Banamex - Head of Security Architecture
hace 6 días
**Security Architect — Banamex**
Banamex is transforming—and we’re doing it from the inside out.
We’re rebuilding one of Mexico’s most iconic banks into a **modern, secure, cloud-first financial platform** that moves at fintech speed but with the scale and trust of a national institution.
As our **Security Architect**, you’ll report directly to the **CTO** and become the **architectural backbone** of that transformation. Your mission: design the next-generation security fabric that protects millions of customers while empowering engineers to deliver faster, safer, and smarter.
You won’t be maintaining controls—you’ll be **defining what secure banking looks like for the next decade**. From **Zero Trust architecture and DevSecOps pipelines** to **SPEI/CoDi payments, cloud workloads, and digital identity**, you’ll embed resilience, privacy, and compliance into every product we launch.
This is a role for someone who wants to **build patterns that outlive them**, influence architectural decisions at the highest level, and see their work ripple across the entire Mexican financial ecosystem.
If you want to make impact—not noise—this is where it happens.
**What you’ll own**
- **Target Security Architecture**: Define and evolve reference architectures, control patterns, and guardrails for on-prem, cloud (AWS/Azure/GCP), and hybrid environments.
- **Design Authority**: Lead architecture reviews and formal threat modeling (STRIDE/LINDDUN); document risk-based decisions that stand up to audit.
- **Zero-Trust & Identity**: Drive identity-centric designs (OIDC/OAuth2/SAML, MFA, PAM), workload identity, micro-segmentation, and continuous verification.
- **Data Security**: Standardize encryption at rest/in transit, KMS/HSM usage, tokenization, data classification, DLP, and secrets management.
- **Cloud & Container Security**: Patterns for Kubernetes, serverless, and IaC (Terraform); adopt policy-as-code (OPA/Conftest), image signing, and runtime protections.
- **DevSecOps Enablement**: Embed SAST/DAST/IAST/SCA and IaC scanning into CI/CD; create reusable modules and golden paths developers love.
- **Payments & Channels**: Architect controls for SPEI/CoDi rails, card issuing/acquiring, mobile/web apps, and open banking APIs.
- **Third-Party & SaaS**: Intake standards, vendor architecture reviews, compensating controls, and continuous monitoring.
- **Detection & Response Architecture**: Telemetry standards and use cases for SIEM/SOAR/EDR/NDR aligned to MITRE ATT&CK.
- **Compliance by Design**: Map controls and evidence to CNBV/Bank of Mexico expectations, PCI DSS, ISO 27001, SOX/GLBA equivalents, and FFIEC-aligned practices.
- **Executive Storytelling**: Translate technical risk into business impact for the CTO, Architecture Board, and senior leadership.
**What makes this opportunity special**
- **Direct impact at the top**: Report to the CTO and shape bank-wide technology strategy.
- **National scale**: Your patterns secure mission-critical platforms used across Mexico.
- **Modernization with purpose**: Move fast with strong guardrails—security that accelerates delivery, not slows it.
- **Growth & visibility**: Present to executive forums, mentor engineers, and build the bank’s security pattern library.
**What you’ve done (required)**
- 10+ years in security engineering/architecture; 3+ designing enterprise systems in regulated industries (banking/fintech preferred).
- Owned reference architectures and security patterns across cloud + on-prem.
- Depth in identity (OAuth2/OIDC/SAML), IAM/PAM, Zero Trust, and secrets management.
- Practical cryptography (TLS/mTLS, key mgmt, HSM/KMS), data protection, and classification.
- DevSecOps experience integrating SAST/DAST/SCA, container/K8s security, and IaC scanning into pipelines.
- Designed logging/telemetry for SIEM/SOAR with clear detection use cases.
- Proven track translating regulatory requirements into automated, auditable controls.
- Excellent documentation (C4/sequence diagrams) and executive communication.
**Nice to have**
- Payments (SPEI/CoDi), open banking APIs, card rails, fraud-signal integration.
- Mobile/web AppSec (OWASP ASVS/MASVS) and customer identity (CIAM).
- Mainframe or legacy modernization security patterns.
- Certifications: CISSP, CCSP, ISSAP, CSSLP, OSCP, AWS/Azure Security Specialty (or equivalent experience).**Job Family Group**:
Technology
- **Job Family**:
Digital Software Engineering
- **Time Type**:
Full time
- **Most Relevant Skills**
Please see the requirements listed above.
