Azure Platform & Security Architect (Madrid)

Azure Platform & Security Architect (Madrid)

22 sep
|
Avanade Spain
|
Madrid

22 sep

Avanade Spain

Madrid

At Roche you can show up as yourself, embraced for the unique qualities you bring. Our culture encourages personal expression, open dialogue, and genuine connections, where you are valued, accepted and respected for who you are, allowing you to thrive both personally and professionally. This is how we aim to prevent, stop and cure diseases and ensure everyone has access to healthcare today and for generations to come. Join Roche, where every voice matters.

Key Responsibilities

- Strategic Representation: Act as the primary cyber security and digital liaison between manufacturing site operations and global PTE teams.
- Architecture & Advisory: Design, define, and enable future manufacturing needs through expert consulting on technologies such as IIoT, Open Source, Unified Namespace (UNS), Asset Administration Shell (AAS), and cloud-based manufacturing systems.
- Site Compliance & Governance: Ensure site-level adherence to corporate cyber security standards, policies, risk frameworks, and regulatory requirements.
- Controls & Infrastructure: Support the implementation and continuous monitoring of cyber security controls across manufacturing equipment, automation systems, and digital infrastructure.
- Bridge & Translation: Adapt global PT and IT cyber security strategies to fit operational realities at the local site level.
- Culture & Empowerment: Facilitate communication, training, and capability building on cyber security practices for cross-functional site teams.
- Incident Response & Resilience: Coordinate site-level incident responses, managing escalations to global teams when required.
- Cross-Functional Collaboration: Partner with IT, Engineering, Quality, and Manufacturing teams to embed security into digital initiatives (e.g., Industry 4.0, IoT, MES).

Qualifications & Skills

- Education: Bachelor's degree in Engineering, Computer Science, Cyber Security, or a related field (Master's preferred), or equivalent practical experience.
- Industry Experience: Proven experience (typically 3-5+ years) in pharmaceutical, biotech, or regulated manufacturing environments.
- Technical Knowledge: Deep understanding of cyber security frameworks, compliance standards, GxP regulations, Purdue Model, OT architectural design, Enterprise Service Bus, and UNS implementations.
- Systems Familiarity: Working knowledge of manufacturing systems and digital technologies (e.g., SCADA, DCS, MES, IIoT).
- Leadership & Collaboration: Demonstrated ability to translate global requirements into practical site action, build trust across global/local teams, and manage diverse stakeholders effectively.
- Problem-Solving & Governance: Experience in risk assessment, KPI governance, audit preparation, and technical documentation.
- Certifications (Bonus): Relevant certifications such as CISSP, CISM, ISA/IEC 62443, GICSP, or SANS ICS are considered a strong asset.

Job Responsibilities

- + Content Leadership: Treats platform services as internal products with clear documentation, lifecycle management, and stakeholder feedback loops. Designs and documents components of shared technology platforms (e.g., CI/CD, observability, DLP policies) while creating proof of concepts, reference implementations, automation scripts, and platform tooling. Closely follows Microsoft's Power Platform roadmap and general developments in the low-code, no-code and AI space to identify opportunities and challenges within Roche.
- + Accountability/Problem Solving: Takes ownership of ambiguous tasks and topics in the "grey zone" and successfully drives small to medium (S/M) initiatives at the platform level. These initiatives may include the implementation of platform level initiatives, such as the deployment of the Center of Excellence (CoE) Starter Kit or other automations to support platform administrations. Challenges the status quo, skillfully navigates group dynamics, and fosters good collaboration, knowledge sharing, coaching, and mentoring.
- + Stakeholder Management: Prioritizes and communicates with stakeholders effectively. Leads the platform team to ensure that platform is fit for use, socializes the platform to prospective internal customers, and represents the platform within architect communities. Maintains a bigger picture view informed by Microsoft's roadmap and general low‑code, no‑code, and AI trends. Understands how various platform components fit into the overall organizational strategy and goals.
- + Impact/Strategy: Acts as a technical mentor and aligns development plans with the integral strategy. Gives speeches and shares knowledge in internal events (e.g., DevOps Days, Tech Talk, Tech Live)



