BANAMEX - Head of Security Architecture

Banamex

México

Presencial

MXN 1.200.000 - 1.900.000

Jornada completa

Hace 3 días
Sé de los primeros/as/es en solicitar esta vacante
Generador de candidaturas

Consigue una respuesta de este empleador — un currículum y una carta de presentación adaptados exactamente a lo que busca la empresa.

Supera los filtros ATS

Descripción de la vacante

Banamex is transforming into a modern, secure, cloud-first financial platform. The Security Architect will report to the CTO and serve as the architectural backbone driving secure banking across on-prem, cloud, and hybrid environments.

Lead threat modeling, Zero Trust, data security, and DevSecOps enablement while embedding compliance by design with CNBV and PCI DSS expectations. You will influence executive decisions and shape the bank's security pattern library across Mexico.

Formación

  • 10+ years in security engineering/architecture; 3+ designing enterprise systems in regulated industries (banking/fintech preferred).
  • Owned reference architectures and security patterns across cloud + on-prem.
  • Depth in identity (OAuth2/OIDC/SAML), IAM/PAM, Zero Trust, and secrets management.
  • Practical cryptography (TLS/mTLS, key mgmt, HSM/KMS), data protection, and classification.
  • DevSecOps experience integrating SAST/DAST/SCA, container/K8s security, and IaC scanning into pipelines.
  • Designed logging/telemetry for SIEM/SOAR with clear detection use cases.
  • Proven track translating regulatory requirements into automated, auditable controls.
  • Excellent documentation (C4/sequence diagrams) and executive communication.

Responsabilidades

  • Define and evolve reference architectures, guardrails for on-prem, cloud (AWS/Azure/GCP), and hybrid environments.
  • Lead architecture reviews and formal threat modeling; document risk-based decisions that stand up to audit.
  • Drive identity-centric designs (OIDC/OAuth2/SAML, MFA, PAM), workload identity, micro-segmentation, and continuous verification.
  • Standardize encryption at rest/in transit, KMS/HSM usage, tokenization, data classification, DLP, and secrets management.
  • Patterns for Kubernetes, serverless, and IaC (Terraform); adopt policy-as-code (OPA/Conftest), image signing, and runtime protections.
  • Embed SAST/DAST/IAST/SCA and IaC scanning into CI/CD; create reusable modules and golden paths developers love.
  • Architect controls for SPEI/CoDi rails, card issuing/acquiring, mobile/web apps, and open banking APIs.
  • Intake standards for third-party & SaaS; vendor architecture reviews and continuous monitoring.
  • Telemetry standards and use cases for SIEM/SOAR/EDR/NDR aligned to MITRE ATT&CK.
  • Compliance by design: map controls to CNBV/Bank of Mexico expectations, PCI DSS, ISO 27001, SOX/GLBA equivalents, FFIEC-aligned practices.
  • Executive storytelling: translate technical risk into business impact for CTO and senior leadership.

Conocimientos

Security architecture
Identity & IAM
Cryptography
DevSecOps
Threat modeling
Compliance mapping
Executive communication
Documentation

Descripción del empleo

Security Architect — Banamex

Banamex is transforming—and we’re doing it from the inside out.

We’re rebuilding one of Mexico’s most iconic banks into a modern, secure, cloud-first financial platform that moves at fintech speed but with the scale and trust of a national institution.

As our Security Architect, you’ll report directly to the CTO and become the architectural backbone of that transformation. Your mission: design the next-generation security fabric that protects millions of customers while empowering engineers to deliver faster, safer, and smarter.

You won’t be maintaining controls—you’ll be defining what secure banking looks like for the next decade. From Zero Trust architecture and DevSecOps pipelines to SPEI/CoDi payments, cloud workloads, and digital identity, you’ll embed resilience, privacy, and compliance into every product we launch.

This is a role for someone who wants to build patterns that outlive them, influence architectural decisions at the highest level, and see their work ripple across the entire Mexican financial ecosystem.

If you want to make impact—not noise—this is where it happens.

