About the Role
Partner with engineering and product teams to deliver secure, scalable cloud-native banking solutions. Act as a security partner, performing design reviews and threat modeling across platform, product, and infrastructure initiatives. Provide pragmatic security guidance that balances risk management with business and delivery objectives, becoming a trusted advisor to project teams. Help build and operate practical security controls for the safe adoption of agentic AI.
Responsibilities
- Lead threat modelling workshops for new products, services, AI tooling and architectural changes.
- Review solution designs and provide clear, actionable security recommendations.
- Assess risks across cloud-native and distributed systems architectures.
- Provide security support throughout the delivery lifecycle, working closely with architects, engineers and product teams.
- Help shape the secure design of APIs, microservices, data flows and cloud infrastructure.
- Support teams in defining security requirements and identifying appropriate compensating controls.
- Contribute to security standards, patterns and reference architectures.
- Communicate technical risks clearly to both technical and non-technical stakeholders.
- Drive remediation activities and help ensure identified risks are managed effectively.
Requirements
- A pragmatic, delivery-focused approach to security.
- Ability to balance risk reduction with business outcomes.
- Strong communication skills, with the confidence to challenge constructively and influence effectively.
- Comfort working with ambiguity and rapidly evolving technology landscapes.
- A passion for enabling teams to build secure products, rather than simply enforcing compliance.
- Significant experience in a Security Consultant, Security Architect or similar senior security role.
- Proven experience conducting security design reviews and threat modelling.
- Strong understanding of AWS security architecture and cloud security best practices.
- Experience securing Java-based microservices and distributed systems.
- Knowledge of modern authentication and authorisation patterns (OAuth2, OIDC, JWT, etc.).
- Experience assessing API security risks and controls.
- Strong stakeholder management and influencing skills.
- Ability to work independently and operate effectively in fast-moving engineering environments.
- Experience within financial services, fintech or regulated environments.
- Familiarity with containerised platforms (Docker, Kubernetes, ECS/EKS).
- Experience with CI/CD security, DevSecOps practices and automated security controls.
- Knowledge of secure software development practices and application security testing.
- Relevant certifications such as CISSP, CCSP, AWS Security Specialty or equivalent.
Skills
- AWS security architecture
- Cloud security best practices
- Securing Java-based microservices
- Distributed systems security
- Modern authentication and authorisation patterns (OAuth2, OIDC, JWT)
- API security risk assessment
- Stakeholder management
- Influencing skills
- Containerised platforms (Docker, Kubernetes, ECS/EKS)
- CI/CD security
- DevSecOps practices
- Automated security controls
- Secure software development practices
- Application security testing
Location
- London
Work Type
- Remote-enabled
- Hybrid
Experience Level
- Senior
Education Level
- CISSP
- CCSP
- AWS Security Specialty
Benefits
- 25 days of holiday in addition to Bank/Public Holidays (with the option to swap some public holidays for alternative dates such as Diwali or Eid)
- 1 day off on or around your birthday
- 4 wellbeing days (1 additional paid day off per quarter, aimed at supporting you to maintain your personal wellbeing)
- Remote enabled working
- Enhanced parental policies, including time off for fertility treatment
- Regular social gatherings and affinity groups
- Work from anywhere outside your typical working location – up to 4 weeks a year
- Career progression and learning pathways
- 1 paid volunteering day a year
- Sabbatical leave
- Options pool
- Private health insurance, with the option to add your family
- Pension scheme
- Enhanced company sick pay
- Life Assurance
- Income Protection
- Subscription to Headspace wellbeing app
- Flexible benefits via salary sacrifice
About the Company
- 10x Banking is transforming the financial industry with its cloud-native core banking platform, powering global banks like Chase UK, Old Mutual, and Westpac.
- The company offers a diverse, global community that thrives on innovation and collaboration, aiming to make a positive impact through its work.
- Core values include Transformation, Integrity, and Impact.
- 10x Banking operates as a remote-enabled organization with agile working principles.
- The company emphasizes a better work/life balance and offers flexibility around core working hours.
Equal Opportunity
- 10x is committed to fostering a diverse and inclusive culture where every employee can be their authentic self and reach their full potential.
- The assessment process identifies unique contributions and potential for growth.
- Core competencies sought are Business Impact, Change Driver & Delivery Excellence.
- All job applicants are treated equally and fairly, regardless of ethnicity, race, religion, sex, sexual orientation, gender identity, family or parental status, age, neurodiversity, or disability status.
- Accommodations are available during the interview process upon request and will be maintained confidentially.
