Senior Security Architect - Mobile Banking Platforms

Hellokindred · Johannesburg, ZA

On-siteWorkplace
1d agoPosted · Sep 21
Company siteSource
$161ksolutions architect median
Checking…All solutions architect jobsPosted on the employer’s own site. Sign in with Google, free, to see who and apply there.
Experience10+ years

Skills in this posting

The posting

Anticipated Contract End Date/Length: October 19th, 2026 - February 28th, 2026

Work set up: Onsite

Our client in the global professional services industry is looking for an experienced Senior Security Architect who will be accountable for the end-to-end security architecture of a large-scale, customer-facing mobile banking platform. The role defines, governs, and continuously evolves security across mobile applications, APIs, identity platforms, cloud infrastructure, backend services, shared platform capabilities, and DevSecOps delivery pipelines.

This role acts as the security design authority across platform teams and delivery squads, ensuring the mobile banking platform achieves world-class standards for customer trust, cyber resilience, regulatory compliance, privacy, fraud resistance, and secure customer experience.

What you will do

Own the end-to-end security architecture for a large-scale, customer-facing mobile banking platform.

Define and govern security across mobile apps, APIs, identity platforms, cloud infrastructure, backend services, shared platforms, and DevSecOps pipelines.

Architect strong customer authentication using PIN, biometrics, device-bound cryptographic keys, risk context, and transaction-level authorization.

Design PIN-based authentication models where PINs unlock cryptographic keys and are never stored or transmitted.

Define biometric-first authentication using Face ID, Touch ID, and platform biometrics through secure enclave and hardware-backed mechanisms.

Govern secure use of mobile keystores and secure enclaves, including iOS Secure Enclave and Android Hardware Keystore.

Ensure biometrics are used only for local cryptographic key release and never treated as raw credentials.

Define integration with enterprise key vaults and HSMs for signing, encryption, certificate handling, and key lifecycle management.

Own OAuth 2.0, OpenID Connect, PKCE, secure token storage, token rotation, and device-bound session models for mobile and web channels.

Define API, Backend-for-Frontend, and service security patterns aligned to Zero Trust principles.

Lead threat modelling across onboarding, authentication, payments, card management, account servicing, and other sensitive customer journeys.

Translate threats into architecture patterns, security controls, non-functional requirements, and architecture decision records.

Embed Security-by-Design into HLDs, LLDs, architecture decision records, release governance, and delivery assurance forums.

Define DevSecOps guardrails including SAST, DAST, dependency scanning, secrets management, container scanning, IaC security, and secure release gates.

Support penetration testing, vulnerability remediation, incident readiness, forensic readiness, and cyber-resilience initiatives.

Embed Privacy-by-Design, consent management, secure data processing, secure data retention, and data lifecycle controls.

Act as a security design authority across delivery squads, platform teams, engineering teams, product stakeholders, risk, fraud, and compliance functions.

Provide clear architectural guidance to Engineering, Product, Operations, Fraud, Risk, and executive technology stakeholders.

Balance security, customer experience, operational resilience, and delivery velocity.

Ensure the mobile banking platform meets world-class standards for security, trust, resilience, and regulatory compliance.

Additional Modern Digital Banking Security responsibilities

Define mobile fraud prevention architecture, including device binding, account takeover prevention, mule account detection integration, and transaction risk scoring.

Architect device binding and trusted device frameworks using hardware-backed cryptographic identities, secure key stores, and device attestation services.

Define transaction signing and transaction verification patterns to support non-repudiation and customer protection for high-risk banking transactions.

Govern certificate pinning, mutual TLS, secure channel enforcement, and secure API communication models.

Define runtime application self-protection and mobile application shielding strategies to detect and prevent tampering, reverse engineering, instrumentation, rooting, and jailbreak attacks.

Architect controls against mobile malware, overlays, screen scraping, session hijacking, credential theft, and application manipulation.

Define mobile and API bot mitigation, API abuse prevention, anomaly detection, and automated attack protection controls.

Govern API security controls including rate limiting, schema validation, API gateways, threat protection, security testing, and behavioural anomaly monitoring.

Define secure customer onboarding patterns using device reputation, identity verification, fraud signals, behavioural analytics, and risk-based authentication.

Architect adaptive authentication using device, location, network, behavioural, transactional, and fraud intelligence signals.

Establish security patterns for digital wallets, tokenized payments, QR payments, card management, open banking, and real-time payment ecosystems.

Define cloud-native security controls for containerized workloads, Kubernetes platforms, service meshes, cloud services, and platform engineering environments.

Govern software supply chain security including signed artefacts, SBOM, dependency risk management, secure build pipelines, provenance verification, and release integrity controls.

Establish cyber-resilience architecture patterns covering denial-of-service protection, disaster recovery, ransomware resilience, backup integrity, and business continuity.

Define security monitoring architecture integrating SIEM, SOAR, threat intelligence, fraud monitoring, application telemetry, audit logging, and incident response workflows.

Govern security logging, auditability, evidentiary controls, and forensic readiness for regulatory investigations and major incident response.

Assess and govern third-party, fintech, SaaS, martech, payment, and partner integrations from a security architecture perspective.

Define and govern AI and agentic platform security controls including model security, prompt injection prevention, data leakage protection, secure retrieval, authorization, auditability, and responsible AI guardrails.

Embed security architecture controls for AI-assisted customer journeys, intelligent agents, digital servicing capabilities, and enterprise AI platforms.

Lead security architecture reviews and risk assessments across Mobile, Web, Backend, Data, Martech, AI, Cloud, Infrastructure, DevOps, Testing, and Shared Platform domains.

Act as the final security architecture authority for production releases, significant design changes, security waivers, and exceptions impacting the digital banking platform.

10+ years of relevant Security Architecture experience, ideally within banking, payments, fintech, financial services, or other regulated digital environments.

Senior-level security architecture experience in digital banking, payments, fintech, financial services, or other regulated customer-facing digital platforms.

Strong hands-on understanding of mobile security, API security, identity, cryptography, cloud security, DevSecOps, platform security, fraud controls, and operational resilience.

The PivotHop read

Where these skills also reach

More solutions architect roles

Backfilled listing, refreshed with the nightly scrape; the employer has not claimed it yet. Are you the employer? Claim this listing and it can be featured to the candidates whose skills already reach it, first month free.

© 2026 PivotHopReal data, real career moves