At a Glance
- Tasks: Support technology change initiatives by identifying security risks and applying controls.
- Company: A leading UK bank undergoing a major technology transformation.
- Benefits: Competitive salary, professional development, and a chance to shape security practices.
- Other info: Join a collaborative team with excellent career growth opportunities.
- Why this job: Make a real impact on security and privacy in a dynamic banking environment.
- Qualifications: Experience in information security, risk assessment, and stakeholder management.
The predicted salary is between 60000 - 80000 € per year.
A leading UK bank is looking for an experienced Information Security Consultant / Security Architect to join its security function during a major technology transformation programme. This is a broad secure change role, sitting within the Bank’s Security Architecture & Consulting function. The successful candidate will support technology and business change initiatives, helping delivery teams identify security risks, apply appropriate controls, and embed security and privacy considerations from early design through to delivery.
This is not a pure data privacy role, and it is not a hands-on engineering role. The Bank is looking for a strong, practical information security consultant or security architect who can operate across security advisory, risk assessment, control assessment, secure-by-design, governance and delivery support. There is, however, a strong data privacy angle. You do not need to be a privacy lawyer or DPO, but you must be comfortable working with privacy-related security topics, including data protection, privacy-by-design, DPIAs, data flows and GDPR-aware change delivery.
You will work closely with embedded security consultants, architects, engineers, product teams, delivery leads and business stakeholders to ensure security is built properly into change initiatives. You will provide practical guidance rather than theoretical policy advice. The role requires someone who can understand a project, identify the real security and privacy risks, explain what needs to happen, and help delivery teams move forward safely.
The Bank has previously hired strong security architecture and security consulting profiles across application security, ERP security, secure change, cloud security, IAM, assurance and financial services security leadership, so the search should be broad rather than narrowly privacy-focused. Relevant hired profiles include AppSec/security architecture, cyber solutions design, security architecture leadership and ERP/cloud security architecture backgrounds.
Key ResponsibilitiesYou will:
- Provide information security consultancy across technology and business change initiatives.
- Support delivery teams in identifying, assessing and managing security risks.
- Carry out security risk and control assessments using the Bank’s secure change processes.
- Review solution designs, project documentation, data flows and security requirements.
- Advise on secure-by-design principles across applications, infrastructure, cloud, data and third-party change.
- Help teams understand how privacy, data protection and information security requirements apply to their projects.
- Support privacy-related activity such as DPIAs, privacy-by-design considerations, data classification and data handling controls.
- Work with specialist privacy, risk, architecture and compliance teams where deeper input is required.
- Provide clear, pragmatic recommendations to engineers, project managers, product owners and business stakeholders.
- Help improve secure change processes, templates, documentation and ways of working.
- Support coaching, guidance and knowledge-sharing across the security consulting community.
- Contribute to assurance and quality review activity, ensuring security and privacy processes are applied consistently.
- Produce management information and reporting on security risks, controls and delivery progress.
Broad information security experience across security architecture, risk, controls, assurance and secure change. Experience supporting technology change, transformation programmes, project delivery or product teams. Ability to assess security risks and recommend proportionate, practical controls. Experience reviewing solution designs, architecture documents, risk assessments or project security artefacts. Understanding of secure-by-design principles and how security should be embedded into delivery lifecycles. Knowledge of data privacy and data protection concepts, including GDPR, DPIAs, data classification, data flows and privacy-by-design. Strong stakeholder management skills, including the ability to work with engineers, architects, project managers, risk teams and business stakeholders. Financial services, banking or regulated industry experience would be highly beneficial. Understanding of risk management and the three lines of defence model. Strong documentation skills, including the ability to produce guidance, reports, process documents and training material. Relevant certifications such as CISSP, CISM, CRISC, CISA, ISO 27001, TOGAF, SABSA, CIPP/E or CIPM would be useful, but experience is more important than certificates alone.
Information Security Architect - Secure Change & Data Privacy in London employer: Rothstein Recruitment
As a leading UK bank, we pride ourselves on fostering a dynamic and inclusive work environment that champions employee growth and innovation. Our commitment to professional development is evident through tailored training programmes and mentorship opportunities, ensuring that our team members thrive in their careers while contributing to meaningful technology transformation initiatives. With a strong focus on security and privacy, we offer a unique chance to work at the forefront of the banking sector, making a tangible impact on how we protect our customers' data and enhance our services.
StudySmarter Expert Advice🤫
We think this is how you could land Information Security Architect - Secure Change & Data Privacy in London
✨Tip Number 1
Network like a pro! Get out there and connect with folks in the industry. Attend meetups, webinars, or even just grab a coffee with someone who’s already in the role you want. You never know who might have the inside scoop on job openings!
✨Tip Number 2
Show off your skills! When you get the chance to chat with potential employers, be ready to discuss specific projects you've worked on. Highlight how you’ve tackled security risks and implemented controls in past roles. Real-life examples can make you stand out!
✨Tip Number 3
Don’t just apply anywhere—apply through our website! We’re all about finding the right fit, and applying directly can give you a better shot at landing that interview. Plus, it shows you’re genuinely interested in joining our team.
✨Tip Number 4
Prepare for those interviews! Research the company and its security practices. Be ready to discuss how you’d approach secure change initiatives and data privacy topics. The more prepared you are, the more confident you’ll feel when it’s time to shine!
We think you need these skills to ace Information Security Architect - Secure Change & Data Privacy in London
Some tips for your application 🫡
Tailor Your CV:Make sure your CV reflects the skills and experiences that align with the Information Security Architect role. Highlight your experience in security consultancy, risk assessment, and secure change processes to catch our eye!
Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about information security and how your background makes you a great fit for our team. Don’t forget to mention any relevant projects or achievements.
Showcase Your Knowledge of Data Privacy:Since this role has a strong data privacy angle, make sure to demonstrate your understanding of GDPR, DPIAs, and privacy-by-design principles. We want to see that you can navigate these topics with ease!
Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way to ensure your application gets into the right hands and shows us you’re serious about joining our team!
How to prepare for a job interview at Rothstein Recruitment
✨Know Your Stuff
Make sure you brush up on your information security knowledge, especially around secure change and data privacy. Familiarise yourself with GDPR, DPIAs, and secure-by-design principles. The more you know, the better you'll be able to discuss how these concepts apply to the role.
✨Showcase Your Experience
Prepare to share specific examples from your past roles where you've successfully identified and managed security risks. Highlight your experience in technology change initiatives and how you've provided practical guidance to delivery teams. Real-world examples will make you stand out.
✨Engage with Stakeholders
Demonstrate your strong stakeholder management skills by discussing how you've collaborated with engineers, architects, and project managers in previous roles. Be ready to explain how you can bridge the gap between technical teams and business stakeholders to ensure security is embedded in projects.
✨Ask Insightful Questions
Prepare thoughtful questions about the bank's security architecture and consulting function. Inquire about their current challenges in secure change and how they measure success in embedding security and privacy considerations. This shows your genuine interest in the role and helps you assess if it's the right fit for you.