Bachelor’s Degree in IT, Cybersecurity, Computer Science, Engineering, or a related field, with a Postgraduate Qualification advantageous.
Minimum 7–15 years of Cybersecurity experience, including at least 5 years in Senior, Lead, or Enterprise Security Architecture roles.
Significant experience within regulated Financial Services, Banking, or Fintech Environments, preferably across multiple entities or jurisdictions.
Proven end-to-end Security Architecture experience across Cloud, Applications and APIs, data, identity, and Integrations.
Proven experience developing target-state architectures, reference patterns, threat models, security requirements, and architecture roadmaps.
Experience leading design assurance, risk treatment, and security decisions across major programmes and third parties.
Strong knowledge of Financial-Sector Cybersecurity, technology risk, privacy, resilience, outsourcing requirements, PCI DSS, ISO/IEC 27001, NIST, CIS, and OWASP.
Define and maintain the Group Security Architecture vision, principles, target states and multi-year roadmaps aligned to business strategy and cyber objectives
Lead security architecture reviews for new products, platforms, material changes, acquisitions, integrations, and strategic programmes.
Translate business, regulatory, privacy, and resilience requirements into security requirements, controls, and architecture decisions.
Perform threat modelling, abuse-case analysis, trust-boundary assessments, and attack-path analysis for material solutions.
Define secure architecture patterns and guardrails across AWS and Azure, including IAM, networking, encryption, logging, key management, and infrastructure security.
Promote Zero Trust, least privilege, segregation of duties, defence in depth, and secure-by-default configurations across technology platforms.
Define security architecture requirements for web, mobile, API, microservice, event-driven, and third-party-integrated solutions.
Embed security controls throughout the SDLC and CI/CD lifecycle, including SAST, SCA, DAST, IaC, secrets, container, and artefact security.
Define identity architecture covering workforce, privileged, service, and customer identities, including federation, MFA, Conditional Access, and lifecycle controls.
Establish security architecture requirements for data classification, encryption, tokenisation, masking, DLP, retention, logging, and secure disposal.
Assess third-party, SaaS, outsourcing, partner, and fourth-party architectures, including shared responsibility, security requirements, and exit considerations.
Advise on risk treatment, compensating controls, formal exceptions, resilience, recoverability, observability, and containment of critical services.
Contribute security architecture expertise during major incidents, forensic investigations, post-incident reviews, cyber exercises, and control-improvement initiatives.
Act as a senior security architecture advisor, coordinate architecture across multiple entities and jurisdictions, influence stakeholders, and mentor architects and security practitioners.
You have successfully created your alert.
You will receive an email when a new job matching your criteria is posted.
Please check your email. It looks like you haven't verified your account yet. Here's what you're missing out on:
Didn't receive the link? Resend Verification Link