Security Architecture and Application Security Senior Manager
Job Description
BBVA CIB US is seeking a hands-on Security Architecture and Application Security Senior Manager to lead security across complex technology initiatives in New York.
Key responsibilities
- Conduct security architecture reviews and threat modeling for applications, APIs, cloud services, infrastructure, and third-party solutions.
- Assess architecture patterns across authentication and authorization, IAM, encryption, secrets and key management, APIs, network segmentation, data protection, cloud security, and secure integration patterns.
- Verify that approved architecture and security controls are implemented as designed prior to production deployment.
- Lead security workstreams for multiple concurrent technology initiatives by defining security deliverables, dependencies, priorities, and milestones and driving execution to completion.
- Manage a portfolio of security engagements simultaneously, prioritizing based on business criticality, architecture complexity, security risk, and delivery timelines.
- Identify early security-related project risks and dependencies; escalate blockers as needed and prevent security activities from becoming late-stage delivery impediments.
- Participate in project governance meetings and provide security guidance to project teams.
- Review Security Models produced by Corporate Security Architecture.
- Evaluate proposed architectures for alignment with BBVA security standards and U.S. regulatory requirements.
- Provide delegated Security Architecture and Application Security support for local initiatives.
- Identify security gaps and recommend compensating controls when appropriate.
- Review initiatives outside standard lifecycle processes, including third-party platforms, trading venues, and standalone SaaS solutions.
- Serve as the primary security advisor for assigned projects.
- Partner with Corporate Security Architecture, Enterprise Architecture, Technology Engineering, Application Development, Infrastructure, Risk, Compliance, and business stakeholders.
Requirements
- Bachelor’s degree in Information Security, Computer Science, Information Technology, Engineering, or a related field, or equivalent experience.
- 10+ years of experience in Information Security, Security Architecture, Application Security, Infrastructure Security, or Cybersecurity Engineering.
- Experience participating in technology projects and implementing security controls.
- Strong understanding of network security, cloud security, identity and access management, application security, and infrastructure security.
- Experience performing security risk assessments and architecture reviews.
- Familiarity with financial services security requirements and regulatory expectations.
- Excellent written and verbal communication skills.
- Ability to influence cross-functional teams without direct authority.
- Experience in banking or financial services.
- Knowledge of cybersecurity and regulatory frameworks including:
- NIST Cybersecurity Framework (NIST CSF)
- NIST 800-53
- ISO 27001
- CIS Controls
- New York DFS Cybersecurity Regulation (23 NYCRR Part 500)
- SEC cybersecurity requirements
- NFA cybersecurity requirements
- FFIEC Guidelines
- EU DORA (Digital Operational Resilience Act)
- SWIFT Customer Security Controls Framework (CSCF)
- FedLine security requirements
- CHIPS-related security requirements
- CRI Profile
- or similar frameworks
- Experience reviewing cloud architectures (Azure, AWS, or GCP).
- Knowledge of AI security, third-party risk, and secure software development practices.
- Professional certifications such as CISSP, CCSP, GCSA, CCSK, CSSLP, SANS certifications (GWEB), and others.
- Strong competencies in Security Architecture, Project Security Governance, Risk Assessment, Application Security, Infrastructure Security, Cloud Security, Regulatory Compliance, Security Control Validation, Stakeholder Management, Analytical Thinking, Problem Solving, and Communication & Collaboration.
- Spanish proficiency is a plus.
Technologies and frameworks
- Azure, AWS, GCP
- NIST Cybersecurity Framework (NIST CSF), NIST 800-53
- ISO 27001
- CIS Controls
- New York DFS Cybersecurity Regulation (23 NYCRR Part 500)
- SEC cybersecurity requirements, NFA cybersecurity requirements, FFIEC Guidelines
- EU DORA (Digital Operational Resilience Act)
- SWIFT Customer Security Controls Framework (CSCF)
- FedLine security requirements
- CHIPS-related security requirements, CRI Profile
- CISSP, CCSP, GCSA, CCSK, CSSLP, SANS certifications (GWEB)
Location: New York, NY (onsite)
Compensation: USD 185,000 - 200,000 per year
Experience: 10+ years
Similar Jobs
A
B