and gets involved in initiatives or tasks reaching outside of the regular project scope.
- + Complexity: Operates at the platform level with a direct impact on the platform team’s technical decisions and an indirect impact on the decisions of citizen developers, professional developers, and business use case owners. Records decisions in architecture decision records and other formal documentation.
- + Business / Technical ability: Possesses a deep understanding of the broader technical landscape beyond the specific component being worked on. Formulates and implements technical strategies aligned with organizational objectives, investing time and energy in initiatives that boost automation and innovation while maintaining the highest engineering quality.

Education / Experience

- Demonstrated experience designing, developing, and managing Power Platform at a global enterprise scale.
- Proven track record of treating platform services as internal products, actively contributing to their lifecycle, governance framework, and operational stability.
- Experience evaluating and integrating third-party or cloud-native services while aligning solutions with strict security and architectural standards.
- Experience in Zero Trust principles within the Power Platform, such as leveraging Microsoft Entra ID Conditional Access and Managed Environments to secure data and governance.
- Bachelor's degree in Engineering, Computer Science, or equivalent experience.

Technical Skills

- In‑depth knowledge of Power Apps (Canvas/Model‑driven), Power Automate, Power BI, Power Pages, and Copilot Studio.
- Proficiency in Terraform, Power Platform Build Tools for Azure DevOps or GitHub Actions, and automation scripting via PowerShell for Power Platform.
- Solid foundational knowledge of Entra ID (Azure AD), Dataverse architecture, and API management.
- Strong expertise in platform security (DLP, encryption, access controls), networking (on‑premises data gateways), and performance monitoring/observability tools.

Additional Qualifications

- Strong collaborative and mentorship skills, with an ability to navigate complex group dynamics and act as a technical mentor to peers.
- Experience in a regulated industry.
- Experience leading or supporting a community of practice.

Job Responsibilities

- + Risk Assessment: Support comprehensive security risk assessments and audits using frameworks like NIST CSF and ISO 27001 to identify vulnerabilities in systems, cloud services, and emerging technologies.
- + Third‑Party Cyber Risk Management: Execute security, privacy and quality evaluations of global vendors, focusing on supply chain integrity, data sovereignty, and breach notification capabilities. Follow up with the vendors on open finding and their remediation status.
- + Audit Assurance: Support internal and external security audits and provide guidance on remediation findings.
- + Continuous Compliance Monitoring: Design and implement automated tools to monitor the effectiveness of security controls in real‑time, moving the organization toward data‑driven monitoring. Monitor security compliance on critical systems and vendors.
- + OT & Manufacturing Protection: Support the evaluation of the security posture of Manufacturing and Operational Technology (OT) environments to ensure high availability and protection against industrial cyber threats.

Education / Experience

- University Degree: Bachelor's degree in Cybersecurity, Computer Science, or a related technical field (Master's preferred).
- Professional Experience: 3+ years in a dedicated Security Risk or Audit or Compliance role within a global enterprise, specifically handling Hybrid‑Cloud and OT/IoT environments.
- Certifications: Active CISSP, CISM or CISA is highly preferred; CRISC, or ISO 27001 Lead Auditor certifications are a significant plus.

Technical Skills

- Knowledge of security standards (ISO 27001, NIST CSF), data protection and privacy regulations such as GDPR or HIPAA.
- Familiar with health authority regulations, systems financial controls, software development lifecycle, computer systems validation, infrastructure qualification, and ITIL processes.
- Audit & Control Automation: Experience in translating manual security controls into automated,



data‑driven monitoring requirements (Continuous Controls Monitoring, ITGC).
- Analytical & Project Management: Strong ability to support complex assessments and drive the optimization of risk monitoring tools.

Additional Qualifications

- Strong communication and relationship‑building skills to manage stakeholder expectations, facilitate meetings, and act as an independent communicator.
- A continuous improvement mindset with the capability to apply analytical and logical reasoning to challenge assumptions and identify discrepancies.

