Global Security Architect, hibrido


Empresa
 Infront Financial Technology
Provincia
 Madrid
Ciudad
Madrid
Tipo de Contrato
 Tiempo Completo
Descripción
Global Security Architect
Purpose of the role
Infront builds and operates financial technology products for banks and asset managers across thirteen countries, on a technology estate that has grown by acquisition. Today, security is built in product by product: encryption, authentication, secrets handling and logging are solved differently in each, by whoever built it. The Global Security Architect owns how security is designed into Infronts products, replacing that patchwork with shared patterns the teams can adopt and reuse.
The role sits in engineering and reports to the Head of Information Security for mandate and standards. It spends its days with the teams that build the products, in the architecture forum, in design reviews, and alongside the Security Champions it coordinates. Success means new products and material changes are secure by design from the start.
Accountabilities
Own the reference security patterns for Infronts products: authentication and authorisation, encryption and key handling, secrets management, logging and telemetry, and secure service-to-service communication. Publish them, keep them current, and see them adopted.
Own the Secure Development Standard and the security gates in the build and deployment pipeline, including continuous scanning that covers components embedded in Infronts own software, not only what is installed on hosts.
Lead threat modelling and security design review for new products and material changes, proportionate to risk, and record the outcome so it is auditable.
Be the technical lead for identity architecture across the estate: the enterprise identity provider, the product authentication platform and the trading authorisation layer, including succession planning for platforms that today depend on a single person.
Own security architecture for the cloud estate, across multiple AWS accounts and Azure tenants, and for the boundary between shared and isolated platform instances.
Coordinate the Security Champions, one named engineer per product area, as a dotted-line community: set their agenda, give them patterns to apply, and use them to reach every team.
Represent security in the architecture forum and in the Cyber Resilience Act secure-by-design work, and translate regulatory expectations into engineering decisions.
Provide the application-layer input to vulnerability prioritisation and penetration test scoping, so that testing concentrates on the shared components most products depend on.
Experience and skills, essential

Substantial experience designing security into software products, in a company that builds and operates its own platforms, ideally financial technology or another regulated SaaS environment.
Hands-on depth in application security and secure development: threat modelling, OWASP-aligned secure coding, SAST, SCA and secrets scanning in CI/CD, and what it takes to get engineers to adopt them.
Cloud security architecture across AWS and Azure, including multi-account governance, container platforms and infrastructure as code.
Identity and access architecture: enterprise identity providers, single sign-on, OAuth and OIDC, and product-level authentication platforms of the Keycloak type.
Cryptography applied in practice: what to use, where, and how to manage keys and certificates, rather than theory.
The credibility to influence engineers without line authority, and the judgement to know when a pattern must be mandatory and when it can be guidance.
Fluent English is a must.

OWASP, SAST, SCA, CI/CD,Cloud security, AWS, Azure, OAuth, OIDC
Regresar
Al enviar este formulario certifico que acepto los Terminos de Uso

 

Empleos más buscados

Ubicaciones Frecuentes