Negotiable
Undetermined
Undetermined
London Area, United Kingdom
Summary: The Application Security Architect role at a Challenger bank involves leading security initiatives during a significant digital transformation. The position requires collaboration with various stakeholders to enhance the security posture of critical banking systems while managing risk assessments and providing expert advice on information security practices. The architect will also develop a deep understanding of secure change processes and build strong relationships within the delivery team. This role is pivotal in integrating application security controls into development processes and ensuring compliance with regulatory requirements.
Key Responsibilities:
- Lead risk & control assessments covering supplier due diligence, privacy impact assessments, and project security.
- Support workstream in identifying and articulating risks, documenting mitigating controls, and ensuring timely actions.
- Provide specialist advice on Information Security best practices and UK regulatory requirements to stakeholders.
- Develop deep knowledge of the bank's secure change processes and shepherd workstreams through assessments.
- Build trust-based relationships with key stakeholders within the delivery team and actively participate in team activities.
Key Skills:
- Solid experience in integrating application security controls into CI/CD pipelines.
- Understanding of cloud security, microservices, and modern architecture.
- Good understanding of core privacy concepts related to technology change initiatives.
- Experience supporting technology change initiatives to deliver secure solutions.
- Experience in undertaking security assessments of complex systems and platforms.
Salary (Rate): undetermined
City: London Area
Country: United Kingdom
Working Arrangements: undetermined
IR35 Status: undetermined
Seniority Level: undetermined
Industry: IT
Application Security Architect - Java- Banking
This is an excellent opportunity for an Application Security Architect to work with a Challenger bank during their massive digital transformation . This is a chance to act as the security lead in an application development delivery team working across a complex hybrid tech stack. Operating with independence, you will be in a critical position to influence the security posture of critical Bank systems while collaborating closely with engineers, product managers, and business stakeholders.
Responsibilities
- Risk and Control Assessments – You will lead risk & control assessments using the Banks defined processes, covering supplier due diligence, privacy impact assessments and project security.
- Risk Management – You will support your workstream identify and articulate risks, steering them towards appropriate treatment plans, documenting mitigating controls and ensuring these are actions within agreed timeframes. You will operate in line with the Bank's Risk Management framework (including sub-frameworks) and relevant risk and compliance policies and procedures, ensuring appropriate and timely escalation of any concerns to your line manager.
- Advisory – You will provide specialist advice and interpretation of Information Security best practice and UK regulatory requirements to a range of different stakeholders as new products, processes and systems are developed. You will need to be aware of your own knowledge gaps and when & where to seek specialist input to solve a particular problem or query
- Subject Matter Expertise – You will develop a deep knowledge of the Banks secure change processes and procedures, shepherding your workstream through various assessments and approval gates
- Relationship Management – You will build deep, trust based relationships with key stakeholders within your delivery team such as developers, testers, product managers, delivery leads and tech leads. You will be an active member of the delivery team, attending daily stand-ups, PI planning sessions and working groups.
Ideal Candidate
- Application Security - Solid, practical and demonstrable experience of integrating application security controls (technical and non technical aspects), covering SDLC and secure coding practices, into CI/CD pipelines.
- Understanding of cloud security, microservices and modern architecture.
- Privacy – You don’t need to be a privacy expert but you will require a good understanding of core privacy concepts and how these apply to technology change initiatives
- Technology Change – Demonstrable experience of supporting technology change initiatives to deliver solutions securely
- Risk and Control Assessments – Although your primary focus will be SDLC and secure coding practices, you’ll also need experience of undertaking security assessments of complex systems and platforms.
Bank Banking Finance Information Security Architect Information Security Architecture Application Security Architect Java J2EE InfoSec Architect AppSec Architect React API RPJ JSP SDLC Software Development Life Cycle Digital Transformation