**The role is open for hiring in Poland, Romania, and Portugal**
About us
bolttech is an international insurtech with a mission to build the world’s leading, technology-enabled ecosystem for protection and insurance. With a full suite of digital and data-driven capabilities, bolttech powers connections between insurers, distributors, and customers to make it easier and more efficient to buy and sell insurance and protection products.
A part of Pacific Century Group, bolttech serves customers in multiple markets across North America, Asia and Europe.
In this position you will…
Own and evolve bolttech’s security architecture as the senior design authority - translating business and risk priorities into secure-by-design reference architectures, patterns and guardrails that engineering builds against by default. This is a senior, hands-on design role centred on architecture design and design feedback, not on running compliance checklists: routine control and compliance reviews are automated using AI, and only genuine design decisions, trade-offs and exceptions elevate to you. As AI becomes embedded across our infrastructure, architecture, tooling and products, you will design a resilient, defence-in-depth architecture that anticipates AI-era threats - partnering with the Group AI Security function and the wider security engineering team, while leadership holds overall accountability for the architecture practice.
You will be responsible for…
- Define, evolve and own bolttech’s target-state security architecture - reference architectures, secure-by-design patterns, “paved roads”, and security design standards across cloud, application, identity, data and infrastructure - that engineering teams adopt by default.
- Act as the senior design authority and escalation point for security architecture decisions on new initiatives, high-risk changes and major releases, applying design judgement, trade-off analysis and compensating controls rather than checklist validation.
- Lead threat modelling of systems, platforms and critical data flows - authentication and authorisation, multi-tenancy, third-party integrations, and AI/agentic components - ensuring mitigations are practical, prioritised and tracked to closure.
- Design a resilient, defence-in-depth architecture that anticipates AI-era risk - securing how AI is embedded across our infrastructure, tooling and products, including machine and non-human identities, agent tool-calling, AI control planes and the expanded blast radius of autonomous workflows - aligned to the guardrails set by the Group AI Security function.
- Champion AI-assisted automation of routine security-control and compliance-mapping reviews (framework and control validation, evidence generation, first-pass threat enumeration), and adopt DevSecOps and policy-as-code so controls are enforced in platforms and CI/CD rather than reviewed by hand - setting the policies, thresholds and guardrails this automation runs against, and validating its output.
- Define and maintain security architecture principles and standards (zero trust, least privilege, secure-by-default, defence-in-depth) and an architecture-decision and exception record, with documented trade-offs, owners and expiry dates.
- Translate incidents and emerging threats into systemic architectural improvements - closing control gaps, hardening platforms and creating new reusable reference patterns.
- Provide technical leadership, design feedback and mentoring to engineers and security specialists, and support customer-trust and assurance with architecture diagrams and control narratives, in partnership with GRC.
- Partner across the security function with clear ownership boundaries - providing the reference architectures and high-risk design decisions that Product Security applies to each product, that the AI Security function extends for AI-specific risk, that IAM operationalises for access governance, and that Cloud, Workspace and Application Security implement within their domains - while the Security Engineering & Architecture leadership holds overall accountability.
- Stay current on emerging threats, architectural approaches and AI security developments, and feed them back into bolttech’s reference architectures and security roadmap.
For you to be successful…
…we expect you to be able to demonstrate the following key competencies:
- You are passionate about secure-by-design and take pride in designing resilient systems that enable the business - taking a risk-based approach that goes beyond checkbox compliance.
- You bring strong design judgement and are comfortable in the “grey zone”, balancing security, business velocity and cost, and making and defending architecture decisions.
- You have broad and deep technical expertise across cloud, identity, application, data and network architecture - enough to set and defend patterns and earn the trust of engineering without needing to do the work yourself.
- AI fluency is central to how you work: you actively use AI-powered tools and automation to take routine control and compliance reviews off your plate and to accelerate threat modelling and design analysis, applying sound judgement to validate AI-generated output before relying on it.
- You understand how AI reshapes both the threat landscape and our own architecture, and you design for resilience as AI is embedded across our infrastructure, architecture, tooling and products.
- You work successfully with all business functions to drive adoption of new approaches and technologies, influencing cross-functional teams without relying on direct authority.
- You can build and mature an architecture practice where standards and processes may not yet exist, and you like to explore new technologies and tools to improve automation.
- You communicate complex security concepts clearly to both technical and executive audiences, and you feel the need to be involved in the decision-making process.
- You feel the need to be part of an international project, spanning multiple continents.
You will require the following qualifications and skills
- At least 10 years of experience in information security, with a deep focus on security architecture and secure-by-design.
- Strong experience defining reference architectures and security design standards at enterprise scale, and leading architecture reviews and threat modelling.
- Demonstrated expertise across IT fundamentals (systems and networks) and modern concepts - cloud, DevSecOps, containerisation, APIs, AI/ML, and secure-by-design.
- Excellent understanding of security technologies, including cloud-native tooling, firewalls, IPS, EDR, CNAPP/CSPM, SIEM and IAM.
- Strong AI fluency - a demonstrated ability to use AI-powered tools and automation to accelerate security design, threat modelling, control review and evidence generation, with the judgement to validate AI output, and a habit of continuously adopting emerging AI capabilities.
- Working understanding of securing AI and agentic systems and of AI-era architecture risk - machine and non-human identity, prompt injection, excessive agency and AI control-plane design — and awareness of AI governance frameworks such as NIST AI RMF, ISO 42001 and the EU AI Act.
- Excellent knowledge of relevant industry standards and frameworks, such as ISO 27001, SOC 2, NIST and PCI DSS.
- Certification in information security, such as CISSP, CISM or CCSP, is a plus.
- Demonstrated exceptional written and verbal English communication skills.
- Advantages:
- Awareness of designing for agentic AI and non-human identity at scale, and awareness of secure AI and ML development (MLSecOps).
- Exposure to AI-assisted security review and design tooling, and to policy-as-code and DevSecOps automation.
- Cloud security certifications such as AWS Certified Security - Specialty or Microsoft AZ-500.
- Experience building or maturing a security architecture practice across a multi-entity, international organisation.
Diversity and Inclusion
At bolttech, we are diverse and inclusive. We value each person's unique skills, background, and identity. We never discriminate on cultural background, religion, sex, gender, gender identity or expression, sexual orientation, age, disability, veteran status, genetic information, marital or family status or any legally protected status. Everyone belongs. And because everyone’s different, we’re also flexible in the ways we work, so each person can bring their best efforts every day.