CIS Security Architect
Work location: 100% remote Start: ASAP/max. 30 days notice period Cooperation form: B2B with ITFS Rate: 200-250 PLN/h + VAT Recruitment process: Short phone call with ITFS recruiter -> Technical interview -> Client interview -> Decision
P3629
Daily tasks
- Analysis and interpretation of CIS Benchmarks, with a particular focus on the Microsoft Azure environment,
- Translating security requirements and controls into technical implementation guidelines,
- Analysis of security control sets, criticality assessment, triage, and prioritization,
- Setting action priorities based on risk level, business impact, and remediation feasibility,
- Designing and assessing secure cloud architectures in the Microsoft Azure environment,
- Conducting structured risk assessments in accordance with CIS, NIST, and ISO 27001 frameworks,
- Advising on remediation or risk acceptance decisions along with creating justifications,
- Documenting risks, deviations from requirements, and recommended corrective actions,
- Reviewing and validating designs for compliance with security standards and best practices,
- Collaborating with Security Governance, Compliance, and Audit teams,
- Presenting and justifying risk-related decisions to technical and business teams.
Requirements
Min. 5 years of experience in the field of cloud security architecture, Practical experience in Microsoft Azure cloud security, Very good knowledge of CIS Controls and CIS Benchmarks, especially in the context of Microsoft Azure, Good knowledge of at least one of the following standards: NIST, ISO 27001, or CIS, Experience in designing secure cloud architectures and conducting risk assessments, Practical experience in analyzing, assessing, and prioritizing security controls, Experience in recommending decisions regarding remediation or risk acceptance, Ability to assess designs in terms of security and compliance requirements, Experience collaborating with Security Governance, Compliance, and Audit teams, Outstanding communication and interpersonal skills, Independence in decision-making and task prioritization under a high volume of requirements, English language proficiency at a minimum of C1 level.
Nice to have:
- Possession of security certifications, e.g., AZ-500, CISSP, CISM, or certifications related to CIS,
- Experience working in complex enterprise-class environments,
- Experience in automating compliance processes, security assessment, or cloud security.
Must have: Azure