Back to search
Montash Linkedin · Posted yesterday

Lead Security Architect - Cloud Database Platforms

Spain

Linkedin
Continue to application Add your email once, then Caio opens the original posting.

Indexed description

On behalf of our client, a global financial services enterprise running a large-scale, highly regulated cloud data platform - we're looking for a Lead Security Architect to own the security of their Oracle (OCI) and PostgreSQL database landscape.


Why this role is different

Most security architect roles hand you the rules and expect someone else to build the control. Most DBA/security-engineering roles hand you a ticket and expect someone else to have already decided what "secure" means. This role is neither.


You will own the full chain: understand what EU regulation (DORA, BaFin, GDPR, and internal group security standards) actually requires, translate that into concrete architecture for the cloud database estate, and then get hands-on with the implementation yourself. You'll also be the person who sits across the table from auditors and regulators and can explain, in plain language, why the architecture is built the way it is and you'll lead a small squad of engineers who help you deliver it.


Our client is entirely cloud-native, working in Kanban, as a pure delivery team fully decoupled from line management - you organize and prioritize the work.


What you'll own

  • End-to-end secure architecture for Oracle Database on OCI and PostgreSQL: encryption, key management, hardening, and secure-by-design patterns.
  • Zero Trust network security for cloud database environments - private endpoints, segmentation, certificate lifecycle management.
  • Threat modelling that turns into real engineering controls, not slide decks.
  • Identity and access integration with Microsoft Entra ID, OAuth/OIDC, Conditional Access, Privileged Identity Management for database access.
  • Vulnerability management and DevSecOps practices across the platform.
  • Being the primary point of contact for security audits and annual pentests - prepping, guiding, and converting findings into remediation.
  • Leading and mentoring a 3-person security engineering squad - priorities, incidents, stakeholder communication (including customer-facing conversations).
  • Defining the concept and continuous improvement of audit record collection and SIEM integration for database security alerting.
  • A growing mandate: today it's mostly Oracle, but PostgreSQL is expanding fast (especially with an upcoming data lake product), and other providers are on the radar. You'll need to grow the security model with the platform, not just maintain what exists.
  • An open field almost nobody is properly covering yet: security of AI tooling as it gets embedded into the platform. If you want to make this your signature project, there's real room to do it.


What you bring and why we're specific about it


  • Strong, hands-on experience securing Oracle Database (including Advanced Security) - experience with Oracle on OCI is a must, not a nice-to-have.
  • Solid PostgreSQL security experience, and genuine openness to extending into Snowflake and other data platforms.
  • Real OCI security and networking expertise, plus working comfort in Azure - the surrounding tech landscape is mostly Azure-based, so you need to operate across both clouds.
  • Deep, practical knowledge of Microsoft Entra ID and identity-based database access.
  • Working knowledge of security and compliance frameworks such as ISO 27001, SOC 2, GDPR, CIS Benchmarks, and DORA
  • Certificate lifecycle and secrets management experience.
  • Previous experience leading or tech-leading a team, ideally shaped by a DevOps career path, in agile/Kanban environments.
  • Excellent communication skills - you can explain a complex control decision to an engineer and to a non-technical compliance stakeholder in the same afternoon.


If you're this rare mix of architect, hands-on implementer, and regulatory translator and the idea of owning security for a large-scale cloud database platform (with room to shape how AI security gets handled next) excites you, we'd love to hear from you. Apply directly or reach out to [email protected] to learn more.


Free. 20 seconds. No password. See every match in this search.

Create a free Caio profile to unlock more results and save your role and location preferences.

Unlock free search
Want help applying to roles like this? Search Caio for free. If repetitive applications get heavy, Managed Job Search adds supervised execution for $99/month.
View Managed Job Search