Director of Cyber Security Architecture - Evinova

at  AstraZeneca

Göteborg, Västra Götalands län, Sweden -

Start DateExpiry DateSalaryPosted OnExperienceSkillsTelecommuteSponsor Visa
Immediate12 Jul, 2024Not Specified13 Apr, 2024N/AKey Management,Design,Security Protocols,Containerization,Continuous Monitoring,Network Architecture,Global Perspective,Security,Amazon Web Services,Aws,Software Design,Policy Development,Cloud Security,Customer Base,Communication Skills,FirewallsNoNo
Add to Wishlist Apply All Jobs
Required Visa Status:
CitizenGC
US CitizenStudent Visa
H1BCPT
OPTH4 Spouse of H1B
GC Green Card
Employment Type:
Full TimePart Time
PermanentIndependent - 1099
Contract – W2C2H Independent
C2H W2Contract – Corp 2 Corp
Contract to Hire – Corp 2 Corp

Description:

Are you ready to be part of the future of healthcare? Can you think big, be bold, and harness the power of digital and AI to tackle longstanding life sciences challenges? Then Evinova, a new health tech business part of the AstraZeneca Group might be for you!
Transform billions of patients’ lives through technology, data, and innovative ways of working. You’re disruptive, decisive, and transformative. Someone excited to use technology to improve patients’ health. We’re building a new Health-tech business – Evinova, a fully-owned subsidiary of AstraZeneca Group.
Evinova delivers market-leading digital health solutions that are science-based, evidence-led, and human experience-driven. Thoughtful risks and quick decisions come together to accelerate innovation across the life sciences sector. Be part of a diverse team that pushes the boundaries of science by digitally empowering a deeper understanding of the patients we’re helping. Launch pioneering digital solutions that improve the patients’ experience and deliver better health outcomes. Together, we have the opportunity to combine deep scientific expertise with digital and artificial intelligence to serve the wider healthcare community and create new standards across the sector.
The Cyber Security Architecture Lead role presents a unique opportunity to join Evinova from the beginning and implement innovative cyber security practices that are designed by industry, for industry. The Cyber Security Architecture Lead, reporting to the Evinova Head of Cyber Security, will be hands-on in ensuring that security requirements are adequately addressed across Evinova’s entire technology architecture (i.e., corporate infrastructure and customer-facing digital solutions). This role will encompass various architectural domains, such as Data Protection, Network Security, Cloud Security, Identity and Access Management, and Security Operations. In addition to developing Evinova-wide cyber architecture methodologies and future roadmaps, the Cyber Security Architecture Lead will also proactively identify and promote opportunities to optimize and simplify our cyber defenses. Additionally, this role will closely collaborate with globally dispersed technology teams – enabling excellent opportunities for professional development across technology domains and international geographies. Success in this role requires leading by influence, exhibiting strong emotional intelligence, and a natural disposition toward problem-solving. The ideal candidate will think holistically and deliver on pivotal initiatives to leverage next-generation security solutions.

MINIMUM QUALIFICATIONS:

