Sr. AWS Security Architect (CISO)

Sr. AWS Security Architect (CISO)

provinceProvince Brussels
locationMarkerIconRegion Brussels
briefcaseIconPermanent Contract
senorityIcon
positionIcon1 open position
provinceProvince BrusselslocationMarkerIconBrusselsbriefcaseIconPermanent ContractsenorityIcon5+ years of experiencepositionIcon1 open position

 

Who Are you?

You are a battle-tested Cloud Security Architect with 15+ years of experience securing critical infrastructure. At bnode, you'll lead the security-by-design agenda across AWS, Azure, and hybrid workloads, embedding controls into every layer - from Terraform modules to Zero Trust access patterns. You won't just advise. You'll architect, review code, and steer execution across the cloud lifecycle with platform, SOC, and architecture teams. Regulatory readiness (NIS2), enterprise resilience, and secure cloud automation - this is your domain.

 

What will you do?

Key Responsibilities

Cloud Security Architecture & Design

  • Lead design and enforcement of secure architectures for AWS and Azure (multi-account, multi-subscription).
  • Define and maintain end-to-end security blueprints: identity, network, encryption, logging, container runtime, secrets, WAF.
  • Build reusable Terraform and StackGuardian components with embedded security controls (e.g., KMS, private endpoints, logging).
  • Validate workload isolation (hub/spoke, VNET/NSG/NACL) and implement advanced network segmentation with Azure Firewall, AWS TGW, NAT Gateway, and PrivateLink.

Security-as-Code & DevSecOps

  • Enforce policy-as-code for AWS & Azure.
  • Integrate security controls into CI/CD pipelines (Azure DevOps, GitHub Actions) and runtime checks (Defender for Cloud, AWS Config).
  • Drive shift-left security: IaC scanning (Checkov, tfsec), container scanning (Trivy, ECR/ACR policies), and workload attestation.
  • Architect secure patterns for Kubernetes (AKS/EKS) with RBAC, Pod Security Policies, egress lockdown, and image signing.

Governance, Compliance & Risk

  • Translate regulatory requirements (NIS2, ISO 27001, PCI DSS, DORA) into actionable cloud controls.
  • Design and implement continuous compliance frameworks across cloud estates.
  • Lead security architecture reviews, threat models, and risk assessments for new digital and modernization programs.

Advisory, Incident Support & Operational Maturity

  • Act as senior escalation for cloud-related incidents; contribute to forensics and root cause analysis.
  • Coach teams on secure architecture standards and support the SOC in tuning detections for cloud-native threats (MITRE ATT&CK for Cloud).
  • Contribute to hardening playbooks, vulnerability remediation guides, and incident runbooks.

 

Required Experience

  • 15+ years in IT/security, with 10+ years in cloud security architecture roles.
  • Deep expertise in AWS and Azure security services (IAM, KMS, VPC/NSG/Security Groups, Defender, Security Hub, Sentinel, etc.).
  • Hands-on with Terraform,  StackGuardian container security, and policy automation.
  • Demonstrated delivery of security frameworks at enterprise scale in regulated industries (finance, logistics, public sector).

 

Certifications (Required/Preferred)

  • Required (at least 2):
    • AWS Certified Security – Specialty
    • Microsoft Certified: Azure Security Engineer Associate (AZ-500)
    • CISSP or CCSP
  • Preferred: TOGAF, SABSA, GIAC Cloud Security Certifications (GCLD, GCSA)

 

What do we offer? 

Like a long-awaited parcel, we want to make you feel welcome and valued. Our offer includes:  

·        Competitive monthly salary 

·        Meal vouchers 

·        Hospitalization-, group- and disability insurances 

·        A phone subscription and company car 

·        20 days of statutory leave and 7 additional extralegal days off  

·        An end-of-year and performance-based bonus and double holiday pay  

·        Many benefits from more than 100 bpost-partners 

 

#LI-BP6

 

 

 

Waarom bpost?

This is how we make sure that you are happy to come to work with us every day:

euro
An interesting package

With a fair salary, of course. Topped off with interesting extra fringe benefits, such as meal vouchers, extra holidays and additional allowances.

cardiology
Work life balance

Your well-being is our priority, so your job should fit into your life: with a job close to home, or a flexible office job. 

school
Job security and growth opportunities

With over 500 different jobs, we gladly offer you growth opportunities. This way, you are assured of your job, and your future.

customer loyality
Equal opportunities for everyone

bpost is diverse, and we are proud of that. It is our strength together with our respect and trust for each other.

At bpost, we really have the ambition to help people grow. You can feel the human values, without losing touch with reality. I also notice this pragmatism, with a human touch, in my colleagues; each and every one of them is capable and exceptionally professional. Besides technical knowledge, mutual support is the key word across all departments.

Elodie

Product Owner

Read more 
Elodie