- **Other Relevant Skills**
For complementary skills, please see above and/or contact the recruiter.-
- View Citi’s _EEO Policy Statement_ and the _Know Your Rights_ poster._
-
BANAMEX - Head of Security Architecture
hace 4 horas
Ciudad de México PowerToFly A tiempo completoOverview Security Architect — Banamex Banamex is transforming—and we’re doing it from the inside out. We’re rebuilding one of Mexico’s most iconic banks into a modern, secure, cloud-first financial platform that moves at fintech speed but with the scale and trust of a national institution. As our Security Architect, you’ll report directly to the...
-
Banamex Head of Digital Engineering
hace 2 semanas
Ciudad de México Citi A tiempo completoWe are seeking a dynamic and experienced Head of Digital Engineering to lead a team of developers and engineers in driving the digital transformation of our bank. As Head of Digital Engineering, you will be responsible for the development and implementation of our digital engineering strategy, as well as overseeing the day-to-day operations of our digital...
-
Head of Ai
hace 4 semanas
Ciudad de México HireHawk A tiempo completo**Overview**:**Job Title**: Head of AI & Solutions Architecture**Job Type**: Full-time contractor**Workplace**: Remote**Schedule**: Monday-Friday, 8:00 AM - 5:00 PM EST**Compensation**: USD $3,000 - $7,000/month**About HireHawk**:**About the Job**:We are hiring a Head of AI & Solutions Architecture to lead a small team of AI Engineers while staying hands-on...
-
Security Head
hace 1 semana
Ciudad de México Novo Nordisk A tiempo completoSecurity Head **Category**:Digital & IT **Location**:Ciudad de México, Ciudad de México, MX **The Position** - As the Head of Security, you will: - Implement and maintain end-to-end product and supply chain security measures, including incident investigations and risk assessments.- - Monitor and combat illicit pharmaceutical activities by supporting...
-
Director,security Architecture
hace 4 semanas
Edo. de México Syneos Health Clinical A tiempo completo**Description****JOB SUMMARY**:**JOB RESPONSIBILITIES**:- Defines, develops, and leads engagement models and frameworks for technical, process, resource, and operational security considerations for solutions at all points of solution development lifecycle- Manages technical security consultancy, including providing design criteria, review and approval-...
-
Security Architect
hace 4 semanas
Ciudad de México Tekcogno A tiempo completo**Security Arcitect****Location**:05349, Av. Santa Fe 495, Cruz Manca, Cuajimalpa de Morelos, 05349 CDMX, Mexico**This role leads **Security Solution Architecture** engagements by designing control implementations from consumption through deployment. It also participates in **Enterprise Security Architecture activities**, including formal security reviews as...
-
Banamex Tactical
hace 2 semanas
Ciudad de México Citi A tiempo completoThe Intelligence Lead Analyst is a senior level professional responsible for driving efforts to prevent, monitor and respond to information/data breaches and cyber-attacks. The overall objective of this role is to ensure the execution of Information Security directives and activities in alignment with Citi's data security policy. **Responsibilities**: -...
-
Head of Procurement
hace 3 semanas
Ciudad de México Ultimate Solar Advanced Technology A tiempo completo**Position**: Head of Procurement**Location**: Mexico City / Puebla**Type of job**:Full time / presential.**Position Objective**The Head of Procurement will lead and manage the end-to-end procurement processes to ensure the efficient and cost-effective sourcing of materials and services essential for the development and execution of solar energy projects....
-
Banamex Senior Application Security Architect
hace 6 días
Ciudad de México Citi A tiempo completoThe Information Security Operations (ISO) Sr Manager is a senior management level position responsible for accomplishing results through the management of a team or department in an effort to prevent, monitor and respond to information/data breaches and cyber-attacks. The overall objective of this role is to ensure the execution of Information Security...
-
Head of Technology
hace 4 semanas
Ciudad de México TOSI A tiempo completoDescripción de la Compañia TOSI es una empresa legaltech enfocada en la creación de valor para las operaciones de las empresas y abogados independientes mediante un ecosistema de fiabilidad digital que sirva como eje articulador entre el derecho y la tecnología. Nuestra solución se basa en criptografía asimétrica y blockchain para crear evidencias con...