Cybersecurity Architect - Embedded Technologies
- Full-time
- Job Family Group: Technology and Operations
Company Description
As the world's leader in digital payments technology, Visa's mission is to connect the world through the most creative, reliable and secure payment network - enabling individuals, businesses, and economies to thrive. Our advanced global processing network, VisaNet, provides secure and reliable payments around the world, and is capable of handling more than 65,000 transaction messages a second. The company's dedication to innovation drives the rapid growth of connected commerce on any device, and fuels the dream of a cashless future for everyone, everywhere. As the world moves from analog to digital, Visa is applying our brand, products, people, network and scale to reshape the future of commerce.
At Visa, your individuality fits right in. Working here gives you an opportunity to impact the world, invest in your career growth, and be part of an inclusive and diverse workplace. We are a global team of disruptors, trailblazers, innovators and risk-takers who are helping drive economic growth in even the most remote parts of the world, creatively moving the industry forward, and doing meaningful work that brings financial literacy and digital commerce to millions of unbanked and underserved consumers.
You're an Individual. We're the team for you. Together, let's transform the way the world pays.
Job Description
What's it all about?
The Security Architect will work as a member of the Global Cybersecurity organisation - Security Architecture team, which is focused on improving technology and architecture decision-making through collaboration with management, staff and customers on technology strategy, enterprise architecture, and investments in strategic security technology.
The individual, with a broad cybersecurity plus systems and network architecture knowledge and experience, will deliver security assessments while supporting our direction, lifecycle management and leadership for security architecture and technology. The individual will perform a key role in Security assessments while supporting various critical initiatives through the identification, analysis, evaluation, lifecycle management and adoption of security architectures and technologies. The Security Architect will work closely with other security functions and will provide guidance to ensure that there is coordination with their activities in technology choices. In addition, the Security Architect will be involved with education and mentorship, supporting the delivery framework, development of technical architecture and associated documentation, as well as advanced topics of research.
What we expect of you, day to day.
Leading and contributing to the security posture of Visa's networks and systems, data centre infrastructures, cloud architectures and solutions
Developing, contributing and management of Design Patterns, Reference Architectures, Security Strategies and Roadmaps
Applying security design principles to develop security solutions architectures
Providing strategic points of view for security solutions
Developing and/or carrying out the strategic direction of security projects to enable execution of the information security strategy
Developing security solutions to enable execution of the long-term security architecture in the cybersecurity product area
Driving security technologies evaluations, proof-of-concepts, and production pilots
Building strong cross-organisational relationship through integration with the teams, in order to effectively influencing staff across the IT organisation and product groups
Managing the lifecycle of security technologies
Working closely with the other technology architects to ensure that security is properly embedded in their technology domains architectures
Assisting other architects in defining the variance processes and making variance decisions
Evaluating and assessing risk as part of lifecycle management
Staying current with security technologies, as well as development techniques and methodologies in order to make recommendations for use based on business value
Advising leadership on Cybersecurity issues, systems, processes, products, and services
Maintaining oversight of the design and implementation of IT systems to ensure appropriate and effective security controls are included.
Contribute to the definition of overall IT architecture from a cybersecurity lens.
Qualifications
What we 're after...
- BSc in Computer Science or another relevant discipline at 2:1 or above / or work-related experience
- Moderate to significant Cybersecurity, engineering and design experience in Data Centre Systems, Cloud Infrastructure and Platforms (IaaS security, PaaS security)
- Experience doing threat-modelling of complex systems
- Experience in delivering comprehensive architecture specifications for complex infrastructure security solutions
- Experience with creating technical documentation: product documentation, technology, software and systems architecture, and technical whitepapers
- Working experience with the following concepts: SSL Crypto Solutions, Data Protection and Security, Software Development Methodologies (E.G. Agile), API Gateways, Data Analytics
- Experience with open source security technologies
- Hands on cloud architecture, with knowledge and working experience in: OpenStack, Cloud Foundry, Server Virtualisation hypervisors (KVM, Xen, Hyper-V, VSphere), Linux Containers technologies (Docker, Mesos, Kubernetes), and distributed computing
- Experience with Linux and Linux security
- Programming/coding and DevOps experience is a plus (Python, Java, Jenkins, Ansible, Chef)
- Experience in feature and bug management through JIRA
- Solid understanding of and ability to speak to security principles in areas such as application security, virtualisation, cloud technologies, access control.
- Experience integrating multiple vendor products
- Hands-on experience and strong understanding of technology and enterprise security
- Experience with compliance, regulatory and legal requirements relevant to the payments processing industry such as PCI, SOX, Bank of England, and GDPR.
- Strong understanding of relevant Industry Principles, Best Practices, and Standards, such as PCI, NIST, ISO, IEEE, and TCG