Behpardakht Mellat is working on a mission-critical and transformative project and is seeking a highly skilled Software Systems Security Specialist to join its security team. This role is ideal for professionals who are passionate about security architecture design, threat analysis, and protecting sensitive systems in large-scale operational environments.
Responsibilities
- Design and review security architectures for distributed and enterprise software systems
- Analyze security risks and threats across system components, from architecture to implementation
- Define, document, and maintain security requirements and protection profiles
- Perform and supervise threat modeling activities to identify and mitigate security risks
- Conduct and support penetration testing activities at application, API, and network levels
- Collaborate closely with software development, infrastructure, and operations teams to embed security into system design
- Ensure compliance with relevant security standards and frameworks
- Provide security guidance throughout the system lifecycle, from design to production
Qualifications
- Strong expertise in designing security architectures for distributed software systems
- Experience in defining and documenting Protection Profiles (PP) and Security Requirements
- Solid knowledge and hands-on experience with Threat Modeling techniques (e.g., STRIDE, Attack Trees, Risk Assessment)
- Practical experience in penetration testing across application, API, and network layers
- In-depth familiarity with security standards and frameworks, such as ISO/IEC 27001, OWASP, NIST, and Common Criteria
- Good understanding of security aspects related to systems involving terminals, devices, or embedded components
- Knowledge of secure communication protocols, key management, and cryptographic concepts
- Strong collaboration skills and the ability to work closely with software, infrastructure, and operations teams
Preferred Qualifications
- Experience in securing payment systems, FinTech platforms, or critical infrastructure
- Familiarity with national cybersecurity requirements, including defensive and regulatory frameworks
- Experience designing secure architectures for hybrid online/offline systems
- Knowledge of system, database, and middleware hardening practices