Security Architect
Role details
Job location
Tech stack
Job description
CFC is embarking on a major transformation of its core platforms and systems. To ensure these changes are secure, resilient, and compliant, we are seeking an experienced Security Architect. This role is critical to embedding secure-by-design principles for the future, supporting our Security Maturity Programme, and aligning with the CISO strategy., You will work daily with the Group CISO to ensure consistent high standards in your areas of responsibility and ensure global adherence to security practices. The ideal candidate will have good knowledge of regulatory frameworks such as NYDFS Cybersecurity Regulation, GDPR, and other European and Australian data protection laws, and will bring a proactive, risk-based approach to the governance and operationalisation of security architecture.
- Lead the design and review of secure architecture across strategic change projects.
- Define and implement SDLC security standards and best practices across change projects.
- Develop and enforce API security standards and secure integration patterns.
- Conduct threat modelling and risk assessments for new technology implementations.
- Ensure alignment with enterprise architecture and regulatory frameworks.
- Support the integration of DevSecOps practices and secure CI/CD pipelines.
- Collaborate with engineering, architecture, and compliance teams to embed security from project inception.
- Provide expert guidance on privacy-by-design and operational resilience requirements., Exceptional understanding of secure software development, cloud security, and API security is essential, along with the ability to apply these principles in practical environments. Experience working with DevSecOps, CI/CD pipelines, and modern development practices further strengthens the capability to embed security into every stage of delivery. The role also requires strong skills in conducting threat modelling, performing risk assessments, and reviewing solution architectures, all supported by excellent communication and stakeholder engagement abilities.
Requirements
Do you have experience in Software development?, Candidates should have proven experience as a Security Architect, ideally with more than five years in regulated environments. Familiarity with regulatory frameworks across the US, UK, and Australia is important, as is holding relevant certifications such as CISSP, SABSA, TOGAF, or AWS/Azure Security, which are highly desirable.