Global Security Architect, Madrid
# Global Security Architect, Madrid **Infront Financial Technology** · Madrid, Madrid provincia · `On-site` 🕒 **Статус:** *Опубликовано: вчера* · *Источник: Indeed* --- ### About the Role Global Security Architect The role sits in engineering. It reports to the Head of Information Security for mandate and standards, and spends its days with the teams that build the products, in the architecture forum, in design reviews, and alongside the Security Champions it coordinates. Its measure of success is that new products and material changes are secure by design, and that the same control is not reinvented twice. Accountabilities Own the reference security patterns for Infronts products: authentication and authorisation, encryption and key handling, secrets management, logging and telemetry, and secure service-to-service communication. Publish them, keep them current, and see them adopted. Own the Secure Development Standard and the security gates in the build and deployment pipeline, including continuous scanning that covers components embedded in Infronts own software, not only what is installed on hosts. Lead threat modelling and security design review for new products and material changes, proportionate to risk, and record the outcome so it is auditable. Be the technical lead for identity architecture across the estate: the enterprise identity provider, the product authentication platform and the trading authorisation layer, including succession planning for platforms that today depend on a single person. Own security architecture for the cloud estate, across multiple AWS accounts and Azure tenants, and for the boundary between shared and isolated platform instances. Coordinate the Security Champions, one named engineer per product area, as a dotted-line community: set their agenda, give them patterns to apply, and use them to reach every team. Represent security in the architecture forum and in the Cyber Resilience Act secure-by-design work, and translate regulatory expectations into engineering decisions. Provide the application-layer input to vulnerability prioritisation and penetration test scoping, so that testing concentrates on the shared components most products depend on. What you will do in the first six months Publish the first three reference patterns, encryption, authentication and secrets, and get them adopted by at least one product team each. Enable continuous pipeline scanning for embedded components across the priority products, with a named owner for findings in each team. Produce the identity architecture and succession plan for the product authentication and authorisation platforms. Stand up the Security Champions community with a named champion in every product area and a monthly cadence. Consolidate Infronts four overlapping secure development policy drafts into one standard that engineers will actually use. Complete threat models for the five shared components on which most priority products depend. Experience and skills, essential Substantial experience designing security into software products, in a company that builds and operates its own platforms, ideally financial technology or another regulated SaaS environment. Hands-on depth in application security and secure development: threat modelling, OWASP-aligned secure coding, SAST, SCA and secrets scanning in CI/CD, and what it takes to get engineers to adopt them. Cloud security architecture across AWS and Azure, including multi-account governance, container platforms and infrastructure as code. Identity and access architecture: enterprise identity providers, single sign-on, OAuth and OIDC, and product-level authentication platforms of the Keycloak type. Cryptography applied in practice: what to use, where, and how to manage keys and certificates, rather than theory. The credibility to influence engineers without line authority, and the judgement to know when a pattern must be mandatory and when it can be guidance. Fluent English. Familiarity with DORA and the Cyber Resilience Act as they apply to a technology supplier to financial institutions. OWASP, SAST, SCA, Cloud Security AWS/Azure, OAuth, OIDC
Наблюдалась 2026-09-15, впервые 2026-09-14, источник — Indeed.