Jobs
My ads
My job alerts
Sign in
Find a job Career Tips Companies
Find

Head of security architecture and engineering - ciso function - bpl

London
Barclays
Head of security
€115,000 a year
Posted: 15 June
The role

The Head of Security Architecture and Engineering leads the pillar responsible for designing and building the security foundations of the cloud-native platform. This role owns the security reference architecture, cloud security posture, identity and access management strategy, data security (including tokenisation and encryption), and the technical standards that the entire engineering organisation builds upon. The pillar operates as an internal platform team: it publishes self‑service security capabilities, automated guardrails, and hardened defaults that enable product teams to build securely by default without needing deep security expertise for every design decision. The ideal candidate is a technically deep security leader who can set architectural direction, make pragmatic engineering trade‑offs, and build a team that earns the trust and respect of platform and product engineers. This is the most technically demanding leadership role in the CISO function. You will be expected to have credible opinions on cloud security architecture, cryptographic implementation, identity federation, container security, and zero‑trust design — and to translate those opinions into practical, adoptable standards and services.

Key Responsibilities

  • Define and own the security reference architecture for the cloud‑native platform, including network security patterns, identity and authentication, encryption, logging, and inter‑service communication security.
  • Own the cloud security posture management (CSPM) strategy, ensuring continuous monitoring and automated enforcement of security policies across the entire cloud estate.
  • Set and maintain security technical standards, including approved technologies, cryptographic algorithms, authentication protocols, and secure design patterns for microservices.
  • Lead the identity and access management strategy, including privileged access management (PAM), service identity (workload identity, service accounts), RBAC models, and zero‑trust architecture principles.
  • Own the data security strategy, including cardholder data tokenisation, encryption key management (HSM/KMS), data classification, and data loss prevention implementation.
  • Chair the Security Architecture Board, reviewing architecture proposals, approving non‑standard patterns, updating standards, and maintaining a decision log.
  • Ensure security guardrails are implemented as automated policies (infrastructure‑as‑code, OPA/Rego, CSPM rules) that scale with the platform and enforce security without manual intervention.
  • Publish self‑service security capabilities for engineering teams: secure base images, IaC security modules, encryption libraries, IAM templates, and approved architecture blueprints.
  • Collaborate closely with Platform Engineering to embed security into the platform layer, ensuring security is a property of the infrastructure, not an afterthought applied on top.
  • Advise the CISO on technical security strategy, emerging technology risks, and the security implications of architectural decisions.
  • Support PCI DSS compliance from an architectural perspective, ensuring the platform design supports scope minimisation, network segmentation, and the technical requirements of PCI DSS 4.0.
  • Manage and develop the Security Architecture and Engineering team of five, building deep technical capability across cloud security, identity, cryptography, and architecture.

Key Deliverables

  • Security reference architecture document, covering cloud, network, identity, data, and application layers — reviewed and updated bi‑annually.
  • Cloud security policy‑as‑code library (OPA/Rego, Terraform Sentinel, or cloud‑native equivalents) integrated into deployment pipelines.
  • IAM strategy and RBAC model documentation, including privileged access management implementation and zero‑trust roadmap.
  • Data security and encryption standards document, including approved algorithms, key management procedures, and tokenisation architecture.
  • Technology security standards catalogue (approved languages, frameworks, libraries, protocols, and configurations).
  • Secure design pattern library (“paved road” patterns for common scenarios: API authentication, inter‑service communication, data handling, secrets management).
  • Security Architecture Board minutes and decision log.
  • CSPM compliance dashboard and drift reporting.
  • Secure base image catalogue for containers and VMs, published and maintained.

Required Skills and Experience

  • AWS Security Specialty, GCP Professional Cloud Security Engineer, or equivalent cloud security certification.
  • Significant experience within FinTech or PayTech/Payments Acquiring.
  • CISSP-ISSAP (Architecture concentration), SABSA, or TOGAF certification.
  • Experience with payment processing architectures (card acquiring, transaction routing, settlement, tokenisation).
  • Kubernetes security certifications (CKS — Certified Kubernetes Security Specialist).
  • Experience with zero‑trust architecture implementation (BeyondCorp model, ZTNA).
  • Experience with service mesh security (Istio, Linkerd) and mTLS implementation at scale.
  • Published security architecture patterns, conference presentations, or thought leadership.
  • Several years of progressive experience in security engineering or security architecture, with a few years years in a leadership role managing a security engineering team.
  • Deep hands‑on experience with at least one major cloud provider (AWS or GCP strongly preferred) at an architectural level, including IAM, networking, encryption services, logging, and security‑specific services (GuardDuty, Security Hub, SCC, etc.).
  • Strong understanding of cloud‑native architectures: containers, Kubernetes, microservices, service mesh, serverless, and event‑driven patterns — and their security implications.
  • Experience designing and implementing security guardrails as code (OPA/Rego, Terraform Sentinel, cloud‑native policy engines, Kubernetes admission controllers).
  • Understanding of cryptographic principles and their practical application in payment systems: tokenisation, format‑preserving encryption, HSM/KMS key management, TLS configuration, and PCI P2PE concepts.
  • Experience leading technical teams, mentoring engineers, and building team capability in a growing organisation.
  • Ability to communicate architectural decisions and trade‑offs to both deeply technical engineers and non‑technical executives — you will present at the Architecture Board and at the CISO Leadership Sync.
  • Understanding of PCI DSS from an architectural perspective: network segmentation, CDE scope management, encryption requirements, logging requirements, and access control architecture.
  • Experience with identity architecture: OAuth 2.0, OpenID Connect, SAML, SCIM, workload identity federation, and zero‑trust access models.
  • Strong understanding of infrastructure‑as‑code practices (Terraform, CloudFormation, Pulumi) and CI/CD pipeline architecture.
#J-18808-Ljbffr
Apply
Create E-mail Alert
Job alert activated
Saved
Save
Similar job
Head of security, privacy & resilience
London
Phoenix Court Group
Head of security
€100,000 a year
Similar job
Head of security
London
Eagle Eye Group
Head of security
€80,000 a year
Similar job
Head of security
London
Abm-Industries-Inc.-2
Head of security
€60,000 a year
See more jobs
Similar jobs
Barclays recruitment
Barclays jobs in London
Security jobs in London
jobs London
jobs Greater London
jobs England
Home > Jobs > Security jobs > Head of security jobs > Head of security jobs in London > Head of Security Architecture and Engineering - CISO function - BPL

About Jobijoba

  • Career Advice
  • Company Reviews

Search for jobs

  • Jobs by Job Title
  • Jobs by Industry
  • Jobs by Company
  • Jobs by Location
  • Jobs by Keywords

Contact / Partnership

  • Contact
  • Publish your job offers on Jobijoba

Legal notice - Terms of Service - Privacy Policy - Manage my cookies - Accessibility: Not compliant

© 2026 Jobijoba - All Rights Reserved

Apply
Create E-mail Alert
Job alert activated
Saved
Save