Job
- Level
- Experienced
- Location
- Paderborn
- Working Model
- Hybrid, Onsite
- Job Field
- IT, Software, Security
- Employment Type
- Full Time
- Contract Type
- Permanent employment
Job Summary
In this role, you design security architectures, integrate security into the software development process, and conduct threat modeling to systematically identify and manage risks.
Job Technologies
Your role in the team
- As a Software Security Architect/Engineer, you embed security into the architecture: you derive security requirements from business goals, establish Security-by-Design principles, document, and advocate for architectural decisions.
- Methodical Threat Modeling: Systematically identify threats, attack vectors, and risks; derive and prioritize risk treatment.
- Secure Software Development (SSDLC): Integrate security throughout the development lifecycle - from requirements, design, and implementation to testing and operations (Shift-Left, automated checks, Definition of Done/Ready).
- Cryptography & Post-Quantum Readiness: Assess cryptographic decisions, ensure crypto agility, and prepare roadmaps for post-quantum migration (e.g., hybrid schemes, key/certificate lifecycle).
- Architecture Reviews & Guidance: Design and code reviews with a focus on security, curating patterns & anti-patterns, developing reference architectures and guardrails.
- Business context & governance: translate security requirements into business value (risk/cost-benefit analysis), define KPIs/OKRs for security, harmonize with compliance/data protection.
- Enablement & Leadership: Technical leadership in cross-functional teams, coaching of engineers/architects, knowledge preparation for the company's projects
This text has been machine translated. Show original
Our expectations of you
Qualifications
- Security-by-Design & SSDLC: Proficient in principles such as OWASP, Least Privilege, Defense-in-Depth, Fail-Secure, secure Defaults; creation of Security Requirements, Policies, and Acceptance Criteria.
- Threat Modeling & Risk Analysis: Routine with structured approaches (e.g., scenario- or component-based), deriving technical and organizational measures.
- Secure coding practices: Solid understanding of common vulnerability classes and practical countermeasures.
- Cryptography expertise: understanding of modern procedures, key/certificate management, PQ risks/migration paths; ability to plan crypto-agnostic interfaces and services.
- Leadership & Communication: Ability to facilitate decisions, provide technical guidance (even without disciplinary authority), and deliver clear decision templates β from Engineering to Management.
Experience
- Several years of experience in software/solution architecture or application security with demonstrable depth of conception.
- Architecture patterns: experience with service-oriented and event-driven architectures, asynchronous communication, robustness/resilience patterns, and secure integration scenarios.
This text has been machine translated. Show original
What we offer
- Of course, we offer the classics such as mobile working, bonuses, incentives, drinks, fruit, snacks, etc. BUT also much more:
- Work models adapted to life situations, sabbaticals, time instead of money.
- Childcare subsidies, Jobrad, Work-Life-Balance Bus, special payments, and much more.
- A wide range of personalized, individual, and up-to-date training programs through our S&N Academy. In addition to courses, access to entwickler.de and coursera.org, Red Hat Trainings, etc.
- Great emphasis on a tailored onboarding process, including a personal mentor. Respectful collaboration and working at eye level, naturally up to the management level.
- Valuable planning of personal career development through regular feedback discussions.
- Internal knowledge sharing through Friday lectures on current topics as well as projects in the S&N Group Competence Management to explore new methods and technologies.
This text has been machine translated. Show original
Benefits
Health, Fitness & Fun
Work-Life-Integration
Higher Take-Home Pay
Topics You Will Work On
Job Locations
About Your Employer
Keycon Informations GmbH
Keycon Informations GmbH was founded in Dresden in 2001 by two freelancers with the aim of ensuring 360Β° customer support.
Description
- Founding Year
- 2001
- Company Type
- Established Company
- Working Model
- Hybrid, Onsite
- Industry
- Internet, IT, Telecommunication