BANAMEX - Head of Security Architecture

hace 2 semanas


Ciudad de México, Ciudad de México Citi A tiempo completo

Security Architect — Banamex

Banamex is transforming—and we're doing it from the inside out.

We're rebuilding one of Mexico's most iconic banks into a modern, secure, cloud-first financial platform that moves at fintech speed but with the scale and trust of a national institution.

As our Security Architect, you'll report directly to the CTO and become the architectural backbone of that transformation. Your mission: design the next-generation security fabric that protects millions of customers while empowering engineers to deliver faster, safer, and smarter.

You won't be maintaining controls—you'll be defining what secure banking looks like for the next decade. From Zero Trust architecture and DevSecOps pipelines to SPEI/CoDi payments, cloud workloads, and digital identity, you'll embed resilience, privacy, and compliance into every product we launch.

This is a role for someone who wants to build patterns that outlive them, influence architectural decisions at the highest level, and see their work ripple across the entire Mexican financial ecosystem.

If you want to make impact—not noise—this is where it happens.

What you'll own

  • Target Security Architecture: Define and evolve reference architectures, control patterns, and guardrails for on-prem, cloud (AWS/Azure/GCP), and hybrid environments.
  • Design Authority: Lead architecture reviews and formal threat modeling (STRIDE/LINDDUN); document risk-based decisions that stand up to audit.
  • Zero-Trust & Identity: Drive identity-centric designs (OIDC/OAuth2/SAML, MFA, PAM), workload identity, micro-segmentation, and continuous verification.
  • Data Security: Standardize encryption at rest/in transit, KMS/HSM usage, tokenization, data classification, DLP, and secrets management.
  • Cloud & Container Security: Patterns for Kubernetes, serverless, and IaC (Terraform); adopt policy-as-code (OPA/Conftest), image signing, and runtime protections.
  • DevSecOps Enablement: Embed SAST/DAST/IAST/SCA and IaC scanning into CI/CD; create reusable modules and golden paths developers love.
  • Payments & Channels: Architect controls for SPEI/CoDi rails, card issuing/acquiring, mobile/web apps, and open banking APIs.
  • Third-Party & SaaS: Intake standards, vendor architecture reviews, compensating controls, and continuous monitoring.
  • Detection & Response Architecture: Telemetry standards and use cases for SIEM/SOAR/EDR/NDR aligned to MITRE ATT&CK.
  • Compliance by Design: Map controls and evidence to CNBV/Bank of Mexico expectations, PCI DSS, ISO 27001, SOX/GLBA equivalents, and FFIEC-aligned practices.
  • Executive Storytelling: Translate technical risk into business impact for the CTO, Architecture Board, and senior leadership.

What makes this opportunity special

  • Direct impact at the top: Report to the CTO and shape bank-wide technology strategy.
  • National scale: Your patterns secure mission-critical platforms used across Mexico.
  • Modernization with purpose: Move fast with strong guardrails—security that accelerates delivery, not slows it.
  • Growth & visibility: Present to executive forums, mentor engineers, and build the bank's security pattern library.

What you've done (Required)

  • 10+ years in security engineering/architecture; 3+ designing enterprise systems in regulated industries (banking/fintech preferred).
  • Owned reference architectures and security patterns across cloud + on-prem.
  • Depth in identity (OAuth2/OIDC/SAML), IAM/PAM, Zero Trust, and secrets management.
  • Practical cryptography (TLS/mTLS, key mgmt, HSM/KMS), data protection, and classification.
  • DevSecOps experience integrating SAST/DAST/SCA, container/K8s security, and IaC scanning into pipelines.
  • Designed logging/telemetry for SIEM/SOAR with clear detection use cases.
  • Proven track translating regulatory requirements into automated, auditable controls.
  • Excellent documentation (C4/sequence diagrams) and executive communication.

Nice to have

  • Payments (SPEI/CoDi), open banking APIs, card rails, fraud-signal integration.
  • Mobile/web AppSec (OWASP ASVS/MASVS) and customer identity (CIAM).
  • Mainframe or legacy modernization security patterns.
  • Certifications: CISSP, CCSP, ISSAP, CSSLP, OSCP, AWS/Azure Security Specialty (or equivalent experience).

-

Job Family Group:

Technology

-

Job Family:

Digital Software Engineering

-

Time Type:

Full time

-

Most Relevant Skills

Please see the requirements listed above.

