CybersecurityJobs.io
← Back to all jobs

Job Description

BBVA CIB US is seeking a hands-on Security Architecture and Application Security Senior Manager to lead security across complex technology initiatives in New York.

Key responsibilities

  • Conduct security architecture reviews and threat modeling for applications, APIs, cloud services, infrastructure, and third-party solutions.
  • Assess architecture patterns across authentication and authorization, IAM, encryption, secrets and key management, APIs, network segmentation, data protection, cloud security, and secure integration patterns.
  • Verify that approved architecture and security controls are implemented as designed prior to production deployment.
  • Lead security workstreams for multiple concurrent technology initiatives by defining security deliverables, dependencies, priorities, and milestones and driving execution to completion.
  • Manage a portfolio of security engagements simultaneously, prioritizing based on business criticality, architecture complexity, security risk, and delivery timelines.
  • Identify early security-related project risks and dependencies; escalate blockers as needed and prevent security activities from becoming late-stage delivery impediments.
  • Participate in project governance meetings and provide security guidance to project teams.
  • Review Security Models produced by Corporate Security Architecture.
  • Evaluate proposed architectures for alignment with BBVA security standards and U.S. regulatory requirements.
  • Provide delegated Security Architecture and Application Security support for local initiatives.
  • Identify security gaps and recommend compensating controls when appropriate.
  • Review initiatives outside standard lifecycle processes, including third-party platforms, trading venues, and standalone SaaS solutions.
  • Serve as the primary security advisor for assigned projects.
  • Partner with Corporate Security Architecture, Enterprise Architecture, Technology Engineering, Application Development, Infrastructure, Risk, Compliance, and business stakeholders.

Requirements

  • Bachelor’s degree in Information Security, Computer Science, Information Technology, Engineering, or a related field, or equivalent experience.
  • 10+ years of experience in Information Security, Security Architecture, Application Security, Infrastructure Security, or Cybersecurity Engineering.
  • Experience participating in technology projects and implementing security controls.
  • Strong understanding of network security, cloud security, identity and access management, application security, and infrastructure security.
  • Experience performing security risk assessments and architecture reviews.
  • Familiarity with financial services security requirements and regulatory expectations.
  • Excellent written and verbal communication skills.
  • Ability to influence cross-functional teams without direct authority.
  • Experience in banking or financial services.
  • Knowledge of cybersecurity and regulatory frameworks including:
    • NIST Cybersecurity Framework (NIST CSF)
    • NIST 800-53
    • ISO 27001
    • CIS Controls
    • New York DFS Cybersecurity Regulation (23 NYCRR Part 500)
    • SEC cybersecurity requirements
    • NFA cybersecurity requirements
    • FFIEC Guidelines
    • EU DORA (Digital Operational Resilience Act)
    • SWIFT Customer Security Controls Framework (CSCF)
    • FedLine security requirements
    • CHIPS-related security requirements
    • CRI Profile
    • or similar frameworks
  • Experience reviewing cloud architectures (Azure, AWS, or GCP).
  • Knowledge of AI security, third-party risk, and secure software development practices.
  • Professional certifications such as CISSP, CCSP, GCSA, CCSK, CSSLP, SANS certifications (GWEB), and others.
  • Strong competencies in Security Architecture, Project Security Governance, Risk Assessment, Application Security, Infrastructure Security, Cloud Security, Regulatory Compliance, Security Control Validation, Stakeholder Management, Analytical Thinking, Problem Solving, and Communication & Collaboration.
  • Spanish proficiency is a plus.

Technologies and frameworks

  • Azure, AWS, GCP
  • NIST Cybersecurity Framework (NIST CSF), NIST 800-53
  • ISO 27001
  • CIS Controls
  • New York DFS Cybersecurity Regulation (23 NYCRR Part 500)
  • SEC cybersecurity requirements, NFA cybersecurity requirements, FFIEC Guidelines
  • EU DORA (Digital Operational Resilience Act)
  • SWIFT Customer Security Controls Framework (CSCF)
  • FedLine security requirements
  • CHIPS-related security requirements, CRI Profile
  • CISSP, CCSP, GCSA, CCSK, CSSLP, SANS certifications (GWEB)

Location: New York, NY (onsite)

Compensation: USD 185,000 - 200,000 per year

Experience: 10+ years

Similar Jobs