Description
Job Summary:
The Digital Security Architect integrates security practices into the software development lifecycle, collaborating with teams to design secure solutions and ensure compliance with standards.
Key Highlights:
1. Lead Threat Modeling sessions
2. Promote automation to enhance security
3. Act as a technical reference and advisor
Would you like to help us achieve our purpose of connecting more people, improve their lives and develop our communities? If so, Tigo is for you!
We believe in innovation, we adapt and are agents of change. Our customers are at the center of everything we do.
Come and grow with our team, where together we will transform lives and communities. Additionally, you will have the opportunity to participate in challenging projects and bring your innovative ideas.
This is your opportunity, come and be part of Sangre Tigo!
**Apply right now!**
Digital Security Architect
**Purpose**
* The Digital Security Architect is responsible for integrating security practices cross-functionally across the entire software development lifecycle (S-SDLC). Their mission is to empower development cells and technical teams to identify risks early, design secure solutions from inception, and ensure security is incorporated seamlessly without friction or impact on delivery speed.
* Acts as a technical reference and strategic partner to solution architects, DevOps teams, and technology leaders, ensuring digital products meet the highest security standards.
**Position Location:**
This position is not limited to a specific country. The selected candidate may be hired in **any country where Millicom operates or maintains corporate presence**, based on business needs and candidate profile. In case the selected candidate is a foreign national relative to the hiring country, they must **possess all valid immigration and legal documentation** permitting formal employment in that country, or fulfill the necessary requirements for its acquisition under applicable local laws.
**Responsibilities**
* Secure Architecture and Design
* Review architectures, designs, and technical solutions from a security perspective.
* Lead and facilitate Threat Modeling sessions to identify threats and propose mitigations.
* Define secure architecture patterns and reference guidelines.
* Secure Software Development Lifecycle (S-SDLC)
* Design, implement, and maintain the corporate S-SDLC framework.
* Participate in the evolution of secure development standards, practices, and policies.
* Integrate security requirements across all phases: design, development, testing, and deployment.
* DevOps Integration and Automation
* Collaborate with DevOps teams to integrate automated controls into CI/CD pipelines (SAST, SCA, Secrets Management, etc.).
* Promote automation as a mechanism to enhance security without affecting speed.
* Risk and Vulnerability Management
* Manage the vulnerability lifecycle across applications and digital solutions.
* Coordinate, manage, and lead penetration testing programs (internal or third-party).
* Define, monitor, and report risk, compliance, and continuous improvement metrics.
* Technical Leadership and Strategic Alignment
* Act as a technical reference and advisor for architects, tech leads, and development teams.
* Promote adoption of modern security practices and support strategic decision-making.
* Facilitate communication between technical and business units to ensure aligned vision.
**Requirements**
**Education**
* Bachelor’s degree in Computer Science, Systems Engineering, Cybersecurity, or related technical field.
**Experience**
* +5 years of experience in software architecture, secure development, or similar technical roles.
* +5 years of prior experience working in agile environments, CI/CD, and DevSecOps (ideal).
**Technical Knowledge**
* Proficiency in information security practices, standards, and frameworks.
* Strong understanding of application, API, infrastructure, and network security.
* Knowledge of SAST, SCA, DAST, IAM, vulnerability management, and application protection tools.
* Ideal: CSSLP certification (Certified Secure Software Lifecycle Professional).
**Key Competencies**
* Passion for digital products and building secure solutions.
* Excellent technical communication and presentation skills.
* Ability to work with remote and multidisciplinary teams.
* Skill to influence, build relationships, and gain credibility quickly.
* Analytical orientation, critical thinking, and problem-solving focus.
* Collaborative work in local and global environments.
* Fluent command of Spanish and English.
At Tigo we want to have the best, for this reason we look for qualified professionals who work to continue achieving our purpose of continuing to connect more and more Colombians. In our Company, our people are the soul of our company, who give their best and work with the premise that our clients are the center of everything we do. In addition, we are characterized because we are agile and disciplined, we work together for a purpose, we are drivers of change, we make a difference with the way we work and no matter what happens, our actions are guided by our integrity. At Tigo we make things happen the right way, always innovating in each of our actions and challenging the status quo. We are consistent and deliver results! If you want to be part of this great team, share your profile with us and find out about the available offers!
*Millicom | Tigo is proud to be an Equal Employment Opportunity employer committed to a diverse workforce and nondiscrimination policy in all aspects of employment. We provide equal opportunity and access for all persons, without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, status as a disabled veteran or other protected veteran, or any other protected characteristic, in all phases of the employment process and in compliance with applicable federal, state, and local laws and regulations.*