Senior Cybersecurity Architect

Il y a 13 heures

Luxembourg Indra Group Télétravail Temps plein
Senior Cybersecurity Architect / Secure Automation Technical Lead

Location:
Remote, with occasional planned travel to Luxembourg Eligibility: EU citizenship required Environment: European institutions | Fully on-premises platform Role: Hands-on technical lead, overseeing 2–3 software engineers

About the role
We are looking for a Senior Cybersecurity Architect to lead the design and implementation of a secure macro and malware validation platform within Ecosystems B2B. You will combine cybersecurity expertise, software engineering and technical leadership to turn analysis tools into a reliable, auditable security service. The platform will bring together static inspection, policy-based detection, antimalware scanning and controlled sandbox investigations to support risk-based decisions. This is a hands-on role involving architecture, development, integration and close collaboration with cybersecurity, infrastructure and client stakeholders. Your responsibilities
• Own the technical architecture and translate security requirements into practical components and interfaces.
• Lead and mentor a team of 2–3 software engineers, providing implementation guidance and code-quality oversight.
• Integrate analysis engines with Ecosystems B2B through secure APIs and asynchronous workflows.
• Define a common evidence model, risk scoring, analysis confidence, blocking rules and manual-review criteria.
• Establish the lifecycle for YARA rules, including testing, approval, versioning, deployment and rollback.
• Lead proof-of-concept activities, technical validation, performance testing and production-readiness assessments.
• Ensure traceability, auditability, monitoring, error handling and resource isolation across the platform.
• Work directly with European Parliament stakeholders and internal delivery teams. What we are looking for
• Approximately 8+ years of experience in cybersecurity architecture, security engineering, malware analysis or security automation.
• Demonstrated experience delivering security platforms or integrating multiple security engines.
• Strong knowledge of malware analysis, threat detection and secure software architecture.
• Understanding of Office malware techniques, including VBA, Excel 4.0 macros, DDE, OLE objects and obfuscation.
• Strong hands-on Python development skills, with experience in REST APIs, queues and asynchronous processing.
• Experience with Linux, containers, Git, automated testing and CI/CD.
• Ability to design performance, timeout, concurrency and resource-isolation controls.
• Proven technical leadership and the ability to translate architecture into a prioritised implementation backlog.
• Clear communication skills, including the ability to explain technical decisions, risks and limitations to non-specialist stakeholders. Relevant technologies The technology scope includes oletools, YARA, ClamAV, ViperMonkey and CAPE Sandbox, alongside Python, Linux, REST APIs and container technologies. Hands-on experience with several of these tools—or credible alternatives—is expected. You should also be comfortable evaluating and integrating unfamiliar technologies. Nice to have
• Experience in European institutions, government, defence, banking or other regulated environments.
• DFIR, threat research or malware-analysis experience.
• Sandbox deployment and operation, including CAPE or Cuckoo-based environments.
• Kubernetes, risk-scoring engines, PKI, code signing or HSM integration.
• Relevant certifications such as CISSP, OSCP, GREM or GCFA, or equivalent practical experience. Interested? Apply with your CV, highlighting your experience in malware analysis, security automation and hands-on technical leadership.