2 hours ago
Madrid, SpainSenior
Responsibilities
- Own and drive BASF’s authenticator ecosystem, including Smartcard Management, Smartcards, Windows Hello for Business, and FIDO2.
- Advance phishing-resistant and passwordless authentication as part of BASF’s global Identity Security strategy.
- Define and execute technical roadmaps aligned with Zero Trust principles and long-term security objectives.
- Influence authentication architecture, technology standards, and future platform capabilities while remaining hands-on with engineering and implementation.
- Design, configure, integrate, operate, and continuously improve enterprise authentication platforms, infrastructure components, client software, and backend services.
- Manage platform stability through administration, upgrades, rollouts, vulnerability remediation, and lifecycle management.
- Lead troubleshooting, root-cause analysis, and sustainable improvements for complex technical issues and major incidents.
- Collaborate with product, architecture, cybersecurity, infrastructure, and business stakeholders.
- Manage technical relationships with vendors and service providers, including service improvements and roadmap discussions.
- Evaluate emerging technologies including FIDO2, passkeys, post-quantum cryptography, and AI-supported operations.
- Mentor junior team members and contribute to agile delivery processes, including backlog refinement, sprint planning, and retrospectives.
Requirements
- Bachelor’s or master’s degree in computer science, Cyber Security, or a comparable qualification, or equivalent professional experience.
- At least 7 years of experience in IT, Cyber Security, IAM, or authentication-related domains.
- Strong expertise in Smartcards, FIDO2, Windows Hello for Business, MFA, and certificate-based authentication.
- Solid understanding of PKI, certificates, and public/private key cryptography.
- Hands-on experience implementing, operating, and troubleshooting enterprise authentication solutions.
- Experience with enterprise-scale authentication architectures and business-critical security services.
- Strong knowledge of Windows client/server environments and backend technologies, including SQL.
- Proven experience managing complex technical issues and major incidents.
- Experience driving technical roadmaps, service evolution, or architecture improvements.
- Familiarity with agile ways of working and tools such as Azure DevOps.
- Experience with IAM platforms, SSO, and federation technologies such as Entra ID is preferred.
- Knowledge of Zero Trust architecture, modern identity security, automation, scripting, Infrastructure-as-Code, AI-supported operations, and regulatory or compliance requirements is preferred.
- Strong communication, collaboration, stakeholder-management, ownership, and independent-working skills.
- Excellent written and spoken English.
Benefits
- Flexible work schedule and home-office options.
- Learning and development opportunities.
- 25 holiday days per year plus 5 additional readjustment days.
- Collaborative, trustful, and innovative work environment.
- International team and global projects.
- Relocation assistance to Madrid.
- Secure work environment focused on health, safety, and wellbeing.
