Temenos
Head of Product Security, Software Supply Chain & AI Security

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
About Temenos
Temenos is a global leader in banking technology. Through our market-leading core banking suite and best-in-class composable solutions, we are modernizing the banking industry. Banks of all sizes utilize our adaptable technology – on-premises, in the cloud, or as SaaS – to deliver next-generation services and AI-enhanced experiences that elevate banking for their customers. Our mission is to create a world where people can live their best financial lives.
VALUES
- Care About Transforming The Banking Landscape.
- Commit to being part of an exciting culture and product evolving within the financial industry.
- Collaborate effectively and proactively with teams within or outside Temenos.
- Challenge yourself to be ambitious and achieve your individual as well as the company targets.
Role purpose
Role
Lead security across Temenos products, the software supply chain and the use of AI. The role covers two distinct AI security domains:
- AI in Temenos products: securing customer-facing AI and agentic banking capabilities.
- AI across the SDLC: governing how AI-assisted tools and autonomous agents are used throughout product design, development, testing, release and maintenance.
The successful candidate will set direction, build the operating model and work with Product and Engineering to turn security requirements into practical controls.
Responsibilities
Product security
- Own the product security strategy across Temenos products and services.
- Embed security into product design, architecture, development, testing, release and maintenance.
- Establish secure engineering standards and risk-based release requirements.
- Lead threat modelling, security architecture reviews and product security testing.
- Oversee vulnerability management, remediation and product security incident response.
- Provide security assurance to customers, auditors and regulators.
Software supply chain security
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
- Secure source control, CI/CD pipelines, build systems, dependencies, containers and release artefacts.
- Establish requirements for SBOMs, provenance, artefact signing and verification.
- Govern open-source and third-party software risk.
- Protect developer identities, build credentials, tokens and secrets.
- Improve Temenos' ability to identify and respond to compromised dependencies or build systems.
AI security in Temenos products
- Define security requirements for customer-facing AI and agentic capabilities.
- Address customer approaches to:
- prompt injection,
- data leakage,
- insecure tool use,
- unsafe outputs and
- excessive agent permissions.
- Require clear agent identities, scoped access, human approval and auditable actions.
- Establish AI threat modelling, adversarial testing and runtime monitoring.
- Ensure models, data sources, prompts, tools and agent workflows have accountable owners.
- Translate AI regulation and responsible AI principles into product controls.
AI security across the SDLC
- Govern the use of AI-assisted tools and autonomous agents throughout the SDLC.
- Define what source code, customer data, intellectual property and internal information may be shared with AI services.
- Assess AI tools based on data handling, model training, retention, security and deployment risks.
- Control AI and agent access to requirements, designs, repositories, development environments, testing systems, CI/CD pipelines and cloud platforms.
- Require human approval for material code changes, releases and privileged or irreversible actions.
- Establish testing, review, traceability and provenance requirements for AI-generated artefacts.
- Monitor AI usage and provide approved alternatives where public services are unsuitable.
Leadership
- Build and lead a global product and AI security team.
- Establish clear ownership across Product, Engineering, Enterprise Security, Risk and Compliance.
- Develop security champions and reusable secure engineering patterns.
- Report material risks and programme performance to senior leadership.
- Represent Temenos in strategic customer and regulatory discussions.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Required Experience
- Senior leadership experience in product or application security within a software company.
- Strong knowledge of secure SDLC, threat modelling and vulnerability management.
- Experience securing CI/CD pipelines and modern software supply chains.
- Practical knowledge of cloud-native, SaaS, API and identity security.
- Experience securing generative AI and agentic systems.
- Understanding of AI-assisted tools across the full SDLC.
- Experience in banking, financial services or another regulated sector.
- Ability to communicate technical risk to engineers, executives, customers and regulators.
Measures of success
- Reduced security risk reaching production.
- Improved remediation times for material vulnerabilities.
- Strong SBOM, provenance and artefact-signing coverage.
- Effective controls for customer-facing AI and agentic capabilities.
- Controlled, traceable use of AI throughout the SDLC.
- Reliable customer and regulatory assurance evidence.
- Strong adoption of security controls by Product and Engineering.
SOME OF OUR BENEFITS Include
- Maternity leave: Transition back with 3 days per week in the first month and 4 days per week in the second month
- Civil Partnership: 1 week of paid leave if you're getting married. This covers marriages and civil partnerships, including same sex/civil partnership
- Family care: 4 weeks of paid family care leave
- Recharge days: 4 days per year to use when you need to physically or mentally needed to recharge
- Study leaves: 2 weeks of paid leave each year for study or personal development
Please make sure to read our Recruitment Privacy Policy
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Location