Back to jobs
New

Global Security Architect

Madrid

At Infront, we help major banks and independent wealth and asset managers make faster, smarter, compliant investment decisions. For decades, we have been at the heart of Europe’s financial services infrastructure, providing financial data and investment tools, from intelligent data feeds to wealth management platforms and trading solutions, and empowering over ninety thousand professionals to navigate complex markets with confidence.

We build technology, but our people power us. We foster an inclusive workplace where diverse perspectives drive innovation and results, guided by our shared values of engagement, communication and recognition. Together, we collaborate, commit to innovation and shape the future of our industry, building a culture of trust, transparency and enjoyment.

Purpose of the role

Infront builds and operates financial technology products for banks and asset managers across thirteen countries, on a technology estate that has grown by acquisition. Today, security is built in product by product: encryption, authentication, secrets handling and logging are solved differently in each, by whoever built it. The Global Security Architect owns how security is designed into Infront's products, replacing that patchwork with shared patterns the teams can adopt and reuse.

The role sits in engineering and reports to the Head of Information Security for mandate and standards. It spends its days with the teams that build the products, in the architecture forum, in design reviews, and alongside the Security Champions it coordinates. Success means new products and material changes are secure by design from the start.

Accountabilities

  • Own the reference security patterns for Infront's products: authentication and authorisation, encryption and key handling, secrets management, logging and telemetry, and secure service-to-service communication. Publish them, keep them current, and see them adopted.
  • Own the Secure Development Standard and the security gates in the build and deployment pipeline, including continuous scanning that covers components embedded in Infront's own software, not only what is installed on hosts.
  • Lead threat modelling and security design review for new products and material changes, proportionate to risk, and record the outcome so it is auditable.
  • Be the technical lead for identity architecture across the estate: the enterprise identity provider, the product authentication platform and the trading authorisation layer, including succession planning for platforms that today depend on a single person.
  • Own security architecture for the cloud estate, across multiple AWS accounts and Azure tenants, and for the boundary between shared and isolated platform instances.
  • Coordinate the Security Champions, one named engineer per product area, as a dotted-line community: set their agenda, give them patterns to apply, and use them to reach every team.
  • Represent security in the architecture forum and in the Cyber Resilience Act secure-by-design work, and translate regulatory expectations into engineering decisions.
  • Provide the application-layer input to vulnerability prioritisation and penetration test scoping, so that testing concentrates on the shared components most products depend on.

What you will do in the first six months

  • Publish the first three reference patterns, encryption, authentication and secrets, and get them adopted by at least one product team each.
  • Enable continuous pipeline scanning for embedded components across the priority products, with a named owner for findings in each team.
  • Produce the identity architecture and succession plan for the product authentication and authorisation platforms.
  • Stand up the Security Champions community with a named champion in every product area and a monthly cadence.
  • Consolidate Infront's four overlapping secure development policy drafts into one standard that engineers will actually use.
  • Complete threat models for the five shared components on which most priority products depend.

Experience and skills, essential

  • Substantial experience designing security into software products, in a company that builds and operates its own platforms, ideally financial technology or another regulated SaaS environment.
  • Hands-on depth in application security and secure development: threat modelling, OWASP-aligned secure coding, SAST, SCA and secrets scanning in CI/CD, and what it takes to get engineers to adopt them.
  • Cloud security architecture across AWS and Azure, including multi-account governance, container platforms and infrastructure as code.
  • Identity and access architecture: enterprise identity providers, single sign-on, OAuth and OIDC, and product-level authentication platforms of the Keycloak type.
  • Cryptography applied in practice: what to use, where, and how to manage keys and certificates, rather than theory.
  • The credibility to influence engineers without line authority, and the judgement to know when a pattern must be mandatory and when it can be guidance.
  • Fluent English is a must.

Experience and skills, valued

  • Experience in a group grown by acquisition, where the same problem has been solved several ways and the job is to converge them.
  • Familiarity with DORA and the Cyber Resilience Act as they apply to a technology supplier to financial institutions.
  • Kubernetes and Kafka security in mixed shared and isolated deployments.
  • Building or running a Security Champions programme.
  • Norwegian, German, French, Italian or Spanish.

How you work

  • You would rather ship a pattern that three teams adopt than a document that all of them ignore.
  • You explain a security decision in terms an engineer can act on and a product owner can prioritise.
  • You are comfortable being the only security person in a room full of developers, and you make that a strength.
  • You know the difference between a control that must be enforced and one that should be made easy, and you build accordingly.

What this role is not

  • Not a governance or policy role. The Head of Information Security owns policy, risk and reporting; this role owns how security is built.
  • Not an operations role. Endpoints, patching, provisioning and monitoring are run by ITIO and the managed detection provider; the Security Engineer configures them.
  • Not a line manager of engineers. The Security Champions report to their product teams; this role leads them by pattern and agenda.

Our offer

While our benefits may vary depending on your location, they typically include:

Health & wellness: Benefit from wellbeing initiatives tailored to local needs, including access to an employee assistance programme that provides confidential support to employees and their families.
Holiday: Enjoy competitive holiday entitlement aligned with local markets, so you can rest and recharge.
Remote work: Enjoy the flexibility to work part of your week from home, with flexible working hours where possible. You may also request to work up to four weeks per year from a different location.
Learning & development: Support your career progression with access to learning resources, ongoing conversations with your manager, and opportunities to share the knowledge you gain with your team.
Culture & impact: Be part of an international team with a startup mindset and play a key role in making a meaningful impact.
Our offices: Work from Europe’s leading financial centres and be at the heart of where finance happens.

Additional notes

  • All candidates selected for employment are subject to Pre-Employment Screening. This process includes professional reference and background checks conducted by our third-party partner, ZINC. These screenings are part of our commitment to ensuring a secure, compliant, and trustworthy workplace.
  • Since your application will be reviewed by an international team, we kindly ask that you submit your CV in English.
  • Please note that visa sponsorship is not available for this position, and applicants should have the right to work in the hiring location.

Create a Job Alert

Interested in building your career at Infront? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Education

Select...

Select...
Select...
Select...
Select...
Select...