×
Register Here to Apply for Jobs or Post Jobs. X

Head of Security Architecture and Engineering - CISO function - BPL

Job in Greater London, London, Greater London, W1B, England, UK
Listing for: Barclays
Full Time position
Listed on 2026-06-12
Job specializations:
  • IT/Tech
    Cybersecurity, Systems Engineer, Security Manager, Network Security
Salary/Wage Range or Industry Benchmark: 150000 - 200000 GBP Yearly GBP 150000.00 200000.00 YEAR
Job Description & How to Apply Below
Location: Greater London

The Head of Security Architecture and Engineering leads the pillar responsible for designing and building the security foundations of the cloud-native platform. This role owns the security reference architecture, cloud security posture, identity and access management strategy, data security (including tokenisation and encryption), and the technical standards that the entire engineering organisation builds upon. The pillar operates as an internal platform team: it publishes self‑service security capabilities, automated guardrails, and hardened defaults that enable product teams to build securely by default without needing deep security expertise for every design decision.

The ideal candidate is a technically deep security leader who can set architectural direction, make pragmatic engineering trade‑offs, and build a team that earns the trust and respect of platform and product engineers. This is the most technically demanding leadership role in the CISO function. You will be expected to have credible opinions on cloud security architecture, cryptographic implementation, identity federation, container security, and zero‑trust design — and to translate those opinions into practical, adoptable standards and services.

Key Responsibilities
  • Define and own the security reference architecture for the cloud‑native platform, including network security patterns, identity and authentication, encryption, logging, and inter‑service communication security.
  • Own the cloud security posture management (CSPM) strategy, ensuring continuous monitoring and automated enforcement of security policies across the entire cloud estate.
  • Set and maintain security technical standards, including approved technologies, cryptographic algorithms, authentication protocols, and secure design patterns for microservices.
  • Lead the identity and access management strategy, including privileged access management (PAM), service identity (workload identity, service accounts), RBAC models, and zero‑trust architecture principles.
  • Own the data security strategy, including cardholder data tokenisation, encryption key management (HSM/KMS), data classification, and data loss prevention implementation.
  • Chair the Security Architecture Board, reviewing architecture proposals, approving non‑standard patterns, updating standards, and maintaining a decision log.
  • Ensure security guardrails are implemented as automated policies (infrastructure‑as‑code, OPA/Rego, CSPM rules) that scale with the platform and enforce security without manual intervention.
  • Publish self‑service security capabilities for engineering teams: secure base images, IaC security modules, encryption libraries, IAM templates, and approved architecture blueprints.
  • Collaborate closely with Platform Engineering to embed security into the platform layer, ensuring security is a property of the infrastructure, not an afterthought applied on top.
  • Advise the CISO on technical security strategy, emerging technology risks, and the security implications of architectural decisions.
  • Support PCI DSS compliance from an architectural perspective, ensuring the platform design supports scope minimisation, network segmentation, and the technical requirements of PCI DSS 4.0.
  • Manage and develop the Security Architecture and Engineering team of five, building deep technical capability across cloud security, identity, cryptography, and architecture.
Key Deliverables
  • Security reference architecture document, covering cloud, network, identity, data, and application layers — reviewed and updated bi‑annually.
  • Cloud security policy‑as‑code library (OPA/Rego, Terraform Sentinel, or cloud‑native equivalents) integrated into deployment pipelines.
  • IAM strategy and RBAC model documentation, including privileged access management implementation and zero‑trust roadmap.
  • Data security and encryption standards document, including approved algorithms, key management procedures, and tokenisation architecture.
  • Technology security standards catalogue (approved languages, frameworks, libraries, protocols, and configurations).
  • Secure design pattern library (“paved road” patterns for common scenarios: API authentication, inter‑service…
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary