Title: Security Architect
Lisbon, PT
At Chain IQ, your ideas move fast.
Chain IQ is a global AI-driven Procurement Service Partner, headquartered in Baar, Switzerland, with operations across main centers and 16 offices worldwide. We provide tailored, end-to-end procurement solutions that enable transformation, drive scalability, and deliver substantial reductions in our clients' indirect spend. Our culture is built on innovation, entrepreneurship, ownership, and impact. Here, your voice matters - bold thinking is encouraged, and action follows ambition.
Role Purpose
We are building an AI-native technology platform where software, data, workflows and autonomous agents increasingly operate as one system. This role defines the technical security architecture across agent-supported software delivery, autonomous systems, data and knowledge platforms, and the wider cloud technology estate.
You will shape how identity, authority, trust, policy, isolation, provenance and control are applied so that automation can scale safely. Working closely with security leadership and engineering teams, you will turn security requirements and emerging risks into practical, reusable platform patterns.
Responsibilities
-
Define the security architecture for agent-supported software development and delivery, including generated code, automated testing, build processes, infrastructure changes, deployment and operational actions.
-
Design the trust and control architecture for autonomous agents, orchestration platforms and AI-enabled workflows, including identity, delegated authority, tool access, credential use and policy enforcement.
-
Establish security patterns for autonomous execution, defining where actions can run independently and where deterministic validation, additional authorization or human approval is required.
-
Design security controls for data and knowledge platforms, including knowledge graphs, retrieval systems, derived information, provenance, context assembly, tenant boundaries and access enforcement.
-
Define identity and authorization models across users, workloads, services, agents and tools, including non-human identities, short-lived credentials, least privilege and delegated access.
-
Establish software supply chain security across source code, generated code, dependencies, models, build environments, infrastructure definitions, artifacts and deployments.
-
Design controls for emerging AI and automation threats, including prompt injection, malicious or poisoned context, tool misuse, excessive agency, privilege escalation and cross-tenant risks.
-
Define reusable security capabilities and engineering patterns for application, platform and data teams rather than relying on one-off security implementations.
-
Establish technical security architecture across cloud platforms, APIs, Kubernetes, networking, enterprise integrations and supporting technology services.
-
Lead technical threat modelling and define the audit, observability and provenance requirements needed to reconstruct and investigate automated decisions and actions.
Requirements
-
Strong experience in security architecture across cloud-native, application or platform environments.
-
Deep understanding of identity, authorization, trust boundaries, least privilege and policy enforcement in distributed systems.
-
Experience with workload identity, non-human identities, credential management, federation and delegated access.
-
Strong understanding of secure software delivery, continuous integration and deployment, infrastructure as code and software supply chain security.
-
Ability to design security controls for systems that can autonomously consume information, make decisions, invoke tools and perform actions.
-
Strong understanding of cloud platforms, APIs, containers, Kubernetes, networking and modern distributed architectures.
-
Understanding of AI and autonomous-system security risks, including prompt injection, untrusted context, tool misuse, excessive permissions and unsafe delegation.
-
Understanding of data security across relational, graph and retrieval architectures, including authorization, provenance, derived information and tenant isolation.
-
Ability to translate threat models, security policy and risk requirements into practical architecture, reusable engineering standards and platform capabilities.
-
Strong communication in English and collaboration skills, with the ability to provide senior technical security leadership across engineering, data, platform and security teams.
Join a truly global team.
We offer a dynamic and international environment where high performance meets real purpose. We're proud to be Great Place to Work-certified and even prouder of the people who make that possible. Let’s shape the future of procurement - together.
Chain IQ – Create. Lead. Make an impact.
Information for agencies: Applications sent or uploaded by placement agencies or similar are not desired, will therefore not be considered and will be deleted.