Position SummaryWe are looking for an experienced Security Architect with strong Application Security expertise who can lead security across a portfolio of complex technology initiatives within BBVA CIB US.
This is a hands-on security leadership role combining security architecture, application security and project security management. The successful candidate will work with engineering and business teams from early design through production, reviewing solution architectures, identifying security risks, defining security requirements and ensuring agreed controls are implemented.
The role requires someone who can manage multiple initiatives simultaneously, prioritize security activities based on risk, and independently drive projects through the security lifecycle while partnering with Corporate Security Architecture, Engineering, Application Development, Infrastructure, Cloud, Risk and business stakeholders.
Key Responsibilities
- Perform security architecture reviews and threat modeling for applications, APIs, cloud services, infrastructure and third-party solutions.
- Evaluate architecture patterns covering authentication and authorization, IAM, encryption, secrets/key management, APIs, network segmentation, data protection, cloud security and secure integration patterns
- Validate that approved architecture and security controls have been implemented as designed before production deployment.
- Own the security workstream for multiple concurrent technology initiatives, establishing security deliverables, dependencies, priorities and milestones and proactively driving them to completion.
- Manage a portfolio of security engagements simultaneously, prioritizing activities based on business criticality, architecture complexity, security risk and delivery timelines.
- Identify security-related project risks and dependencies early, escalate blockers when necessary, and ensure security activities do not become a late-stage impediment to delivery.
- Participate in project governance meetings and provide security guidance to project teams.
- Review Security Models produced by Corporate Security Architecture.
- Assess proposed architectures for alignment with BBVA security standards and U.S. regulatory requirements.
- Provide delegated Security Architecture and Application Security support for local initiatives.
- Identify security gaps and recommend compensating controls where appropriate.
- Review initiatives that may fall outside the standard lifecycle process, including third-party platforms, trading venues, and standalone SaaS solutions.
- Validate that approved security controls are implemented as designed prior to production deployment.
- Serve as the primary security advisor for assigned projects.
- Collaborate with Corporate Security Architecture, Enterprise Architecture, Technology Engineering, Application Development, Infrastructure, Risk, Compliance, and business stakeholders.
Qualifications and Experience
- Bachelor's degree in Information Security, Computer Science, Information Technology, Engineering, or related field (or equivalent experience).
- 10+ years of experience in Information Security, Security Architecture, Application Security, Infrastructure Security, or Cybersecurity Engineering.
- Experience participating in technology projects and implementing security controls.
- Strong understanding of network security, cloud security, identity and access management, application security, and infrastructure security.
- Experience performing security risk assessments and architecture reviews.
- Familiarity with financial services security requirements and regulatory expectations.
- Excellent written and verbal communication skills.
- Ability to influence cross-functional teams without direct authority.
- Experience in banking or financial services.
- Knowledge of cybersecurity and regulatory frameworks including NIST Cybersecurity Framework (NIST CSF), NIST 800-53, ISO 27001, CIS Controls, New York DFS Cybersecurity Regulation (23 NYCRR Part 500), SEC cybersecurity requirements, NFA cybersecurity requirements, FFIEC Guidelines, EU DORA (Digital Operational Resilience Act), SWIFT Customer Security Controls Framework (CSCF), FedLine security requirements, CHIPS-related security requirements, and CRI Profile, or similar frameworks.
- Experience reviewing cloud architectures (Azure, AWS, or GCP).
- Knowledge of AI security, third-party risk, and secure software development practices.
- Professional certifications such as CISSP, CCSP, GCSA, CCSK, CSSLP, SANS certifications (GWEB) and others.
- Strong competencies in Security Architecture, Project Security Governance, Risk Assessment, Application Security, Infrastructure Security, Cloud Security, Regulatory Compliance, Security Control Validation, Stakeholder Management, Analytical Thinking, Problem Solving, and Communication & Collaboration
- Spanish proficiency is a plus
With respect to this position in our New York Office, the expected base salary ranges from $185,000 to $200,000. It is not typical for offers to be made at or near the top of the range. Salary offers are based on a wide range of factors including relevant skills, training, experience, education, and, where applicable, certifications obtained. Market and organizational factors are also considered. In addition to salary and a generous employee benefits package, successful candidates are eligible to receive a discretionary bonus.
*Employment eligibility to work with BBVA in the U.S. is required as the company will not pursue visa sponsorship for these positions