Location: UB Plaza – 30F Pasig (Headquarters)
Employment Type: Full-Time
About The Role
We're looking for a Security Architect who will design, review, and implement security solutions that protect the Bank's technology environment against cyber threats and unauthorized access. This role works closely with business, architecture, and technical teams to ensure security controls are embedded across infrastructure, applications, cloud platforms, and digital initiatives.
What You'll Do
- Analyze systems, applications, and infrastructure to identify risks and design security controls that safeguard information assets.
- Design and implement security solutions across infrastructure, cloud environments, applications, SDLC processes, and technologies such as DLP, SIEM, and Identity & Access Management.
- Collaborate with enterprise architects, engineering teams, and security specialists to ensure security requirements are integrated into all IT systems and projects.
- Manage and enhance the Bank's information security architecture, staying ahead of emerging threats, vulnerabilities, and industry best practices.
- Research, recommend, and support the adoption of new security technologies while maintaining security documentation and contributing to the organization's security strategy.
What We're Looking For
- Bachelor's degree in Information Security, Computer Science, Information Technology, Engineering, or a related field.
- At least 3-5 years of experience in cybersecurity, information security, security architecture, or security engineering, with hands-on experience in threat modeling and secure solution design.
- Strong knowledge of security domains including Identity and Access Management (IAM), Network Security, Cloud Security, API Security, and related technologies.
- Experience in cybersecurity risk management and security governance within a regulated environment, preferably in banking, financial services, or other highly regulated industries.
- Relevant cybersecurity certifications such as ISC2 Certified in Cybersecurity (CC), CISSP, CCSP, CISM, or cloud security certifications are preferred; able to translate regulatory and risk requirements into practical security controls