What You’ll Own
  • Target Security Architecture: Define and evolve reference architectures, control patterns, and guardrails for on-prem, cloud (AWS/Azure/GCP), and hybrid environments.
  • Design Authority: Lead architecture reviews and formal threat modeling (STRIDE/LINDDUN); document risk-based decisions that stand up to audit.
  • Zero-Trust & Identity: Drive identity-centric designs (OIDC/OAuth2/SAML, MFA, PAM), workload identity, micro-segmentation, and continuous verification.
  • Data Security: Standardize encryption at rest/in transit, KMS/HSM usage, tokenization, data classification, DLP, and secrets management.
  • Cloud & Container Security: Patterns for Kubernetes, serverless, and IaC (Terraform); adopt policy-as-code (OPA/Conftest), image signing, and runtime protections.
  • DevSecOps Enablement: Embed SAST/DAST/IAST/SCA and IaC scanning into CI/CD; create reusable modules and golden paths developers love.
  • Payments & Channels: Architect controls for SPEI/CoDi rails, card issuing/acquiring, mobile/web apps, and open banking APIs.
  • Third-Party & SaaS: Intake standards, vendor architecture reviews, compensating controls, and continuous monitoring.
  • Detection & Response Architecture: Telemetry standards and use cases for SIEM/SOAR/EDR/NDR aligned to MITRE ATT&CK.
  • Compliance by Design: Map controls and evidence to CNBV/Bank of Mexico expectations, PCI DSS, ISO 27001, SOX/GLBA equivalents, and FFIEC-aligned practices.
  • Executive Storytelling: Translate technical risk into business impact for the CTO, Architecture Board, and senior leadership.
What Makes This Opportunity Special
  • Direct impact at the top: Report to the CTO and shape bank-wide technology strategy.
  • National scale: Your patterns secure mission-critical platforms used across Mexico.
  • Modernization with purpose: Move fast with strong guardrails—security that accelerates delivery, not slows it.
  • Growth & visibility: Present to executive forums, mentor engineers, and build the bank’s security pattern library.
What You’ve Done (Required)
  • 10+ years in security engineering/architecture; 3+ designing enterprise systems in regulated industries (banking/fintech preferred).
  • Owned reference architectures and security patterns across cloud + on-prem.
  • Depth in identity (OAuth2/OIDC/SAML), IAM/PAM, Zero Trust, and secrets management.
  • Practical cryptography (TLS/mTLS, key mgmt, HSM/KMS), data protection, and classification.
  • DevSecOps experience integrating SAST/DAST/SCA, container/K8s security, and IaC scanning into pipelines.
  • Designed logging/telemetry for SIEM/SOAR with clear detection use cases.
  • Proven track translating regulatory requirements into automated, auditable controls.
  • Excellent documentation (C4/sequence diagrams) and executive communication.
Nice to have
  • Payments (SPEI/CoDi), open banking APIs, card rails, fraud-signal integration.
  • Mobile/web AppSec (OWASP ASVS/MASVS) and customer identity (CIAM).
  • Mainframe or legacy modernization security patterns.
  • Certifications: CISSP, CCSP, ISSAP, CSSLP, OSCP, AWS/Azure Security Specialty (or equivalent experience).
Job Family Group

Technology

Job Family

Digital Software Engineering

Time Type

Full time

Most Relevant Skills

Please see the requirements listed above.

Other Relevant Skills

For complementary skills, please see above and/or contact the recruiter.

Citi is an equal opportunity employer, and qualified candidates will receive consideration without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other characteristic protected by law.

If you are a person with a disability and need a reasonable accommodation to use our search tools and/or apply for a career opportunity review Accessibility at Citi.

View Citi’s EEO Policy Statement and the Know Your Rights poster.

Consigue la evaluación confidencial y gratuita de tu currículum.

o arrastra y suelta tu archivo aquí

Similar jobs

Puestos de trabajo similares que vale la pena comparar

BANAMEX - Head of Security Architecture
BANAMEX - Head of Security Architecture

Citigroup • Ciudad de México

Presencial
MXN 1.100.000 - 1.900.000
BANAMEX - Head of Security Architecture Citi · Mexico Full-time · On-site — 23 minutes ago
BANAMEX - Head of Security Architecture Citi · Mexico Full-time · On-site — 23 minutes ago

Emploive • México

A distancia
MXN 1.800.000 - 3.000.000
Banamex Cloud Architecture Lead
Banamex Cloud Architecture Lead

Citigroup Inc. • Ciudad de México

Híbrido
MXN 900.000 - 1.300.000
Security Architect — Cloud, Zero Trust & Compliance
Security Architect — Cloud, Zero Trust & Compliance

Citigroup • Ciudad de México

Presencial
MXN 1.100.000 - 1.900.000
Banamex Cloud Architecture Lead
Banamex Cloud Architecture Lead

Citigroup • Ciudad de México

Presencial
MXN 1.200.000 - 1.800.000
Cloud-First Security Architecture Leader
Cloud-First Security Architecture Leader

Banamex • México

Presencial
MXN 1.200.000 - 1.900.000
Cloud Architect
Cloud Architect

HSBC • Ciudad de México

Presencial
MXN 1.200.000 - 2.000.000
Paid leave and well-being benefits
Flexible working arrangements
Career development opportunities
Sr. Manager SRE (Individual Contributor)
Sr. Manager SRE (Individual Contributor)

capitalone • Ciudad de México

Híbrido
MXN 2.000.000 - 4.000.000
Cloud Architect
Cloud Architect

HSBC Global Services Limited • Ciudad de México

Presencial
MXN 1.800.000 - 2.400.000
Paid leave package
Senior Director, Software Engineering
Senior Director, Software Engineering

Capital One National Association • Ciudad de México

Presencial
MXN 1.800.000 - 2.400.000