We are looking for a highly skilled Principal Architect with extensive experience in IT business architecture to join our team in Columbus, Ohio. This contract position will involve driving strategic initiatives to modernize applications and align technology solutions with banking objectives. The ideal candidate will possess a strong background in financial services and a proven track record of leading digital transformation efforts in regulated environments.<br><br>Responsibilities:<br>• Collaborate with business units such as Retail, Commercial, Risk, and Compliance to develop enterprise architecture strategies that align with organizational goals.<br>• Create business capability models, value streams, and process architectures tailored to the financial services industry.<br>• Lead application modernization initiatives, including assessing legacy systems, strategizing cloud migrations, and implementing modern platforms like microservices, APIs, and containers.<br>• Work closely with enterprise architects, solution architects, and engineering teams to ensure the seamless delivery of modernized applications.<br>• Facilitate workshops to identify capability gaps, regulatory impacts, and opportunities for transformation.<br>• Support strategic planning, investment prioritization, and governance processes for IT initiatives.<br>• Ensure compliance with banking regulations, data privacy standards, and internal governance frameworks.<br>• Evaluate and recommend emerging technologies, such as AI, low-code tools, and cloud-native platforms, for integration into banking operations.
<p>As the API Standards & Compliance Lead, you will define, implement, and enforce enterprise-wide API governance frameworks that ensure consistency, security, and scalability across all APIs. This strategic role focuses on establishing API design standards, lifecycle governance, and compliance policies aligned with industry best practices and regulatory requirements. You will partner closely with Enterprise Architecture, Security, Platform Engineering, and Developer Experience teams to advance an API-first strategy and enable seamless integration across the enterprise.</p><p><br></p><p>What You’ll Do</p><p>Governance Framework & Standards</p><ul><li>Define and maintain enterprise-wide API design and governance policies aligned with architecture principles and industry standards (OpenAPI, REST, GraphQL).</li><li>Establish naming conventions, versioning guidelines, backward compatibility expectations, deprecation/retirement policies, and documentation standards.</li><li>Run the API Governance Board (reviews, approvals, waivers) and maintain the governance operating model and RACI.</li><li>Author and maintain reference architecture, standards playbooks, and reusable policy templates.</li></ul><p>Lifecycle Governance & Platform Integration (Apigee X)</p><ul><li>Design and oversee API onboarding workflows via the Developer Portal, ensuring proper documentation, cataloging, and discoverability.</li><li>Define governance processes integrated with Apigee X for publishing, runtime policies (e.g., quotas, rate limiting), and analytics.</li><li>Ensure consistent use of API products, proxies, and catalogs; promote high-quality API definitions and reusability.</li></ul><p>Security & Regulatory Compliance</p><ul><li>Implement governance for security patterns (OAuth2, JWT, JWKS, mTLS) using Apigee X and Ping Identity.</li><li>Align APIs to regulatory requirements (e.g., Open Banking, PSD2, HIPAA, GDPR) and enterprise security standards.</li><li>Partner with Risk, Compliance, and Security Engineering to define control objectives, evidence, and auditability (e.g., NIST, ISO 27001, SOC 2).</li></ul><p>Developer Experience & Enablement</p><ul><li>Collaborate with the API Gateway and DevEx teams to optimize portal usability, API discoverability, and policy adoption.</li><li>Create artifacts (cheat sheets, checklists, sample OpenAPI specs, policy catalogs) that accelerate compliant delivery.</li></ul><p>Analytics, Metrics & Continuous Improvement</p><ul><li>Define and track governance KPIs (e.g., % APIs compliant, time-to-approve, policy adoption rates, security defect trends).</li><li>Use Apigee Analytics and GCP monitoring to identify gaps and refine standards based on data insights and evolving business needs.</li></ul><p>Risk, Audit & Controls</p><ul><li>Establish controls and evidence for audits (design-time and runtime), including conformity checks against policy and standards.</li><li>Coordinate remediation plans for non-compliant APIs; manage waivers/exceptions with clear time-bound conditions.</li></ul>