Senior Cloud and Security Architect
π Job Overview
- Job Title: Senior Cloud and Security Architect
- Company: Boeing
- Location: Gothenburg, VΓ€stra GΓΆtaland, Sweden
- Job Type: Hybrid (3 days on-site)
- Category: Cloud Security Architecture
- Date Posted: June 13, 2025
- Experience Level: 10+ years
- Remote Status: On-site (3 days a week)
π Role Summary
- Lead the definition and implementation of secure architecture and coding best practices for cloud native, customer-facing software solutions.
- Drive best-in-class software security practices into the Application Engineering organization in support of DAS modernization efforts.
- Collaborate with teams to ensure architecture conforms to security requirements and assess security impact of architectural decisions.
- Work across software engineering teams and architects for end-to-end alignment, process improvements, and future designs.
π Enhancement Note: This role requires a strong technical background in cloud and application security, with experience in leading security architecture and driving security best practices across teams.
π» Primary Responsibilities
- Develop and lead implementation of security architecture and secure coding standards for DAS software solutions.
- Contribute to the definition of overall DAS architecture security principles, guidelines, patterns, training, and standards.
- Drive adoption of DevSecOps practices into the software engineering organization by working directly with teams on implementation.
- Perform security tool evaluations and make recommendations for adoption.
- Assess security impact of architectural decisions to product lifecycle.
- Lead the identification of design constraints and ensure architecture conforms to security requirements.
- Work with customers to understand their security requirements and ensure compliance with Boeing Information Security requirements.
- Collaborate with cloud service providers, Boeing InfoSec, and Boeing Enterprise External Cloud teams to architect best-of-breed application security solutions across multiple clouds.
- Review internal and vendor artifacts for security architecture compliance.
π Enhancement Note: This role involves a high level of technical leadership, requiring strong analytical skills, teamwork, and excellent communication skills to communicate effectively with technical personnel, business leaders, and customers.
π Skills & Qualifications
Education: Bachelor's degree or higher in a related field.
Experience: 10+ years of IT implementation experience, with 5+ years in IT security, compliance, and risk management.
Required Skills:
- Strong technical expertise in Security Architecture, automation, integration, and deployment (DevSecOps).
- Proven experience leading a globally distributed team.
- Proven experience researching, advising, comparing, and recommending technology solutions.
- Proven ability to deliver application and infrastructure security solutions in a multi-cloud environment.
- DFARS/FedRAMP/ITAR, NIST Cybersecurity Framework, ISO 27001, Security Development Lifecycle, AWS/Azure/GCP Security services, Cloud Security monitoring process, Certificate Management, Threat modeling, Dynamic and Static Application Security Testing (DAST & SAST), Software Composition Analysis.
Preferred Skills:
- Experience with software engineering teams and architects for end-to-end alignment, process improvements, and future designs.
π Enhancement Note: This role requires a broad cloud and application security background, with experience in leading the definition and implementation of secure architecture and coding best practices for cloud native, customer-facing software solutions.
π Web Portfolio & Project Requirements
Portfolio Essentials:
- Demonstrate strong technical expertise in Security Architecture, automation, integration, and deployment (DevSecOps).
- Showcase experience leading a globally distributed team and driving best-in-class software security practices.
- Highlight projects that showcase security tool evaluations, recommendations for adoption, and security impact assessments.
- Include examples of collaboration with cloud service providers, Boeing InfoSec, and Boeing Enterprise External Cloud teams to architect best-of-breed application security solutions across multiple clouds.
Technical Documentation:
- Provide documentation showcasing security architecture and coding standards for software solutions.
- Include examples of security principles, guidelines, patterns, training, and standards.
- Demonstrate understanding of DFARS/FedRAMP/ITAR, NIST Cybersecurity Framework, ISO 27001, Security Development Lifecycle, AWS/Azure/GCP Security services, Cloud Security monitoring process, Certificate Management, Threat modeling, Dynamic and Static Application Security Testing (DAST & SAST), and Software Composition Analysis.
π Enhancement Note: This role requires a strong portfolio demonstrating a broad cloud and application security background, with experience in leading the definition and implementation of secure architecture and coding best practices for cloud native, customer-facing software solutions.
π΅ Compensation & Benefits
Salary Range: The salary range for this role is not provided. However, based on market research, the average salary for a Senior Cloud and Security Architect in Sweden is approximately 800,000 - 1,200,000 SEK per year.
Benefits:
- Not specified.
Working Hours: 40 hours per week, with 3 days on-site in Gothenburg.
π Enhancement Note: The salary range is estimated based on market research for a Senior Cloud and Security Architect role in Sweden. Benefits are not specified and should be discussed with the hiring organization.
π― Team & Company Context
Company Culture:
- Boeing is a large, multinational corporation with a strong focus on innovation and technology.
- The company's culture values collaboration, continuous learning, and a commitment to safety and quality.
Team Structure:
- The team consists of software engineering teams and architects, with a focus on application engineering and digital aviation solutions.
