IT/OT Security Architect
Posted 1ds ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
IT/OT Security Architect designing secure IT, OT, cloud, and AI architectures for Berlin-based cybersecurity consultancy APT-ONE. Translating regulatory requirements into controls and advising CISOs and technical leaders.
Responsibilities:
- Design and further develop security architectures across IT, OT, cloud, and AI systems
- Design secure cloud and hybrid architectures using Azure, AWS, and GCP, including landing zones, identity and network design, encryption, and security baselines
- Create target architectures, security roadmaps, and migration paths for cloud transformations and multi-cloud environments
- Conduct threat modeling, architecture reviews, and risk analyses
- Design network and perimeter security, including segmentation, firewalling, and Zero Trust Network Access
- Develop IAM and PAM architectures as well as cryptography and PKI concepts
- Assess and secure cloud platform services, container/Kubernetes environments, and CI/CD pipelines (DevSecOps)
- Define security requirements for projects, products, cloud providers, and service providers
- Translate regulatory requirements into technical specifications and auditable controls
- Provide expert advice to CISOs, cloud teams, architecture boards, and technical decision-makers
- Create security concepts, policies, and technical documentation
- Use AI-assisted tools for discovery, architecture reviews, and documentation, including expert validation and approval
Requirements:
- Confidently use AI tools in day-to-day consulting, including critically evaluating their results
- Strong awareness of confidentiality when using AI; knowledge of permitted data use and risks such as data leakage, model training, and prompt injection
- Willingness to continuously develop processes and products using AI
- At least 3–5 years of experience in IT/cybersecurity, including several years in architecture or consulting roles
- Broad understanding of networking, endpoints, identity, applications, and cloud technologies
- Experience with Zero Trust and segmentation concepts as well as IAM/PAM (Entra ID, Active Directory)
- Proficiency in ISO 27001, BSI IT-Grundschutz, NIST CSF, MITRE ATT&CK, and SABSA/TOGAF
- Knowledge of cryptography, PKI, and secure application design
- Business-fluent German and English
- Highly desirable: cloud architecture expertise, prompt engineering, AI agents or LLM integration, AI governance, and experience in regulated environments
- Certifications (nice to have): CCSP, CCSK, Microsoft SC-100, Azure AZ-305, AWS Solutions Architect Professional, AWS Security Specialty, Google Professional Cloud Architect, Google Professional Cloud Security Engineer, CISSP, CISSP-ISSAP, SABSA SCF, TOGAF, CISM, OSCP
Benefits:
- Base salary starting at €80,000 plus profit sharing of up to €70,000
- Flexible working hours
- Remote work
- 30 days of annual leave
- IT equipment, such as an Apple MacBook
- Regular team events
- Company pension plan and health insurance
- Shopping and employee discounts



















