AND FOR THIS, WE BELIEVE IT WOULD BE IDEAL IF YOU HAD...
Experience
More than 4 years of experience in infrastructure projects for Public Administrations, Defense, and Interior, as well as in platforms intended for the processing of classified or confidential information, including accreditation requirements, segregation, and secure operation.
Experience in security architectures for Sovereign Cloud environments, including physical and logical isolation, air-gap environments, bastioning of platforms, separation of security domains, and network segmentation.
Experience in certifications and regulatory frameworks.
Knowledge of the Cloud business:
Market situation and main benchmarks (Hyperscalers and European Sovereign Clouds: OVHcloud, Scaleway, StackIT, TCloud, etc.)
As-a-service commercialization models, which allow customers to consume on a pay-per-use basis, reducing investment and accelerating innovation.
Deploy, operate, and evolve technology through automation, reducing operational times and errors.
High-level knowledge of the product and service catalog of Spanish and European competitors.
Technical skills:
High-level knowledge of certifications and regulatory frameworks, including ENS High, CCN-STIC (Limited and Confidential Distribution), Cloud Sovereignty Framework / EUCS-SECS/SEAL, CADA, DORA, NIS2, CRA (Cyber Resilience Act), Data Act, Data Governance Act, CLOUD Act, GDPR, ISO 27001, ISO 27017, ISO 27018, and ISO 27701.
Identity and Access Management (IAM) platforms, including Keycloak, LDAP, Active Directory, OpenID Connect (OIDC), OAuth2, SAML, Identity Federation, Multi-Factor Authentication (MFA), and Privileged Access Management (PAM).
Cloud security platforms, including certificate lifecycle management (PKI), encryption in transit and at rest, key management (KMS), Hardware Security Modules (HSM), secrets management (HashiCorp Vault or similar), and automatic credential rotation.
Knowledge of Zero Trust architectures, including continuous authentication, micro-segmentation, identity-based access control, least privilege policies, and conditional access.
Knowledge of Confidential Computing technologies, Trusted Execution Environments (TEE), Secure Boot, TPM, and attestation mechanisms for sensitive workloads.
Knowledge of integration with SIEM, SOAR, and SOC, including auditing, traceability, and incident response capabilities.
Knowledge of Kubernetes and container security, including admission policies, Pod Security Standards, Network Policies, secure image management, artifact signing and verification (Sigstore/Cosign), vulnerability scanning, and runtime protection.
Knowledge of software supply chain security, including SBOM, SLSA, artifact signing, secure repositories, and dependency validation.
Knowledge of the CNCF and OpenInfra Foundation ecosystem, as well as the main open source technologies used to build sovereign clouds, with special attention to their security, resilience, and regulatory compliance capabilities.
Cloud Native architectures based on microservices, containers, Kubernetes, Service Mesh (Istio, Linkerd), and GitOps (ArgoCD, FluxCD).
Enterprise capabilities of a PaaS platform, including multi-tenancy, RBAC, high availability, horizontal scalability, disaster recovery, backup/restore, auditing, observability, regulatory compliance, and Day-2 operations automation.
Observability services for monitoring, logging, and tracing (Prometheus, Grafana, OpenSearch, Loki, Jaeger, OpenTelemetry).
AIOps (Prometheus, Grafana, OpenTelemetry, ELK/OpenSearch, etc.)