Project & Architecture Security Senior Vice President

BBVA

New York (NY)

On-site

USD 185,000 - 200,000

Full time

6 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Discretionary bonus

Job summary

BBVA is seeking an Information Security Project Security & Architecture Specialist in New York to represent the Information Security function across the lifecycle of technology initiatives. You will ensure security requirements are defined, reviewed, implemented, and validated while guiding security architecture and regulatory compliance.

The role acts as the primary security liaison for CIB US projects, collaborating with Global Corporate Security, Technology, Product Owners, and Infrastructure

Qualifications

  • Bachelor's degree in Information Security, Computer Science, IT, Engineering, or related field.
  • 10+ years of experience in Information Security, Security Architecture, or related roles.
  • Experience reviewing cloud architectures and security controls.

Responsibilities

  • Represent the Information Security function in technology and business projects from initiation through implementation.
  • Review project designs to identify cybersecurity risks and recommend mitigating controls.
  • Ensure Information Security requirements are integrated throughout the project lifecycle.
  • Participate in project governance meetings and provide security guidance to teams.
  • Track remediation activities and validate security-related items are closed.
  • Review Security Models produced by Corporate Security Architecture.
  • Assess proposed architectures for BBVA security and US regulatory alignment.
  • Provide delegated Security Architecture and Application Security support for local initiatives.
  • Identify security gaps and recommend compensating controls.
  • Review initiatives outside standard lifecycle, including SaaS platforms and third-party solutions.
  • Validate that approved security controls are implemented as designed prior to production.

Skills

Security Architecture
Project Governance
Risk Assessment
Application Security
Infrastructure Security
Cloud Security
Regulatory Compliance
Security Controls
Stakeholder Management
Analytical Thinking
Communication & Collaboration

Education

Bachelor's degree in Information Security / related field

Tools

Azure
AWS
GCP

Job description

The Information Security Project Security & Architecture Specialist is responsible for representing the Information Security function throughout the lifecycle of technology initiatives across BBVA CIB US. The role ensures that security requirements are appropriately defined, reviewed, implemented, and validated, while providing security architecture guidance and supporting compliance with Corporate Security standards and U.S. regulatory expectations.

This position serves as the primary Information Security liaison for CIB US projects, working closely with Global (Head Office) Corporate Security teams (Security Architecture), Technology, Product Owners, Tech Leads, Infrastructure, Application Development, and Business Units to reduce technology risk and ensure secure implementation of business initiatives.

As BBVA CIB US expands its technology landscape, this role ensures security is embedded in project delivery. It provides project security oversight and architecture support, strengthening governance, reducing risk, improving regulatory compliance, and enabling the Information Security team to focus on strategic initiatives while maintaining effective coverage across the portfolio.

