Search Jobs

Search by job, company or skills

Head of Security Architecture and Engineering (Banking / Financial Services)

Head of Security Architecture and Engineering (Banking / Financial Services)

risewave consulting, inc.
  • Posted 15 hours ago
  • Be among the first 10 applicants

Job Description

The Opportunity

Our client is seeking an experienced Security Architecture & Engineering Head to provide strategic direction and technical leadership across its enterprise security landscape.

The role will oversee multiple security disciplines, including Security Architecture, Application Security, Platform & Cloud Security, and Security & Fraud Product Management. The successful candidate will be responsible for driving security transformation initiatives, strengthening security capabilities, and ensuring security is embedded into technology and business decisions.

This is a leadership position suited for a security professional who combines strong technical depth, enterprise-level thinking, and proven people leadership.

What You'll Be Responsible For

Security Strategy & Leadership

  • Set the overall direction and roadmap for security architecture and engineering initiatives.
  • Translate business objectives into practical security strategies and technology solutions.
  • Work closely with senior stakeholders across Technology, Product, Risk, and other business functions.
  • Provide guidance on emerging cybersecurity technologies, industry developments, and evolving security practices.
  • Drive initiatives that continuously improve the organization's overall security maturity.

Enterprise Security Architecture

  • Establish and continuously improve the organization's security architecture standards and principles.
  • Ensure security is incorporated into the design of applications, systems, infrastructure, and technology platforms.
  • Review and provide direction on security-related architecture and technology decisions.
  • Establish appropriate security governance and ensure adherence to internal policies and standards.
  • Promote a secure-by-design approach across technology initiatives.

Application & Software Security

  • Lead initiatives focused on improving application security throughout the development lifecycle.
  • Partner with software engineering teams to incorporate security practices into development processes.
  • Oversee secure coding, security testing, vulnerability identification, and remediation activities.
  • Drive the use of automated security testing and monitoring capabilities.
  • Help engineering teams adopt and maintain effective application security practices.

Cloud, Infrastructure & Platform Security

  • Provide leadership over security controls across infrastructure, cloud, and enterprise technology environments.
  • Define appropriate security configurations, hardening standards, and protection mechanisms.
  • Oversee capabilities covering areas such as Identity & Access Management, Endpoint Security, Network Security, and Cloud Security.
  • Ensure technology environments are appropriately protected against evolving security threats.
  • Support the adoption of secure and scalable cloud and platform architectures.

Security & Fraud Solutions

  • Lead the direction and delivery of security and fraud prevention products and capabilities.
  • Work with Product, Engineering, and Business teams to establish and execute relevant security product roadmaps.
  • Ensure security solutions address business requirements while meeting applicable regulatory and compliance obligations.
  • Identify opportunities to improve security and fraud prevention capabilities through technology and innovation.

People & Organizational Leadership

  • Build, lead, and develop a high-performing organization of security architects, engineers, and product professionals.
  • Establish clear objectives, performance expectations, and development plans for the team.
  • Encourage collaboration, innovation, knowledge sharing, and continuous improvement.
  • Manage workforce planning, resource allocation, budget requirements, and recruitment activities.
  • Develop the team's technical and leadership capabilities to support long-term organizational needs.

Risk, Governance & Compliance

  • Work alongside Risk, Legal, Compliance, and other stakeholders to ensure security practices meet relevant regulatory and industry requirements.
  • Lead or support enterprise security risk assessments and remediation planning.
  • Monitor key security risks and ensure appropriate mitigation strategies are implemented.
  • Present security initiatives, risks, performance, and progress to senior leadership.

What We're Looking For

Education & Professional Experience

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related discipline.
  • Master's degree is an advantage.
  • At least 10 years of experience in Information Security/Cybersecurity.
  • Minimum 5 years of experience in a leadership or management capacity.
  • Strong track record in security architecture and engineering, ideally combined with experience in security product management.
  • Experience leading security initiatives across complex enterprise technology environments.

Technical Background

Strong knowledge and practical experience in several of the following areas:

  • Enterprise Security Architecture
  • Application Security
  • Cloud Security – AWS, Azure, or GCP
  • Platform & Infrastructure Security
  • DevSecOps and secure CI/CD practices
  • Container and workload security
  • Identity & Access Management
  • Endpoint and Network Security
  • Vulnerability Management
  • Security Testing and Assessment
  • SIEM and security monitoring technologies
  • SAST / DAST solutions

Familiarity with established cybersecurity frameworks and standards such as:

  • NIST Cybersecurity Framework (CSF)
  • ISO 27001
  • CSA Cloud Controls Matrix

More Info

Job Type:
Industry:
Employment Type:

Key Skills

NIST Cybersecurity Framework CSF

Security Testing and Assessment

Cloud Security – AWS Azure or GCP

SIEM and security monitoring technologies

Container and workload security

Enterprise Security Architecture

SAST DAST solutions

CSA Cloud Controls Matrix

Endpoint and Network Security

DevSecOps and secure CI CD practices

Platform Infrastructure Security