- The team works closely with business leaders and customers to ensure security requirements are met and best-in-class software security practices are implemented.
Development Methodology:
- The team follows Agile methodologies, with a focus on collaboration, continuous improvement, and customer value.
- The team uses version control, automated deployment, and CI/CD pipelines to ensure efficient and secure software development.
Company Website: www.boeing.com
π Enhancement Note: Boeing's culture values collaboration and continuous learning, with a strong focus on innovation and technology. The team follows Agile methodologies and uses version control, automated deployment, and CI/CD pipelines to ensure efficient and secure software development.
π Career & Growth Analysis
Web Technology Career Level: This role is a senior-level position, requiring a high level of technical expertise and leadership in cloud and application security.
Reporting Structure: The role reports directly to the Boeing Digital Aviation Solutions organization and works closely with software engineering teams, architects, business leaders, and customers.
Technical Impact: The role has a significant impact on the security of Boeing's digital aviation solutions, ensuring that software solutions are secure, compliant, and meet customer requirements.
Growth Opportunities:
- Opportunities for career progression within the Boeing Digital Aviation Solutions organization.
- Opportunities to work on cutting-edge technology and collaborate with a diverse, global team.
- Opportunities to develop leadership skills and drive best-in-class software security practices across the organization.
π Enhancement Note: This role offers significant opportunities for career progression and technical growth within the Boeing Digital Aviation Solutions organization.
π Work Environment
Office Type: The office is a hybrid environment, with employees working on-site 3 days a week and remotely for the remaining days.
Office Location(s): Gothenburg, Sweden.
Workspace Context:
- The workspace is designed to facilitate collaboration and communication between team members, business leaders, and customers.
- The workspace includes multiple monitors, testing devices, and development tools to support efficient and secure software development.
- The workspace encourages knowledge sharing, technical mentoring, and continuous learning.
Work Schedule: The work schedule is 40 hours per week, with 3 days on-site in Gothenburg.
π Enhancement Note: The work environment is a hybrid environment, with a focus on collaboration, communication, and continuous learning. The workspace is designed to support efficient and secure software development, with access to multiple monitors, testing devices, and development tools.
π Application & Technical Interview Process
Interview Process:
- Technical Assessment: A technical assessment to evaluate the candidate's understanding of cloud and application security, security architecture, and secure coding best practices.
- Behavioral Interview: A behavioral interview to assess the candidate's leadership skills, teamwork, and communication skills.
- Final Interview: A final interview with key stakeholders to assess the candidate's fit for the role and the organization.
Portfolio Review Tips:
- Highlight projects that demonstrate strong technical expertise in Security Architecture, automation, integration, and deployment (DevSecOps).
- Showcase experience leading a globally distributed team and driving best-in-class software security practices.
- Include examples of security tool evaluations, recommendations for adoption, and security impact assessments.
- Demonstrate understanding of DFARS/FedRAMP/ITAR, NIST Cybersecurity Framework, ISO 27001, Security Development Lifecycle, AWS/Azure/GCP Security services, Cloud Security monitoring process, Certificate Management, Threat modeling, Dynamic and Static Application Security Testing (DAST & SAST), and Software Composition Analysis.
Technical Challenge Preparation:
- Brush up on cloud and application security fundamentals, with a focus on security architecture and secure coding best practices.
- Familiarize yourself with DFARS/FedRAMP/ITAR, NIST Cybersecurity Framework, ISO 27001, Security Development Lifecycle, AWS/Azure/GCP Security services, Cloud Security monitoring process, Certificate Management, Threat modeling, Dynamic and Static Application Security Testing (DAST & SAST), and Software Composition Analysis.
- Prepare for behavioral interview questions that assess leadership skills, teamwork, and communication skills.
ATS Keywords: [See the comprehensive list of web development and server administration-relevant keywords for resume optimization, organized by category: programming languages, web frameworks, server technologies, databases, tools, methodologies, soft skills, industry terms]
π Enhancement Note: The interview process is designed to assess the candidate's technical expertise in cloud and application security, as well as their leadership skills, teamwork, and communication skills. The portfolio review tips and technical challenge preparation are tailored to the specific requirements of this role.
π Technology Stack & Web Infrastructure
Cloud Platforms:
- AWS, Azure, GCP
Security Tools:
- DFARS/FedRAMP/ITAR, NIST Cybersecurity Framework, ISO 27001, Security Development Lifecycle, AWS/Azure/GCP Security services, Cloud Security monitoring process, Certificate Management, Threat modeling, Dynamic and Static Application Security Testing (DAST & SAST), Software Composition Analysis.
Development & DevOps Tools:
- Version control systems (e.g., Git)
- CI/CD pipelines (e.g., Jenkins, GitLab CI/CD)
- Containerization and orchestration tools (e.g., Docker, Kubernetes)
- Infrastructure as Code (IaC) tools (e.g., Terraform, CloudFormation)
- Monitoring and logging tools (e.g., Prometheus, ELK Stack)
π Enhancement Note: The technology stack for this role is focused on cloud and application security, with a strong emphasis on security tools, development, and DevOps tools.
