Logo S&N Invent GmbH

Software Security Architect/Engineer

Job

  • Level
    Experienced
  • Job Field
    IT, Application, Security
  • Employment Type
    Full Time
  • Contract Type
    Permanent employment
  • Location
    Eschborn, Paderborn
  • Working Model
    Hybrid, Onsite
  • Job Summary

    In this role, you integrate security requirements into software architecture, conduct threat analyses, and establish security practices throughout the development lifecycle.

    Job Technologies

    Your role in the team

    • As a Software Security Architect/Engineer, you embed security into the architecture: you derive security requirements from business objectives, establish security-by-design principles, document, and advocate for architectural decisions.
    • Methodical Threat Modeling: Systematically identify threats, abuse/misuse paths, and risks; derive and prioritize risk treatment.
    • Secure Software Development (SSDLC): Integrate security throughout the development lifecycle - from requirements, design, and implementation to testing and operations (Shift-Left, automated checks, Definition of Done/Ready).
    • Cryptography & Post-Quantum Readiness: Assess cryptographic decisions, ensure crypto-agility, and prepare roadmaps for post-quantum migration (e.g., hybrid schemes, key/certificate lifecycle).
    • Architecture Reviews & Guidance: Design and code reviews with a security focus, curating patterns & anti-patterns, developing reference architectures and guardrails.
    • Business context & governance: translating security requirements into business value (risk/cost-benefit analysis), defining KPIs/OKRs for security, harmonizing with compliance/data protection.
    • Enablement & Leadership: Technical leadership in cross-functional teams, coaching of engineers/architects, knowledge preparation for the company's projects.

    This text has been machine translated. Show original

    Our expectations of you

    Qualifications

    • Security-by-Design & SSDLC: Proficient in principles such as OWASP, Least Privilege, Defense-in-Depth, Fail-Secure, secure Defaults; development of Security Requirements, Policies, and Acceptance Criteria.
    • Threat Modeling & Risk Analysis: Routine with structured approaches (e.g., scenario- or component-based), deriving technical and organizational measures.
    • Secure coding practices: Solid understanding of common vulnerability classes and practical countermeasures.
    • Cryptography expertise: understanding of modern techniques, key/certificate management, PQ risks/migration paths; ability to plan crypto-agnostic interfaces and services.
    • Leadership & Communication: Ability to facilitate decision-making, provide technical leadership (even without disciplinary authority), and deliver clear decision templates — from Engineering to Management.

    Experience

    • Several years of experience in software/solution architecture or application security with demonstrable depth of conception.
    • Architecture patterns: Experience with service-oriented and event-driven architectures, asynchronous communication, robustness/resilience patterns, and secure integration scenarios.

    This text has been machine translated. Show original

    What we offer

    • Of course, we offer the classics such as remote work, bonuses, incentives, beverages, fruit, snacks, etc. BUT also much more:
    • Work time models adapted to life situations, sabbaticals, time instead of money.
    • Childcare subsidies, Jobrad, Work-Life-Balance Bus, special payments, and much more.
    • A wide range of individual, personalized, and up-to-date training programs through our S&N Academy. In addition to training sessions, access to entwickler.de and coursera.org, Red Hat Trainings, etc.
    • Great emphasis on a tailored onboarding process, including a personal mentor. Respectful collaboration and working at eye level, naturally up to the management level.
    • Valuable planning of personal career development through regular feedback discussions.
    • Internal knowledge sharing through Friday lectures on current topics as well as projects in the S&N Group Competence Management to explore new methods and technologies.

    This text has been machine translated. Show original

    Benefits

    Work-Life-Integration

    Health, Fitness & Fun

    Topics You Will Work On

    Job Locations

    • Location Eschborn

      65760 Hessen

      Germany

    • Location Paderborn

      Nordrhein-Westfalen

      Germany

    About Your Employer

    S&N Invent GmbH

    S&N Invent GmbH

    We are a nationwide IT company with a comprehensive range of services across the entire IT lifecycle. Together with our customers, we develop solutions, implement projects and create digital added value.

    Description

  • Company Type
    Established Company
  • Working Model
    Hybrid, Onsite
  • Industry
    Internet, IT, Telecommunication
  • Employer reviews

    by devworkplaces.com

    Total

    (1 Review)
    3.9
    • Career Growth

      4.2
    • Engineering

      3.6
    • Workingconditions

      4.0
    • Culture

      4.0
    Show all reviews
    Logo S&N Invent GmbH

    Software Security Architect/Engineer

    Location
    Eschborn, Paderborn
    Working Model
    Hybrid, Onsite
    Diversity
    Open for all genders

    More Jobs