Key Responsibilities

- Service Ownership & Strategy: Drive the end‑to‑end lifecycle of our Security Log Management (Splunk & Cribl) and Security Scanning (Tenable) platforms.
- Service Reliability: Ensure the high availability and performance of our security services globally, acting as an escalation point for complex technical challenges.
- System Interconnectivity: Develop and manage sophisticated API integrations to ensure seamless data flow between the security scanning (Tenable) and logging (Splunk/Cribl) tiers.
- Next‑Gen Security Log Architecture: Drive the transition from a traditional "index‑all" logging approach to a "data‑tiering" mindset. You will focus on cost optimization and performance across all data lifecycle phases: routing, filtering, storing and searching, ensuring security data is accessible and cost‑effective.
- Infrastructure as Code (IaC): Orchestrate the evolution of our security infrastructure by managing all configurations via CI/CD pipelines (GitHub, Ansible, and Python), to ensure a fully automated and version‑controlled environment.
- AI‑Augmented Engineering: Actively integrate AI Agents and MCP (Model Context Protocol) servers into daily operations. You will build agentic AI workflows to automate configuration, troubleshooting, and complex interconnectivity, while simultaneously improving service offerings and user experience.
- Mentorship: Act as a technical catalyst for the team, mentoring colleagues in the art of prompt engineering, agentic AI development, and advanced AI ecosystems.
- Technical Leadership: Serve as a technical lead, defining implementation plans and driving continuous process improvements.
- Stakeholder Engagement: Effectively manage relationships across functional teams, acting as a clear communicator and advisor to ensure alignment on security goals and project delivery.

Technical Requirements & Expertise

- Security Service Depth: Deep conceptual understanding of the SIEM/Log Management lifecycle (Collection, Indexing, Storage, Retention and Searching) and Vulnerability Management.
- Networking Fundamentals: Expert understanding of networking (TCP/IP, Load Balancing, Firewalls) as it relates to high‑volume security data transport.
- Coding & API Mastery: Strong experience with Python and interacting with complex REST APIs. Proven ability to interconnect disparate technologies via APIs and custom integrations.
- Modern DevOps: Strong experience with Ansible and GitHub for managing infrastructure.
- Advanced AI/Automation: Proven experience or deep project work building Agentic AI workflows. Practical expertise in MCP (Model Context Protocol) or building custom LLM‑based tools to automate technical tasks.
- Tooling (Preferred): Experience with Cribl, Splunk, or Tenable is a plus, but the ability to rapidly upscale and automate these via AI is essential.

Job Responsibilities

- Service Ownership & Strategy: Drive the end‑to‑end lifecycle of our Security Log Management (Splunk & Cribl) and Security Scanning (Tenable) platforms.
- Service Reliability: Ensure the high availability and performance of our security services globally, acting as an escalation point for complex technical challenges.
- System Interconnectivity: Develop and manage sophisticated API integrations to ensure seamless data flow between the security scanning (Tenable) and logging (Splunk/Cribl) tiers.
- Next‑Gen Security Log Architecture: Drive the transition from a traditional "index‑all" logging approach to a "data‑tiering" mindset. You will focus on cost optimization and performance across all data lifecycle phases: routing, filtering, storing and searching, ensuring security data is accessible and cost‑effective.

We want to keep all other sections such as company culture statements, equal opportunity statements, and location/benefit lines unchanged and formatted within the rules above. All other company-specific details, benefits, and the remaining administrative text have been omitted as they were identified as remove‑list artifacts.

#J-18808-Ljbffr

📌 Azure Platform & Security Architect (Madrid)
🏢 Avanade Spain
📍 Madrid

Postulate a este anuncio

Muestra tus habilidades a la empresa, rellenar el formulario y deja un toque personal en la carta, ayudará el reclutador en la elección del candidato.

Suscribete a esta alerta:

Recibe por email las nuevas ofertas de trabajo para: azure platform & security architect (madrid) / madrid

Suscribete a esta alerta:

Recibe por email las nuevas ofertas de trabajo para: azure platform & security architect (madrid) / madrid