- Company Name
- Project Recruit
- Job Title
- Security Architect (Service Mesh & IBM DataPower)
- Job Description
-
Job Title: Security Architect (Service Mesh & IBM DataPower)
Role Summary:
Design, implement, and maintain secure service mesh architectures across Kubernetes and containerised environments, leveraging IBM DataPower for API security. Deliver risk assessments, threat models, and enforce compliance with PCI DSS, ISO 27001, GDPR, and other financial‑sector regulatory frameworks.
Expectations:
- Provide expert guidance on zero‑trust, mTLS, RBAC, and micro‑services security.
- Integrate security controls into CI/CD pipelines and downstream systems.
- Communicate security posture and remediation plans to technical teams and executive stakeholders.
Key Responsibilities:
- Develop and maintain service‑mesh security architecture for hybrid and multi‑cloud deployments.
- Conduct risk assessments, create threat models using MITRE ATT&CK & STRIDE, and recommend mitigations.
- Design, configure, and review API gateways and integration patterns with IBM DataPower appliances.
- Define and enforce security policies, standards, and best practices for APIs, data flows, and micro‑services.
- Implement mTLS, RBAC, zero‑trust principles within service mesh frameworks.
- Configure DataPower for API security, encryption, OAuth 2.0, JWT, WS‑Security, and traffic mediation.
- Collaborate with cross‑functional teams to embed security throughout development lifecycles.
- Present security risks, strategies, and business impact to leadership and stakeholders.
Required Skills:
- Proven experience as a Security Architect in large, complex or financially regulated organisations (PCI compliance).
- Hands‑on expertise with IBM DataPower, OAuth 2.0, JWT, TLS, WS‑Security, and encryption standards.
- Ability to develop bespoke threat models using MITRE ATT&CK & STRIDE.
- Strong knowledge of zero‑trust security models, micro‑services, and hybrid/multi‑cloud environments.
- Familiarity with PCI‑DSS, PCI‑P, ISO 27001, GDPR, and other regulatory compliance frameworks.
- Proficiency in CI/CD automation tools (Terraform, Ansible, Git, Jenkins).
- Excellent communication, interpersonal, and stakeholder‑management skills.
- Understanding of M&A security challenges is a plus.
Required Education & Certifications:
- Minimum bachelor’s degree in Computer Science, Information Security, or related field.
- Relevant professional qualification or actively pursuing: CISM, CISSP, or equivalent.
- PCI‑P certification or equivalent PCI‑DSS knowledge.
---