Leave us your email address and we'll send you all the new jobs according to your preferences.

Head of Security Architecture and Engineering - CISO function - BPL

Posted 55 minutes 50 seconds ago by Barclays

Permanent
Full Time
Other
London, United Kingdom
Job Description

The Head of Security Architecture and Engineering leads the pillar responsible for designing and building the security foundations of the cloud-native platform. This role owns the security reference architecture, cloud security posture, identity and access management strategy, data security (including tokenisation and encryption), and the technical standards that the entire engineering organisation builds upon. The pillar operates as an internal platform team: it publishes self service security capabilities, automated guardrails, and hardened defaults that enable product teams to build securely by default without needing deep security expertise for every design decision. The ideal candidate is a technically deep security leader who can set architectural direction, make pragmatic engineering trade offs, and build a team that earns the trust and respect of platform and product engineers. This is the most technically demanding leadership role in the CISO function. You will be expected to have credible opinions on cloud security architecture, cryptographic implementation, identity federation, container security, and zero trust design - and to translate those opinions into practical, adoptable standards and services.

Key Responsibilities
  • Define and own the security reference architecture for the cloud native platform, including network security patterns, identity and authentication, encryption, logging, and inter service communication security.
  • Own the cloud security posture management (CSPM) strategy, ensuring continuous monitoring and automated enforcement of security policies across the entire cloud estate.
  • Set and maintain security technical standards, including approved technologies, cryptographic algorithms, authentication protocols, and secure design patterns for microservices.
  • Lead the identity and access management strategy, including privileged access management (PAM), service identity (workload identity, service accounts), RBAC models, and zero trust architecture principles.
  • Own the data security strategy, including cardholder data tokenisation, encryption key management (HSM/KMS), data classification, and data loss prevention implementation.
  • Chair the Security Architecture Board, reviewing architecture proposals, approving non standard patterns, updating standards, and maintaining a decision log.
  • Ensure security guardrails are implemented as automated policies (infrastructure as code, OPA/Rego, CSPM rules) that scale with the platform and enforce security without manual intervention.
  • Publish self service security capabilities for engineering teams: secure base images, IaC security modules, encryption libraries, IAM templates, and approved architecture blueprints.
  • Collaborate closely with Platform Engineering to embed security into the platform layer, ensuring security is a property of the infrastructure, not an afterthought applied on top.
  • Advise the CISO on technical security strategy, emerging technology risks, and the security implications of architectural decisions.
  • Support PCI DSS compliance from an architectural perspective, ensuring the platform design supports scope minimisation, network segmentation, and the technical requirements of PCI DSS 4.0.
  • Manage and develop the Security Architecture and Engineering team of five, building deep technical capability across cloud security, identity, cryptography, and architecture.
Key Deliverables
  • Security reference architecture document, covering cloud, network, identity, data, and application layers - reviewed and updated bi annually.
  • Cloud security policy as code library (OPA/Rego, Terraform Sentinel, or cloud native equivalents) integrated into deployment pipelines.
  • IAM strategy and RBAC model documentation, including privileged access management implementation and zero trust roadmap.
  • Data security and encryption standards document, including approved algorithms, key management procedures, and tokenisation architecture.
  • Technology security standards catalogue (approved languages, frameworks, libraries, protocols, and configurations).
  • Secure design pattern library ("paved road" patterns for common scenarios: API authentication, inter service communication, data handling, secrets management).
  • Security Architecture Board minutes and decision log.
  • CSPM compliance dashboard and drift reporting.
  • Secure base image catalogue for containers and VMs, published and maintained.
Required Skills and Experience
  • AWS Security Specialty, GCP Professional Cloud Security Engineer, or equivalent cloud security certification.
  • Significant experience within FinTech or PayTech/Payments Acquiring.
  • CISSP-ISSAP (Architecture concentration), SABSA, or TOGAF certification.
  • Experience with payment processing architectures (card acquiring, transaction routing, settlement, tokenisation).
  • Kubernetes security certifications (CKS - Certified Kubernetes Security Specialist).
  • Experience with zero trust architecture implementation (BeyondCorp model, ZTNA).
  • Experience with service mesh security (Istio, Linkerd) and mTLS implementation at scale.
  • Published security architecture patterns, conference presentations, or thought leadership.
  • Several years of progressive experience in security engineering or security architecture, with a few years years in a leadership role managing a security engineering team.
  • Deep hands on experience with at least one major cloud provider (AWS or GCP strongly preferred) at an architectural level, including IAM, networking, encryption services, logging, and security specific services (GuardDuty, Security Hub, SCC, etc.).
  • Strong understanding of cloud native architectures: containers, Kubernetes, microservices, service mesh, serverless, and event driven patterns - and their security implications.
  • Experience designing and implementing security guardrails as code (OPA/Rego, Terraform Sentinel, cloud native policy engines, Kubernetes admission controllers).
  • Understanding of cryptographic principles and their practical application in payment systems: tokenisation, format preserving encryption, HSM/KMS key management, TLS configuration, and PCI P2PE concepts.
  • Experience leading technical teams, mentoring engineers, and building team capability in a growing organisation.
  • Ability to communicate architectural decisions and trade offs to both deeply technical engineers and non technical executives - you will present at the Architecture Board and at the CISO Leadership Sync.
  • Understanding of PCI DSS from an architectural perspective: network segmentation, CDE scope management, encryption requirements, logging requirements, and access control architecture.
  • Experience with identity architecture: OAuth 2.0, OpenID Connect, SAML, SCIM, workload identity federation, and zero trust access models.
  • Strong understanding of infrastructure as code practices (Terraform, CloudFormation, Pulumi) and CI/CD pipeline architecture.
Email this Job