ABOUT TEMENOS
Temenos is a global leader in banking technology. Through our market-leading core banking suite and best-in-class composable solutions, we are modernizing the banking industry. Banks of all sizes utilize our adaptable technology - on-premises, in the cloud, or as SaaS - to deliver next-generation services and AI-enhanced experiences that elevate banking for their customers. Our mission is to create a world where people can live their best financial lives.
VALUES
Care about transforming the Banking landscape.
Commit to being part of an exciting culture and product evolving within the financial industry.
Collaborate effectively and proactively with teams within or outside Temenos.
Challenge yourself to be ambitious and achieve your individual as well as the company targets.
Role purpose
Lead security across Temenos products, the software supply chain and the use of AI. The role covers two distinct AI security domains:
- AI in Temenos products: securing customer-facing AI and agentic banking capabilities.
- AI across the SDLC: governing how AI-assisted tools and autonomous agents are used throughout product design, development, testing, release and maintenance.
The successful candidate will set direction, build the operating model and work with Product and Engineering to turn security requirements into practical controls.
Responsibilities
Product security
- Own the product security strategy across Temenos products and services.
- Embed security into product design, architecture, development, testing, release and maintenance.
- Establish secure engineering standards and risk-based release requirements.
- Lead threat modelling, security architecture reviews and product security testing.
- Oversee vulnerability management, remediation and product security incident response.
- Provide security assurance to customers, auditors and regulators.
Software supply chain security
- Secure source control, CI/CD pipelines, build systems, dependencies, containers and release artefacts.
- Establish requirements for SBOMs, provenance, artefact signing and verification.
- Govern open-source and third-party software risk.
- Protect developer identities, build credentials, tokens and secrets.
- Improve Temenos' ability to identify and respond to compromised dependencies or build systems.
AI security in Temenos products
- Define security requirements for customer-facing AI and agentic capabilities.
- Address customer approaches to: -
- prompt injection, data leakage, insecure tool use, unsafe outputs and excessive agent permissions.
- Require clear agent identities, scoped access, human approval and auditable actions.
- Establish AI threat modelling, adversarial testing and runtime monitoring.
- Ensure models, data sources, prompts, tools and agent workflows have accountable owners.
- Translate AI regulation and responsible AI principles into product controls.
AI security across the SDLC
- Govern the use of AI-assisted tools and autonomous agents throughout the SDLC.
- Define what source code, customer data, intellectual property and internal information may be shared with AI services.
- Assess AI tools based on data handling, model training, retention, security and deployment risks.
- Control AI and agent access to requirements, designs, repositories, development environments, testing systems, CI/CD pipelines and cloud platforms.
- Require human approval for material code changes, releases and privileged or irreversible actions.
- Establish testing, review, traceability and provenance requirements for AI-generated artefacts.
- Monitor AI usage and provide approved alternatives where public services are unsuitable.
Leadership
- Build and lead a global product and AI security team.
- Establish clear ownership across Product, Engineering, Enterprise Security, Risk and Compliance.
- Develop security champions and reusable secure engineering patterns.
- Report material risks and programme performance to senior leadership.
- Represent Temenos in strategic customer and regulatory discussions.
Required experience
- Senior leadership experience in product or application security within a software company.
- Strong knowledge of secure SDLC, threat modelling and vulnerability management.
- Experience securing CI/CD pipelines and modern software supply chains.
- Practical knowledge of cloud-native, SaaS, API and identity security.
- Experience securing generative AI and agentic systems.
- Understanding of AI-assisted tools across the full SDLC.
- Experience in banking, financial services or another regulated sector.
- Ability to communicate technical risk to engineers, executives, customers and regulators.
Measures of success
- Reduced security risk reaching production.
- Improved remediation times for material vulnerabilities.
- Strong SBOM, provenance and artefact-signing coverage.
- Effective controls for customer-facing AI and agentic capabilities.
- Controlled, traceable use of AI throughout the SDLC.
- Reliable customer and regulatory assurance evidence.
Strong adoption of security controls by Product and Engineering.
SOME OF OUR BENEFITS include:
Maternity leave: Transition back with 3 days per week in the first month and 4 days per week in the second month
Civil Partnership: 1 week of paid leave if you're getting married. This covers marriages and civil partnerships, including same sex/civil partnership
Family care: 4 weeks of paid family care leave
Recharge days: 4 days per year to use when you need to physically or mentally needed to recharge
Study leaves: 2 weeks of paid leave each year for study or personal development
Please make sure to read our Recruitment Privacy Policy

