Apply now »

Technical Security Control Architect

Location: 

Mumbai, IN, 400076

Req ID:  86420
Facility:  Mumbai-470
Department:  Enterprise Solution Architecture
Division:  Innovation

LyondellBasell (NYSE: LYB): As a leader in the global chemical industry, LyondellBasell strives every day to be the safest, best operated and most valued company in our industry. The company’s products, materials and technologies are advancing sustainable solutions for food safety, access to clean water, healthcare and fuel efficiency in more than 100 international markets. LyondellBasell places high priority on diversity, equity and inclusion and is Advancing Good with an emphasis on our planet, the communities where we operate and our future workforce.  The company takes great pride in its world-class technology and customer focus. LyondellBasell has stepped up its circularity and climate ambitions and actions to address the global challenges of plastic waste and decarbonization. For more information, please visit www.lyondellbasell.com or follow @LyondellBasell on LinkedIn.

Basic Function

As a Principal Technical Security Controls Remediation IT Architect you are responsible for designing, implementing, and managing security controls across all technology platforms, excluding SAP and define a strategy that supports the company’s overall strategy and the Technology roadmap. This role plays a critical role in ensuring the effective functioning and compliance of non-SAP systems within LYB. This role is pivotal in safeguarding LYB’s critical assets by ensuring the confidentiality, integrity, and availability of our systems and data. This position involves leading the development of non-SAP application security architecture frameworks, policies, and procedures to protect the organization's IT assets and ensure compliance with industry standards and regulations. This position involves developing and implementing strategies to identify, assess, and remediate controls-related issues within LYB IT environments. This role will be driving security efficiencies, ensuring that technical governance is based on sound architectural principles and correctly documented. This position will work closely with other IT functional and technical Architects, IT Leadership Team, Cyber Security, Internal Controls, Internal Audits and Product teams. 

Roles & Responsibilities

A Principal Technical Security Control Architect is responsible for ensuring the security of a company's non-SAP systems including on-prem and Cloud. They develop and implement security policies and procedures, conduct security assessments, and perform audits to identify vulnerabilities and risks. They also design Application Security models (Access control and Process control), manage business workshops for requirement gathering, and convert business requirements into technical design/authorization matrix and documentation.:

  • Continuously conducting comprehensive assessments of existing controls frameworks, policies, and procedures within different systems, excluding SAP, to identify weaknesses, gaps, and areas of non-compliance.
  • Designing and implementing remediation plans to address identified control deficiencies, ensuring alignment with industry best practices, regulatory requirements, and organizational objectives.
  • Design, implement, and manage security controls for various applications and technologies, including but not limited to:
  • Identity and access management (IAM)
  • Cloud security (IaaS, PaaS, SaaS)
  • Network infrastructure (firewalls, routers, switches, VPNs)
  • Endpoint protection (antivirus, intrusion detection/prevention systems)
  • Data protection and encryption
  • Security information and event management (SIEM)
  • Collaborating with other LYB IT architects, IT CoE, IT Product teams and Cyber Security team to design and implement technical solutions that enhance control mechanisms within on-prem and cloud systems, including configuration changes, system upgrades, and integration with third-party tools.
  • Collaborate with IT teams to ensure security is integrated into the software development lifecycle (SDLC).
  • Collaborating with internal audit and business stakeholders to understand control requirements and risk assessments.
  • Systematically design and implement technical solutions to mitigate control risks using best practices and industry standards.
  • Regularly document and communicate control remediation activities and their impact on business processes.
  • Staying up-to-date on the latest security threats and vulnerabilities.
  • Participating in continuous improvement initiatives to enhance the overall security posture of the technology environment.
  • Providing strategic leadership and creative thinking to help the technical delivery team through the project lifecycle
  • Creating conceptual architecture views, Architecture Technical designs, collect and document architecture significant decisions and architecture key constraints
  • Analyzing architecture alternatives and provide recommendations on best options, considering input from the development teams
  • Working on multiple concurrent projects, meet business expectations, influence outcomes and maintain stated timelines
  • Creating documents such as System Security Plan (SSP), Security Assessment Report (SAR), Contingency Planning, Incident Response Plan, Technical Risk Assessments(TRA) Plans of Actions and Milestones (POA&Ms)

Min. Qualifications

This is a Principal Technical security control architect position requiring either a degreed professional who possesses a Bachelor's degree in Computer Science, Business or Engineering with a minimum of fifteen (15) years of relevant experience. This individual must demonstrate strong technical security expertise and knowledge in each of the following technology disciplines:

  • Bachelor’s degree or higher in information technology, Computer Science or a related discipline
  • 15 years of professional experience in security, controls and remediation.
  • Minimum of 5 years of experience in security and controls.
  • Proven experience in identifying, analyzing, and remediating control deficiencies.
  • In-depth understanding of security concepts, including authorization, segregation of duties, and user access management.
  • Experience with internal audit methodologies and frameworks is a plus.
  • Knowledge of relevant compliance regulations (e.g., SOX, GDPR).
  • A strong understanding of data privacy and security best practices is a plus.
  • Strong analytical and problem-solving skills.
  • Ability to work independently and as part of a team.
  • Excellent project management skills.
  • Demonstrated problem solving, multi-tasking, troubleshooting skills with a high degree of flexibility
  • Experience in Software Development Life Cycle (SDLC) / Agile development / DevOps
  • Strong analytical skills with the ability to understand key business processes and related issues
  • Strong self-leadership and ability to work independently and manage conflict
  • Demonstrated competency in accurately identifying the scope of work and preparing thorough, accurate and detailed schedule estimates.
  • Non-functional requirements gathering and solutioning experience
  • Ability to develop successful relationships with external and internal partners
  • Good understanding of Microsoft and other technology systems such as Azure Cloud, Office 365, AspenTech, OpenText, Salesforce, OneStream 

#LI-SK1

#LI-Hybrid

 

Preferred Qualifications

Competencies

Build Partnerships
Deliver Results
Drive Innovation
Grow Capabilities
Promote Inclusion
Motivational/Cultural Fit
Technical Skills

 

We are LyondellBasell – a leader in the global chemical industry creating solutions for everyday sustainable living. Through advanced technology and focused investments, we are enabling a circular and low carbon economy. Across all we do, we aim to champion our employees, and unlock value for customers, investors and society. LyondellBasell places high priority on diversity, equity and inclusion and is strongly committed to our planet, the communities where we operate and our future workforce.  As one of the world’s largest producers of polymers and a leader in polyolefin technologies, we develop, manufacture and market high-quality and innovative products for applications ranging from sustainable transportation and food safety to clean water and quality healthcare. For more information, please visit www.lyondellbasell.com or follow @LyondellBasell on LinkedIn.

 

Must be at least 18 years of age and must be legally authorized to work in the United States (US) on a permanent basis without visa sponsorship.

 

LyondellBasell does not accept or retain unsolicited résumés or phone calls and/or respond to them or to any third party representing job seekers.

 

LyondellBasell is an equal opportunity employer.  We evaluate qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, age, veteran status, and other protected characteristics.  The US EEO is the Law poster is available here.

Apply now »