Key Responsibilities
  • Represent the Information Security function in technology and business projects from initiation through implementation.
  • Review project designs to identify cybersecurity risks and recommend appropriate mitigating controls.
  • Ensure Information Security requirements are incorporated throughout the project lifecycle.
  • Participate in project governance meetings and provide security guidance to project teams.
  • Track remediation activities and validate completion of security-related action items.
  • Review Security Models produced by Corporate Security Architecture.
  • Assess proposed architectures for alignment with BBVA security standards and U.S. regulatory requirements.
  • Provide delegated Security Architecture and Application Security support for local initiatives.
  • Identify security gaps and recommend compensating controls where appropriate.
  • Review initiatives that may fall outside the standard lifecycle process, including third-party platforms, trading venues, and standalone SaaS solutions.
  • Validate that approved security controls are implemented as designed prior to production deployment.
  • Collaborate closely with the First Line of Defense (Risk Control Assurance) to ensure project and solution compliance with the Mitigation Control Frameworks, including validation of control adherence and effectiveness.
  • Coordinate security verification activities with infrastructure, networking, cloud, and application teams.
  • Review implementation evidence and document compliance with approved security models.
  • Serve as the primary security advisor for assigned projects.
  • Collaborate with Corporate Security Architecture, Enterprise Architecture, Technology Engineering, Application Development, Infrastructure, Risk, Compliance, and business stakeholders.
  • Support Information Security initiatives related to AI security, cloud security, and third-party risk management.
Qualifications and Experience
  • Bachelor's degree in Information Security, Computer Science, Information Technology, Engineering, or related field (or equivalent experience).
  • 10+ years of experience in Information Security, Security Architecture, Application Security, Infrastructure Security, or Cybersecurity Engineering.
  • Experience participating in technology projects and implementing security controls.
  • Strong understanding of network security, cloud security, identity and access management, application security, and infrastructure security.
  • Experience performing security risk assessments and architecture reviews.
  • Familiarity with financial services security requirements and regulatory expectations.
  • Excellent written and verbal communication skills.
  • Ability to influence cross-functional teams without direct authority.
  • Experience in banking or financial services.
  • Knowledge of cybersecurity and regulatory frameworks including NIST Cybersecurity Framework (NIST CSF), NIST 800-53, ISO 27001, CIS Controls, New York DFS Cybersecurity Regulation (23 NYCRR Part 500), SEC cybersecurity requirements, NFA cybersecurity requirements, FFIEC Guidelines, EU DORA (Digital Operational Resilience Act), SWIFT Customer Security Controls Framework (CSCF), FedLine security requirements, CHIPS-related security requirements, and CRI Profile, or similar frameworks.
  • Experience reviewing cloud architectures (Azure, AWS, or GCP).
  • Knowledge of AI security, third-party risk, and secure software development practices.
  • Professional certifications such as CISSP, CCSP, GCSA, CCSK, CSSLP, SANS certifications (GWEB) and others.
  • Strong competencies in Security Architecture, Project Security Governance, Risk Assessment, Application Security, Infrastructure Security, Cloud Security, Regulatory Compliance, Security Control Validation, Stakeholder Management, Analytical Thinking, Problem Solving, and Communication & Collaboration
  • Spanish proficiency is a plus

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

With respect to this position in our New York Office, the expected base salary ranges from $185,000 to $200,000. It is not typical for offers to be made at or near the top of the range. Salary offers are based on a wide range of factors including relevant skills, training, experience, education, and, where applicable, certifications obtained. Market and organizational factors are also considered. In addition to salary and a generous employee benefits package, successful candidates are eligible to receive a discretionary bonus.

*Employment eligibility to work with BBVA in the U.S. is required as the company will not pursue visa sponsorship for these positions

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cybersecurity Regulatory Senior Vice President
Cybersecurity Regulatory Senior Vice President

BBVA • New York (NY)

On-site
USD 185,000 - 200,000
Senior VP, Project Security & Architecture
Senior VP, Project Security & Architecture

BBVA • New York (NY)

On-site
USD 185,000 - 200,000
Discretionary bonus
Cybersecurity Regulatory Lead
Cybersecurity Regulatory Lead

Bbva Sa • New York (NY)

On-site
USD 185,000 - 200,000
Project Finance Analyst
Project Finance Analyst

BBVA • New York (NY)

On-site
USD 100,000 - 110,000
Generous employee benefits package
Discretionary bonus
Senior Enterprise Infrastructure Engineer
Senior Enterprise Infrastructure Engineer

BBVA • New York (NY)

On-site
USD 180,000 - 195,000
Generous employee benefits package
Discretionary bonus eligibility
Executive Director, Head of Client Service US
Executive Director, Head of Client Service US

Socket.dev • New York (NY)

On-site
USD 185,000 - 225,000
Executive Director, Securitization Portfolio Management
Executive Director, Securitization Portfolio Management

Bbva Sa • New York (NY), Northern (KY)

Hybrid
USD 275,000 - 300,000
AI Process Manager
AI Process Manager

BBVA • New York (NY)

On-site
USD 130,000 - 140,000
Counterparty Credit Risk FIG Insurance SVP
Counterparty Credit Risk FIG Insurance SVP

bbva • New York (NY)

On-site
USD 160,000 - 220,000
Discretionary bonus
Generous benefits package
Client Coverage Senior Analyst
Client Coverage Senior Analyst

Bbva Sa • New York (NY)

On-site
USD 90,000 - 130,000