-

Other Relevant Skills

For complementary skills, please see above and/or contact the recruiter.

-

Citi is an equal opportunity employer, and qualified candidates will receive consideration without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other characteristic protected by law.

If you are a person with a disability and need a reasonable accommodation to use our search tools and/or apply for a career opportunity review Accessibility at Citi.

View Citi's EEO Policy Statement and the Know Your Rights poster.



  • Ciudad de México, Ciudad de México Capgemini A tiempo completo

    We are seeking a strategic and visionary Director of Enterprise Security and Network Architecture to define and lead the strategic direction for a broad portfolio of critical technology domains. This executive leadership role is responsible for the design, implementation, and governance of a secure, resilient, and high-performing infrastructure that includes...

  • Director of Security

    hace 1 día


    Ciudad de México, Ciudad de México Jeeves A tiempo completo

    Jeeves is a groundbreaking financial operating system built for global businesses that provides corporate cards, cross-border payments, and spend management software within one unified platform. The company operates across 20+ countries including Brazil, Canada, Colombia, Mexico, the United Kingdom, across Europe, and the United States, and serves over 5,000...


  • Ciudad de México, Ciudad de México Citi A tiempo completo

    The Digital S/W Engineer Group Mgr is accountable for management of complex/critical/large professional disciplinary areas. Leads and directs a team of professionals. Requires a comprehensive understanding of multiple areas within a function and how they interact in order to achieve the objectives of the function. Applies in-depth understanding of the...


  • Ciudad de México, Ciudad de México Citi A tiempo completo

    The Digital S/W Engineer Group Mgr is accountable for management of complex/critical/large professional disciplinary areas. Leads and directs a team of professionals. Requires a comprehensive understanding of multiple areas within a function and how they interact in order to achieve the objectives of the function. Applies in-depth understanding of the...

  • Security AI

    hace 1 día


    Ciudad de México, Ciudad de México Cognizant Technology Solutions A tiempo completo

    Job SummarySecure AI Specialist5+ years cloud security compliance or architecture ideally in enterprise MSFT environmentsResponsibilitiesProven experience advising enterprise customers on secure adoption of M365 and AI workloads (Copilot Copilot Chat Copilot Studio Ai Foundry)Deep hands-on knowledge of security governance & management on MSFT Purview MSFT...


  • Ciudad de México, Ciudad de México Diebold Nixdorf A tiempo completo

    Join our global team at Diebold Nixdorf MexicoWe are hiring aCloud Security Architectto design and implement robust security architectures in cloud environments.Ideal Profile: 4+ years in security architecture Experience withAWS/Azure, application and API security Knowledge ofPCI, GDPR, and security frameworksWhy join us? Work with global teams Excellent...

  • Head of Sales

    hace 1 día


    Ciudad de México, Ciudad de México Aviva Financiera A tiempo completo

    After raising USD 15 million in venture capital and building a network of 150+ nano-branches across Mexico, Aviva is seeking a Head of Sales to lead and develop a high-performing nationwide sales org.As Head of Sales, you will own a core pillar of Aviva's go-to-market strategy. Our sales teams are the pioneers and the human bridge" bringing premium financial...

  • Head of Operations

    hace 1 día


    Ciudad de México, Ciudad de México H&CO A tiempo completo

    The RoleThe Head of Head of Head of Operations Alternative Investments/Assets will be responsible for leading specialized operations in Mexico related to Alternative Investments/Assets trust structures and pension fund vehicles. This position will oversee the end-to-end administration of Alternative Investments/Assets mandates, ensuring compliance with...

  • Head of Recruitment

    hace 1 día


    Ciudad de México, Ciudad de México CheaperTeam A tiempo completo

    Company DescriptionCheaperTeam is a trusted offshore staffing company with over 5 years of industry experience, serving 100+ clients with a team of 400+ virtual assistants globally. Operating fully managed offices with on-site Account Managers, HR, and IT, CheaperTeam has a presence in Europe, Mexico, the Philippines, and Kenya. The company supports various...

  • Head of Content

    hace 1 día


    Ciudad de México, Ciudad de México Workana A tiempo completo

    Nuestro cliente, Energía Nutritiva, busca un/a Head of Content para liderar la estrategia, dirección y ejecución de todo el ecosistema de contenido de la marca con foco en crecimiento, conversión y performance.Este rol es transversal: conecta contenido orgánico, paid media, producción audiovisual, copy estratégico y narrativa, asegurando coherencia,...