Security Architect, Italy
About us:
We are a community of visionary innovators, dedicated to providing pioneering software and consultancy services to financial institutions, trading firms, central banks, governments, and corporations around the world. We strive to simplify the way people work. We do that by providing workflow and process automation software, as well as providing real-time data and business intelligence to help people make better decisions. We are 13,000+ employees, we operate globally with 80+ global offices, and we serve over 4,800+ customers worldwide.
For the strengthening of the Chief Information Security Office (CISO) function within Cedacri’s companies, part of ION Group, we are looking for talented professionals to grow their career as Security Architect. This position is targeted at candidates with at least 5 years of relevant experience in Information Security, Security Architecture, or Cybersecurity Governance. Selected candidates will be placed in a dynamic and innovative environment and will collaborate with cross-functional teams to design, implement, and continuously improve the organization's security architecture and cybersecurity controls.
Learn more at www.iongroup.com.
Your role
Your key duties and responsibilities
- Define, review, and evolve the organization's security architecture strategy in alignment with business needs, technology roadmaps, and regulatory expectations.
- Contribute to the design and validate secure architectures for enterprise platforms, cloud services, applications, APIs, networks, and infrastructure environments.
- Define security requirements, architectural standards, patterns, and security-by-design principles to be adopted across projects and initiatives.
- Conduct security architecture reviews and risk assessments to identify control gaps and define appropriate mitigation strategies.
- Design and govern security controls related to Identity & Access Management (IAM), Privileged Access Management (PAM), PKI, encryption, authentication, and network security.
- Contribute to threat modeling activities for critical applications, business services, and enterprise platforms.
- Support the implementation of architectures aimed at reducing attack surface, improving resilience, and strengthening segregation and tenant isolation controls.
- Collaborate with Development, Infrastructure, Cloud, DevSecOps, Security Operations, Risk, and Compliance teams to ensure security requirements are embedded throughout the technology lifecycle.
- Evaluate emerging technologies, cybersecurity threats, and industry trends to continuously improve the organization's security posture.
- Contribute to the development of security standards, reference architectures, and strategic cybersecurity initiatives.
Other duties
We might ask you to perform other tasks and duties as your role expands.
Your skills, experience, and qualifications required
- Master's degree in Computer Science, Computer Engineering, Cybersecurity, Information Technology, or a related field (with honors preferred).
- At least 5 years of experience in Security Architecture, Cybersecurity Engineering, Information Security, or related disciplines.
- Strong knowledge of enterprise security architecture principles and industry frameworks.
- Proven experience designing secure architectures across cloud, infrastructure, network, application, and hybrid environments.
- Strong knowledge of IAM, PAM, PKI, encryption technologies, authentication protocols, and Zero Trust principles.
- Familiarity with security architecture concepts related to cloud-native environments, APIs, containers, Kubernetes, DevSecOps practices and SBOM/SCA processes.
- Experience conducting threat modeling and security risk assessments.
- Knowledge of ISO 27001, NIST, CIS Controls, DORA, NIS2, and operational resilience requirements applicable to regulated environments.
- Strong analytical skills with the ability to translate business and technical requirements into pragmatic security solutions.
- Excellent communication skills and ability to engage effectively with both technical and non-technical stakeholders.
- Certifications such as CISSP, CCSP, SABSA, TOGAF, ISO 27001 Lead Implementer, or equivalent would be considered a strong plus.
What we offer:
- Permanent employment contract
- Italian National Collective Labour Agreement for the Metalworking Industry (CCNL Metalmeccanico)
- Gross Annual Salary (RAL) ranging from €50,000 to €60,000, depending on experience, skills, and qualifications
- Job grade to be determined upon completion of the selection process, with final assessment between B3 and A1 level
- Opportunity to join a leading international technology group operating in the financial services industry
- Exposure to enterprise-wide cybersecurity initiatives in a dynamic, international, and highly innovative environment
Location:
Milano.
Important notes:
According to the Italian Law (L.68/99), candidates belonging to the protected categories list will be given priority.
Job Details
Salary
€50,000 – €60,000/yr (it)
Experience
Management