & Networking , Identity & Access Management, Securing the CI/CD Pipeline, Secrets and Data Protection, logging and monitoring and Security controls for Containers(e.g., Dockers, Kubernetes).
Excellent communication and interpersonal skills, with the ability to interact with stakeholders at all levels and explain complex security concepts in an easily understandable manner.
Constantly research capabilities of current and new disruptive solutions on the market and make recommendations to security leadership.
Drive security efficiencies, enabling security team members to work on more advanced tasks.
Perform engineering performance testing to stress the limitations of security solutions while at the same time ensuring business innovation and day-to-day processes are not negatively impacted.
Experience in cloud computing technologies, including software-, infrastructure and platform-as-a-service, as well as public, private and hybrid environments.
Other qualifications:
Extensive knowledge of traditional security controls and technologies, such as Security Information and Event Management (SIEM) systems, intrusion detection/prevention systems (IDS/IPS), public key infrastructure (PKI), identity and access management (IDAM) systems, antivirus and firewalls, in addition to newer offerings such as endpoint detection and response (EDR), threat intelligence platforms, security automation and orchestration, deception technologies and application controls.
Competences required:
Analytical and problem-solving skills
Ability to work in cross functional teams, including remote and external resources
Ability to effectively communicate with technical resources
Works with minimal guidance and recognitions when guidance needed
Ability to understand and develop enterprise policy and technical standards with specific regard to data loss protection and secure configuration
Ability and willingness to learn new things about data loss protection management, exploits, hacker techniques, and overall security operations
We offer:
Being part of a fast-growing, dynamic company, recognized as one of the foremost global packaging manufacturers.
Great professional growth opportunities.
Annual bonus.
Private medical care & insurance plan for you to keep an eye on your health.
MyBenefit program.
Flexible and hybrid work arrangement: We offer a flexible hybrid work model – 2 days a week in the Krakow office, or fully remote if you're located elsewhere.
Parking space for all employees.
Comfortable working environment (library, relaxation area with a view of the Wawel castle and city center, casual dress code).
If you are a current CANPACK employee, please apply through your Workday account.
CANPACK Group is an Equal Opportunity Employer and all qualified applicants will receive consideration for employment without regard to race, colour, religion, age, sex, sexual orientation, gender identity, national origin, disability, or any other characteristic protected by law or not related to job requirements, unless such distinction is required by law.
-
Senior Security Specialist IAM
1 tydzień temu
Kraków, Lesser Poland canpack Pełny etatSenior Security Specialist IAMThe security architect provides expert guidance for addressing current security issues but has the foresight to see where the industry is headed and proactively deliver optimal secure solutions. The architect is expected to think like an adversary and identify how solutions should evolve as the threat landscape changes. A senior...
-
IAM Senior Risk Analyst
1 tydzień temu
Kraków, Lesser Poland Euroclear Pełny etatJob DescriptionAn Identity and Access Management (IAM) Senior Risk Analyst is responsible for identifying, assessing, and mitigating risks related to Identity and Access Management across the organisation. The Senior Analyst acts as a subject matter expert, collaborating with IT, security, compliance, and business stakeholders to drive continuous improvement...
-
Senior Manager IAM Enterprise Security
2 tygodni temu
Kraków, Lesser Poland Genuine Parts Company Pełny etatCompany BackgroundGenuine Parts Company founded in 1928 and based in Atlanta, Georgia, is a leading specialty distributor engaged in the distribution of automotive and industrial replacement parts and value-added services. The Company operates a global portfolio of businesses with more than 10,000 locations across the world, employing 63,000 people.The GPC...
-
IAM Consultant
3 dni temu
Kraków, Lesser Poland inhire Pełny etatDla naszego klienta Reply Polska poszukujemy osoby na stanowisko IAM Consultant.ResponsibilitiesAs an Identity and Access Management Consultant, you support our clients in the strategic further development of their IAM landscapes, ensuring sustainable and future-proof solutions.You analyze business processes, translate business requirements into tailored...
-
Global IT Security Expert
2 tygodni temu
Kraków, Lesser Poland CANPACK Pełny etatGlobal IT Security Expert - IAMPosition of broad specialization, with main area focusing on Identity and Access Management (IAM). In this role employee will lead and advance the strategic security operations and engineering initiatives across GGH related to Identity and Access Management, ensuring robust protection of digital assets, infrastructure, and...
-
Global IT Security Expert
1 tydzień temu
Kraków, Lesser Poland canpack Pełny etatGlobal IT Security Expert - IAMPosition of broad specialization, with main area focusing on Identity and Access Management (IAM). In this role employee will lead and advance the strategic security operations and engineering initiatives across GGH related to Identity and Access Management, ensuring robust protection of digital assets, infrastructure, and...
-
Information Security Senior Specialist
5 dni temu
Kraków, Lesser Poland Zurich Insurance Pełny etatPlace of work: CracowJob purpose:As an Information Security Specialist at Zurich, you will help protect our data, systems, and customers by implementing robust security measures and fostering a culture of security awareness. You'll work collaboratively across the business to reduce risks and ensure compliance, supporting Zurich's commitment to creating a...
-
Principal Domain Architect
1 tydzień temu
Kraków, Lesser Poland ABB Pełny etatW ABB pomagamy przemysłowi wyprzedzać konkurencję - działać sprawniej i ekologicznie. U nas postęp to standard – dla Ciebie, Twojego zespołu i całego świata. Jako globalny lider dajemy Ci to, czego potrzebujesz, by to osiągnąć. Nie zawsze będzie łatwo, rozwój wymaga determinacji. Ale w ABB nigdy nie będziesz działać sam. Zarządzaj tym,...
-
Principal Domain Architect
3 dni temu
Kraków, Lesser Poland ABB Pełny etatAt ABB, we help industries outrun - leaner and cleaner. Here, progress is an expectation - for you, your team, and the world. As a global market leader, we'll give you what you need to make it happen. It won't always be easy, growing takes grit. But at ABB, you'll never run alone. Run what runs the world.This Position reports to:IS ManagerIn this role, you...
-
Security Administration Specialist
3 dni temu
Kraków, Lesser Poland Brown Brothers Harriman Pełny etatAt BBH, Partnership is more than a form of ownership—it's our approach to business and relationships. We know that supporting your professional and personal goals is the best way to help our clients and advance our business. We take that responsibility seriously. With a 200-year legacy and a shared passion for what's next, this is the right place to build...