π₯ Team Culture & Values
Web Development Values:
- Innovation and continuous learning
- Collaboration and teamwork
- Customer focus and user experience
- Quality and excellence
- Safety and security
Collaboration Style:
- The team follows Agile methodologies, with a focus on collaboration, continuous improvement, and customer value.
- The team uses version control, automated deployment, and CI/CD pipelines to ensure efficient and secure software development.
- The team encourages knowledge sharing, technical mentoring, and continuous learning.
π Enhancement Note: Boeing's culture values innovation and continuous learning, with a strong focus on collaboration, teamwork, and customer focus. The team follows Agile methodologies and uses version control, automated deployment, and CI/CD pipelines to ensure efficient and secure software development.
β‘ Challenges & Growth Opportunities
Technical Challenges:
- Staying up-to-date with the latest cloud and application security trends and best practices.
- Balancing security requirements with customer needs and business objectives.
- Ensuring compliance with security standards and regulations, such as DFARS/FedRAMP/ITAR, NIST Cybersecurity Framework, ISO 27001, and Security Development Lifecycle.
Learning & Development Opportunities:
- Opportunities to develop expertise in cloud and application security, with a focus on security architecture and secure coding best practices.
- Opportunities to work on cutting-edge technology and collaborate with a diverse, global team.
- Opportunities to develop leadership skills and drive best-in-class software security practices across the organization.
π Enhancement Note: This role offers significant opportunities for technical growth and development, with a focus on cloud and application security, security architecture, and secure coding best practices.
π‘ Interview Preparation
Technical Questions:
- Cloud and Application Security: Questions that assess the candidate's understanding of cloud and application security, security architecture, and secure coding best practices.
- Security Standards and Regulations: Questions that assess the candidate's understanding of DFARS/FedRAMP/ITAR, NIST Cybersecurity Framework, ISO 27001, and Security Development Lifecycle.
- Security Tools and Technologies: Questions that assess the candidate's understanding of security tools, development, and DevOps tools.
Company & Culture Questions:
- Boeing's Culture: Questions that assess the candidate's understanding of Boeing's culture, values, and work environment.
- Team Dynamics: Questions that assess the candidate's ability to work effectively within a team, collaborate with business leaders and customers, and drive best-in-class software security practices.
Portfolio Presentation Strategy:
- Highlight projects that demonstrate strong technical expertise in Security Architecture, automation, integration, and deployment (DevSecOps).
- Showcase experience leading a globally distributed team and driving best-in-class software security practices.
- Include examples of security tool evaluations, recommendations for adoption, and security impact assessments.
- Demonstrate understanding of DFARS/FedRAMP/ITAR, NIST Cybersecurity Framework, ISO 27001, Security Development Lifecycle, AWS/Azure/GCP Security services, Cloud Security monitoring process, Certificate Management, Threat modeling, Dynamic and Static Application Security Testing (DAST & SAST), and Software Composition Analysis.
π Enhancement Note: The interview preparation is tailored to the specific requirements of this role, with a focus on cloud and application security, security architecture, and secure coding best practices.
π Application Steps
To apply for this Senior Cloud and Security Architect position:
- Prepare Your Portfolio: Highlight projects that demonstrate strong technical expertise in Security Architecture, automation, integration, and deployment (DevSecOps). Include examples of security tool evaluations, recommendations for adoption, and security impact assessments. Ensure your portfolio showcases your understanding of DFARS/FedRAMP/ITAR, NIST Cybersecurity Framework, ISO 27001, Security Development Lifecycle, AWS/Azure/GCP Security services, Cloud Security monitoring process, Certificate Management, Threat modeling, Dynamic and Static Application Security Testing (DAST & SAST), and Software Composition Analysis.
- Tailor Your Resume: Highlight your experience in cloud and application security, security architecture, and secure coding best practices. Include relevant keywords and phrases to optimize your resume for the ATS system.
- Prepare for Technical Interviews: Brush up on cloud and application security fundamentals, with a focus on security architecture and secure coding best practices. Familiarize yourself with DFARS/FedRAMP/ITAR, NIST Cybersecurity Framework, ISO 27001, Security Development Lifecycle, AWS/Azure/GCP Security services, Cloud Security monitoring process, Certificate Management, Threat modeling, Dynamic and Static Application Security Testing (DAST & SAST), and Software Composition Analysis. Prepare for behavioral interview questions that assess your leadership skills, teamwork, and communication skills.
- Research the Company: Familiarize yourself with Boeing's culture, values, and work environment. Understand the team dynamics and how the role fits within the organization.
π Enhancement Note: The application steps are designed to help candidates prepare for the Senior Cloud and Security Architect position, with a focus on cloud and application security, security architecture, and secure coding best practices.
Application Requirements
Candidates must have a bachelor's degree and at least 10 years of IT implementation experience, with 5+ years in IT security and compliance. Strong technical expertise in security architecture and excellent communication skills are essential.