Job Purpose
Lead customer-facing security architecture and forward-deployed cybersecurity engineering for financial services and high-volume digital businesses. The role reviews complex application, cloud and infrastructure architectures, identifies material security risks, and converts findings into practical, deployable solutions. It bridges security, engineering and customer delivery by supporting technical design, prototyping, implementation, validation and reusable solution development across AWS, Java-based platforms, DevSecOps and AI-assisted security engineering.
Key Responsibilities
- Security Architecture & Risk-to-Solution Delivery: Perform end-to-end security architecture reviews for banking, mobile banking, core banking, payment, e-commerce, online retail, marketplace and cloud-native platforms. Assess application, API, identity, data, network, cloud, containers, CI/CD, third-party integration, resilience and operational security, and convert findings into implementable remediation and architecture solutions.
- Customer-Facing Forward Deployed Engineering: Work directly with customers, application, infrastructure, DevOps and security teams from problem discovery through technical design, prototyping, implementation support, production validation and measurable security outcomes. Balance security requirements with delivery timelines, business operations and commercial practicality.
- AWS, Infrastructure & Application Security Engineering: Design and recommend AWS-native security architectures using services such as IAM, KMS, WAF, Shield, GuardDuty, Security Hub, Inspector, CloudTrail, Config, EKS, ECR and Systems Manager. Review VPC architecture, segmentation, routing, security groups, NACLs, load balancers, VPN, Direct Connect, Transit Gateway, PrivateLink, DNS and ingress/egress controls. Assess Java/Spring application risks, including framework upgrades, dependencies, middleware interaction, API compatibility and production impact.
- DevSecOps, AI & Security Automation: Support secure SDLC and DevSecOps implementation across SAST, SCA, container security, CI/CD security, secrets management and security gates. Use AI/GenAI-assisted engineering for source-code analysis, dependency analysis, vulnerability remediation, architecture review, impact assessment, testing and automation. Build prototypes, security tooling, standardized patterns and implementation accelerators for large application and infrastructure estates.
- Governance, Reuse, Measurement & Pre-Sales: Develop reusable security reference architectures, security patterns and remediation playbooks for common banking, e-commerce and AWS scenarios. Validate implemented controls through testing and operational review, measure risk reduction and remediation progress, communicate technical and business impact to stakeholders, and support pre-sales by turning security challenges into solution offerings, architecture proposals and implementation roadmaps.
Qualifications & Requirements
- Education: Bachelor’s degree or above in Computer Science, Information Security, Information Technology, Engineering or a related discipline.
- Experience: 5+ years of relevant experience in financial services, banking, fintech or payment environments. Experience in e-commerce, online retail, digital marketplaces, payment platforms or other high-volume digital businesses is also valuable. Demonstrated experience in security architecture reviews, complex vulnerability remediation and customer-facing technical solution delivery is required.
- Technical Skills: Strong knowledge of Java enterprise architecture (Java/JDK, Spring Framework, Spring Boot, Spring Security, REST APIs, Maven/Gradle and dependency management); application and API security; IAM; cryptography and data protection; AWS security architecture; VPC and hybrid networking; TCP/IP, DNS, TLS, routing, firewalls, segmentation, reverse proxies and load balancers; containers, Kubernetes/EKS, microservices, API gateways and CI/CD; DevSecOps, SAST, SCA, container security and secrets management; and practical use of AI/GenAI for engineering, security analysis or automation.
- Soft Skills: Strong customer-facing communication, architecture thinking, problem-solving and ownership. Able to work effectively in ambiguous environments, collaborate across security and engineering teams, explain complex technical risks in business terms, and balance security, delivery, operational and commercial requirements.
- Certifications (if applicable): Relevant certifications such as CISSP, CCSP, AWS Certified Solutions Architect – Professional, AWS Certified Security – Specialty, CISA or equivalent are advantageous.
- Language Requirements: Fluent professional English is required. Additional languages used in regional banking or customer engagements are an advantage.
Preferred Qualifications
- Experience with core banking, mobile banking, payment platforms or large-scale financial applications.
- Experience with e-commerce, online retail, digital marketplaces, order-management platforms, customer-facing digital platforms or high-volume transaction environments.
- Experience designing AWS security landing zones, cloud security foundations, enterprise security platforms or multi-account security architectures.
- Deep familiarity with Java/Spring-based banking, e-commerce or enterprise platforms and the security/compatibility impact of framework and library upgrades.
- Advanced AWS networking experience, including VPC, Transit Gateway, Direct Connect, PrivateLink, Route 53 and multi-account network design.
- Knowledge of OWASP ASVS/MASVS, NIST SSDF, threat modelling and secure architecture principles.
- Knowledge of AI security, AI governance, AI-assisted development and agentic security workflows.
- Experience developing security architecture governance, standards, reusable reference architectures and review processes.
- Experience in forward-deployed engineering, embedded consulting, technical solution delivery or customer-facing cybersecurity engineering.
- Experience turning customer-specific security solutions into reusable products, accelerators, reference implementations or managed services.