  • Bachelor’s degree in Technology, Computer Science, Engineering, or a related field.
  • 8+ years of combined experience in the following: software design, distributed technologies, cloud security, security architecture, and enterprise security solutions for multiple technology platforms/frameworks/ languages.
  • Prior experience providing cybersecurity architecture-related capabilities at a SaaS/cloud service provider.
  • Prior experience architecting cyber security solutions for multi-tenant cloud environments across a global customer base.
  • Well-versed with application security implementations, firewalls, web application firewalls, DMZs, and network architectures.
  • Ability to guide the development, design, and implementation of security standard methodologies for all layers of the application stack.
  • Solid understanding of deploying applications in a cloud environment, containerization (e.g., Kubernetes, EKS, etc.), cloud patterns, and cloud service/user authentication.
  • Good understanding of Identity and Access Management (IAM), Cryptography / Key Management, Access Controls and Security Protocols, Secrets Modernization, and Secrets Management (e.g., MFA, SAML, OAuth, OIDC, etc.).
  • Demonstrable experience establishing cloud security strategies, securing multi tenant environments, and implementing data segregation/isolation controls in AWS.
  • Demonstrable experience securing cloud-based custom-developed solutions (e.g., policy development, controls identification and implementation, continuous monitoring, audit response, etc.).
  • A deep understanding of information security technologies, networking, and network architecture is required – preferably in-depth exposure to Amazon Web Services and Microsoft Azure security concepts/services.
  • Ability to make pragmatic decisions by analyzing highly complex situations, assessing risks, and balancing strategic and tactical compliance/quality requirements.
  • Ability to work independently in a fast-paced environment with a validated ability to handle contending priorities.
  • Excellent written and verbal communication skills, project management, process improvement, attention to detail, and critical thinking skills are highly preferred.
  • At least one of the following professional certifications: AWS Certified Solution Architect, AWS Security Principles, Certified Information Systems Security Professional (CISSP), and/or Certified Cloud Security Professional (CCSP).

DESIRED QUALIFICATIONS:

  • Master’s degree in computer science, engineering, or similar relevant area of study
  • Experience in ensuring compliance within a highly regulated sophisticated global business environment, particularly in the healthcare and/or clinical research industry.
  • A global perspective on privacy, security, and data protection issues and trends (experience with Asia-Pacific data privacy and protection regulations is a strong plus).
  • Demonstrate initiative, strong customer orientation, and cross-cultural working.

Responsibilities:

  • Develop and maintain the Evinova Cyber Security Architecture methodology and reference materials (e.g., designs, hardening guides, standards).
  • Develop and maintain a multi-year roadmap outlining key protection measures and their planned maturity/investment targets.
  • Determine and articulate risk-based protection schemes for relevant data, cloud environments, corporate infrastructure, and end-customer-facing digital solutions – addressing all applicable layers (e.g., data, transport, network, storage, etc.).
  • Ensure complete isolation of Evinova’s sensitive customer information from our partner company through physical and logical isolation, policies, and procedures.
  • Establish and maintain authoritative documentation articulating established security controls/technologies and system descriptions.
  • Evaluate proposed security architectures and designs to determine the coverage and effectiveness of planned cyber risk reduction measures.
  • Perform periodic reviews over critical components to identify gaps in the architecture and ensure developed systems and architectures are consistent with the Evinova Cyber security Architecture guidelines.
  • Contribute to Security Risk Management Plans and Data Flow diagrams for products and solutions.
  • Provide domain expertise level advisory to platform and product engineering teams, enabling timely consideration of cyber protection controls and integration with relevant cyber services (e.g., Security Monitoring, Threat Intelligence, etc.).
  • Partner with the Quality and Compliance Team to ensure the effectiveness of engineering security practices, aligned with relevant standards, and fully documented in policies/procedures. Supervise and develop remediation strategies to ensure continued compliance with relevant regulations and audit requirements.
  • Provide leadership and hands-on implementation support for cyber capability/tooling deployments.
  • Provide guidance and direction to distributed Security Engineers and Security Leads to ensure standardization and risk-aligned protection measures.
  • Collaborate with the Security Operations Lead and outsourced partners to optimize our security monitoring, vulnerability management, and detection capabilities.
  • Drive continuous improvement initiatives to enhance the effectiveness and efficiency of the cyber security program, leveraging feedback, metrics, and lessons learned.
  • Provide advisory-based perspectives to the CTO leadership team on appropriate technology solutions to align residual risk to the organizational risk appetite.
  • Actively collaborate with Evinova and AstraZeneca Group leadership to align and share best practices for cyber security, business continuity, and other related policies and procedures.


REQUIREMENT SUMMARY

Min:N/AMax:5.0 year(s)

Information Technology/IT

IT Software - Network Administration / Security

Software Engineering

Graduate

Technology computer science engineering or a related field

Proficient

1

Göteborg, Sweden