Sr. Associate, Cybersecurity Architect
About the role
Santander is evolving from a high-impact brand into a technology-driven organization. This role operates at the intersection of security engineering, enterprise architecture, and regulatory compliance within a high-control financial environment. The Sr. Associate, Cybersecurity Architect is responsible for designing, governing, and continuously improving secure architecture across enterprise platforms, applications, and infrastructure, ensuring alignment with policies, standards, and regulatory mandates.
Responsibilities
- Conduct threat modeling, security design reviews, and lead cybersecurity architecture risk assessments (ISARs).
- Define and maintain enterprise security architecture aligned to business strategy, policies, and reference architecture for cloud, hybrid, and on-prem environments.
- Embed security controls early in the project lifecycle under a “shift-left” model: partner with engineering, product, and business teams to translate risk into actionable design requirements.
- Architect and oversee encryption strategies for data at rest, in transit, and in use including PKI, HSM, and Certificate lifecycle processes (issuance, rotation, revocation, automation, PKI governance).
- Establish cryptographic key management standards and oversee key custody models.
- Ensure architectural compliance with regulatory and supervisory expectations.
- Support regulatory examinations, audits, and control validation activities.
Requirements
- Bachelor's Degree or equivalent work experience in Computer Science, Engineering, Information Technology Management, or equivalent field. Required.
- 5+ years of experience in architecture within financial services or similarly regulated industries.
- Cybersecurity experience preferred.
- Demonstrated experience operating in a shift-left security model embedded with development and business teams.
- Deep expertise in encryption technologies, including:
- PKI architecture and governance
- HSM deployment and management
- Certificate lifecycle automation
- Key management systems (KMS)
- TLS, mTLS, IPSec, and database encryption
- Experience designing secure architectures in cloud environments (AWS mainly).
- Proven experience conducting threat modeling and architecture risk assessments.
Regulatory & Framework Knowledge
- Demonstrated working knowledge of:
- FFIEC IT Examination Handbook
- GLBA Safeguards Rule
- NYDFS 23 NYCRR 500
- PCI-DSS
- NIST Cybersecurity Framework (CSF)
- NIST SP 800-53 and 800-57 (Cryptographic Key Management)
- ISO/IEC 27001 and 27002
Skills
- Strong risk-based decision-making capability.
- Ability to articulate technical risk in business terms.
- Architectural governance and documentation discipline.
- Cryptographic rigor and operational resilience mindset.
- Cross-functional collaboration across engineering, infrastructure, legal, and risk teams.
Nice to Have
- Established work history or equivalent demonstrated through a combination of work experience, training, military service, or education.
- Experience in Microsoft Office products.
Work Authorization & Sponsorship
Applicants must be legally authorized to work in the United States on a full-time basis without requiring employer sponsorship to commence employment.
Pay
The base pay range for this position is $108,750.00 USD to $180,000.00 USD annually. The exact compensation may vary based on skills, experience, training, licensure, certifications, and location.
Benefits
Santander offers a comprehensive benefits package designed to support you, your family, and your well-being, now and into the future. For more details, visit Santander Benefits - 2026 Santander OnGoing/NH eGuide.
Working Conditions
Frequent minimal physical effort such as sitting, standing, and walking is required for this role. Depending on location, occasional moving and lifting of light equipment and/or furniture may be required.