Job responsibilities
- Cultivate a security culture among product, technology, and business colleagues, prioritizing sustainable controls and real risk reduction outcomes.
- Embed security fundamentals like threat modeling, secure architecture design, and secure code review into agile product development to empower teams to ship secure products faster.
- Gain comprehensive knowledge of your product's strategy, roadmap, and key investment programs, and be self-motivated to learn unfamiliar technology components and business concepts.
- Serve as a security thought leader, sharing best practices with product and cybersecurity teams, and be recognized as the subject matter expert for IT Risk and Cyber domains.
- Act with urgency in managing emerging issues by proactively monitoring Key Risk Indicators and ensuring timely identification, communication, and management of issues.
- Collaborate across the product's supply chain, working with colleagues on audit and regulatory engagements, risk activities, and project initiatives, with a focus on effective technology risk management in Cloud computing and emerging technologies
- Leads communities of practice to drive awareness and use of new and leading-edge cybersecurity technologies
- Adds to team culture of diversity, opportunity, inclusion, and respect
Required qualifications, capabilities, and skills
- Formal training or certification on security engineering concepts and 5+ years applied experience
- Strong written and verbal communication skills
- Ability to clearly explain complex technical concepts in simple terms
- Demonstrated experience/understanding with product technologies including but not limited to
- Risk and controls working experience, specifically in application controls
- Understanding of Public Cloud computing, especially how controls are applied to secure data, ensure resiliency and availability.
- APIs, micro-services oriented architectures.
- Ability to collaborate on, and/or lead, ad hoc teams for control architecture and design
- Experience translating firm wide policy or regulatory requirements into control design and definition for Software Engineers and Solutions Architects
- Experience in building, architecting or designing secure financial services consumer businesses (i.e., Mortgages, Cards or Digital) preferred but not required
- Thinks in terms of risks and outcomes, and able to translate those into actions required to achieve business and technology goals
- Advanced knowledge of cybersecurity architecture, applications, and technical processes with considerable, in-depth knowledge in one or more technical disciplines (e.g., public cloud, artificial intelligence, machine learning, mobile, etc.)
- Ability to tackle design and functionality problems independently with little to no oversight
- Manage to evaluate current and emerging technologies to recommend the best solutions for the future state architecture.
- Proficiency in secure designing or architecting Payment HSMs and PCI , AWS cloud experience
Preferred qualifications, capabilities, and skills
- Independently tackle design and functionality problems with minimal oversight.
- Familiar with emerging technologies to recommend optimal solutions for future state architecture.