1 day ago
Mexico City, MexicoStaff+
Responsibilities
- Define and evolve security reference architectures, control patterns, and guardrails for on-premises, cloud, and hybrid environments.
- Lead architecture reviews, formal STRIDE and LINDDUN threat modeling, and risk-based architectural decisions.
- Drive Zero Trust, identity-centric design, OIDC/OAuth2/SAML, MFA, PAM, workload identity, micro-segmentation, and continuous verification.
- Standardize encryption, KMS/HSM usage, tokenization, data classification, DLP, and secrets management.
- Develop security patterns for Kubernetes, serverless systems, Terraform, policy-as-code, image signing, and runtime protection.
- Embed SAST, DAST, IAST, SCA, and infrastructure-as-code scanning into CI/CD pipelines and create reusable developer modules and golden paths.
- Architect security controls for SPEI/CoDi, card issuing and acquiring, mobile and web applications, and open banking APIs.
- Establish third-party and SaaS intake standards, vendor architecture reviews, compensating controls, and continuous monitoring.
- Design telemetry and detection use cases for SIEM, SOAR, EDR, and NDR aligned to MITRE ATT&CK.
- Map security controls and evidence to CNBV, Bank of Mexico, PCI DSS, ISO 27001, SOX/GLBA, and FFIEC-aligned requirements.
- Translate technical risk into business impact for the CTO, Architecture Board, and senior leadership; present to executive forums and mentor engineers.
Requirements
- 10+ years of experience in security engineering or architecture, including 3+ years designing enterprise systems in regulated industries.
- Experience owning reference architectures and security patterns across cloud and on-premises environments.
- Deep expertise in OAuth2/OIDC/SAML, IAM/PAM, Zero Trust, and secrets management.
- Practical cryptography and data-protection experience, including TLS/mTLS, key management, HSM/KMS, and data classification.
- Experience integrating SAST, DAST, SCA, container/Kubernetes security, and infrastructure-as-code scanning into pipelines.
- Experience designing logging and telemetry for SIEM/SOAR with clear detection use cases.
- Demonstrated ability to translate regulatory requirements into automated, auditable controls.
- Strong documentation skills, including C4 and sequence diagrams, and excellent executive communication.
- Preferred experience with SPEI/CoDi, open banking APIs, card rails, fraud-signal integration, mobile and web application security, customer identity, and mainframe or legacy modernization security patterns.
- Preferred certifications include CISSP, CCSP, ISSAP, CSSLP, OSCP, AWS Security Specialty, or Azure Security Specialty, or equivalent experience.
Benefits
- Full-time role reporting directly to the CTO with bank-wide technology-strategy influence.
- Opportunity to secure mission-critical platforms used across Mexico and present to executive forums.
- Opportunity to mentor engineers and build Banamex’s security pattern library.
Categories
About Citi
Citi is a public financial-services company offering consumer and institutional banking, credit cards, wealth management, treasury and trade solutions, and capital-markets services. It serves individuals, corporations, financial institutions, and governments in more than 160 countries and jurisdictions, earning interest and fee income from lending, payments, trading, and advisory. Founded in 1812 and headquartered in New York, it trades on the NYSE under the ticker C.
