Principal Security Architect - DevSecOps
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+40 more
Job description
- Define and evolve the DevSecOps strategy for our cloud-native banking transformation platform.
- Embed security across the SDLC, including design, coding, build, test, deployment, runtime, monitoring, and incident response.
- Design and implement automated security controls across CI/CD pipelines, infrastructure provisioning, application delivery, container images, Kubernetes, and cloud services.
- Integrate and operationalize SAST, DAST, SCA, container scanning, secrets scanning, and policy-as-code.
- Define secure engineering standards and reusable guardrails that help teams move quickly within approved boundaries.
- Apply cloud-native security patterns for IAM, network segmentation, workload identity, secrets management, least privilege, zero trust, runtime security, and auditability.
- Guide secure architecture for APIs, microservices, event-driven systems, SaaS integrations, and developer tooling.
- Partner with platform, backend, DevOps, QA, product, and delivery teams to build security into delivery.
- Mentor engineers through design reviews, threat modeling, code and pipeline reviews, and pairing.
- Ensure production systems are secure, observable, resilient, compliant, and ready for regulated banking.
- Work with our CTO to define standards, identify engineering gaps, improve delivery quality, and ensure architecture is reflected in production code, platforms, and operational practices.
- Influence multiple teams, establish reusable standards, mentor technical leaders, challenge weak designs, and turn technical direction into production-quality execution.
- Use engineering judgment to validate, refine, or reject AI-generated outputs and ensure controls are automated, observable, repeatable, and embedded.
Technologies:
- AI
- API
- AWS
- Architect
- Backend
- CI/CD
- Cloud
- CloudWatch
- CTO
- DevSecOps
- DevOps
- Embedded
- GitOps
- Grafana
- IAM
- Kubernetes
- Network
- OpenTelemetry
- Prometheus
- RBAC
- Security
- Terraform
- microservices
- LESS
Requirements
- 8+ years of experience in software, security, cloud security, DevSecOps, or platform engineering; 10-15 years is ideal, with production platform ownership.
- Strong software engineering background, including the ability to review application code, system designs, CI/CD workflows, infrastructure automation, and runtime behavior.
- Proven experience securing cloud-native platforms in production.
- Deep knowledge of secure SDLC practices, including secure design and coding, threat modeling, automated testing, vulnerability and dependency management, release controls, and production readiness.
- Practical experience integrating SAST, DAST, and SCA into CI/CD workflows.
- Experience with container security, including image scanning, base-image strategy, registry controls, remediation, runtime configuration, and secure workload deployment.
- Kubernetes security experience, including cluster hardening, namespace isolation, RBAC, admission control, network policies, workload identity, pod security, secrets, ingress, and runtime protection.
- Experience with policy-as-code tools such as OPA, Gatekeeper, or Kyverno, or equivalent tools.
- Knowledge of IAM, least privilege, zero trust, workload identity, service-to-service authentication, and identity-driven security models.
- Experience with secrets management, including secure storage, rotation, access control, pipeline integration, runtime injection, and governance.
- Experience securing SaaS integrations and platform architectures, including identity, access, data protection, tenant boundaries, and auditability.
- Experience with CI/CD security automation, including pipeline hardening, artifact integrity, dependency controls, environment promotion, deployment approvals, rollback safety, and supply-chain security.
- Production security experience, including reliability, auditability, scalability, incident response, monitoring, and remediation.
- Strong communication skills, including the ability to explain architecture, risks, and trade-offs to globally distributed teams.
- Technical leadership and mentoring skills to raise engineering standards without formal authority.
- Comfort working in a global, distributed organization across multiple teams, stakeholders, and time zones.
- Preferred: AWS security experience, including IAM, Organizations, networking, KMS, CloudTrail, GuardDuty, Security Hub, workload identity, private connectivity, and multi-account patterns.
- Preferred: Production experience with Amazon EKS or equivalent Kubernetes platforms.
- Preferred: IaC security experience with AWS CDK, Terraform, or CloudFormation, including static analysis, policy enforcement, and secure module design.
- Preferred: GitOps security experience, including repository controls, signed artifacts, environment promotion, drift detection, and deployment guardrails.
- Preferred: Software supply-chain security experience, including SBOMs, artifact signing, provenance, dependency controls, and build integrity.
- Preferred: Observability and security monitoring experience with tools such as Prometheus, Grafana, CloudWatch, OpenTelemetry, SIEM, tracing, logging, and event correlation.
- Preferred: API security experience, including OAuth2/OIDC, mTLS, service mesh, gateway security, rate limiting, token validation, and service-to-service authorization.
- Preferred: Experience in financial services, banking, or regulated environments where auditability and operational control are critical.
- Preferred: Experience building reusable security platforms, guardrails, templates, policy libraries, and paved-road patterns for multiple teams.
- Preferred: Experience supporting, patching, auditing, scaling, migrating, and evolving secure platforms after adoption.
About the company
UST has worked alongside leading companies since 1999, partnering from design through operation to deliver technology-driven transformation. Headquartered in the United States, we have more than 30,000 employees in over 30 countries and focus on creating measurable value and lasting change. UST FinX brings together professionals working to help banks move beyond legacy technology constraints. We are hiring a Principal Security Architect - DevSecOps for a senior, hands-on technical leadership role focused on embedding security throughout our engineering lifecycle. The role reports directly to the CTO of UST FinX and provides technical influence across teams; it is neither a passive advisory position nor a traditional people-management role. We value integrity, humility, humanity, innovation, diversity, and inclusion, and we are an equal opportunity employer.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
Now is the time for industrialized software development
Is Software Engineering Over-Saturated?
Why Upskilling And Reskilling is Important For Developers