Senior Security Architect Mobile Banking Platforms
Johannesburg - South Africa
Job Summary
Anticipated Contract End Date/Length: October 19th 2026 - February 28th 2026
Work set up: Onsite
Our client in the global professional services industry is looking for an experienced Senior Security Architect who will be accountable for the end-to-end security architecture of a large-scale customer-facing mobile banking platform. The role defines governs and continuously evolves security across mobile applications APIs identity platforms cloud infrastructure backend services shared platform capabilities and DevSecOps delivery pipelines.
This role acts as the security design authority across platform teams and delivery squads ensuring the mobile banking platform achieves world-class standards for customer trust cyber resilience regulatory compliance privacy fraud resistance and secure customer experience.
What you will do:
- Own the end-to-end security architecture for a large-scale customer-facing mobile banking platform.
- Define and govern security across mobile apps APIs identity platforms cloud infrastructure backend services shared platforms and DevSecOps pipelines.
- Architect strong customer authentication using PIN biometrics device-bound cryptographic keys risk context and transaction-level authorization.
- Design PIN-based authentication models where PINs unlock cryptographic keys and are never stored or transmitted.
- Define biometric-first authentication using Face ID Touch ID and platform biometrics through secure enclave and hardware-backed mechanisms.
- Govern secure use of mobile keystores and secure enclaves including iOS Secure Enclave and Android Hardware Keystore.
- Ensure biometrics are used only for local cryptographic key release and never treated as raw credentials.
- Define integration with enterprise key vaults and HSMs for signing encryption certificate handling and key lifecycle management.
- Own OAuth 2.0 OpenID Connect PKCE secure token storage token rotation and device-bound session models for mobile and web channels.
- Define API Backend-for-Frontend and service security patterns aligned to Zero Trust principles.
- Lead threat modelling across onboarding authentication payments card management account servicing and other sensitive customer journeys.
- Translate threats into architecture patterns security controls non-functional requirements and architecture decision records.
- Embed Security-by-Design into HLDs LLDs architecture decision records release governance and delivery assurance forums.
- Define DevSecOps guardrails including SAST DAST dependency scanning secrets management container scanning IaC security and secure release gates.
- Support penetration testing vulnerability remediation incident readiness forensic readiness and cyber-resilience initiatives.
- Embed Privacy-by-Design consent management secure data processing secure data retention and data lifecycle controls.
- Act as a security design authority across delivery squads platform teams engineering teams product stakeholders risk fraud and compliance functions.
- Provide clear architectural guidance to Engineering Product Operations Fraud Risk and executive technology stakeholders.
- Balance security customer experience operational resilience and delivery velocity.
- Ensure the mobile banking platform meets world-class standards for security trust resilience and regulatory compliance.
Additional Modern Digital Banking Security responsibilities
- Define mobile fraud prevention architecture including device binding account takeover prevention mule account detection integration and transaction risk scoring.
- Architect device binding and trusted device frameworks using hardware-backed cryptographic identities secure key stores and device attestation services.
- Define transaction signing and transaction verification patterns to support non-repudiation and customer protection for high-risk banking transactions.
- Govern certificate pinning mutual TLS secure channel enforcement and secure API communication models.
- Define runtime application self-protection and mobile application shielding strategies to detect and prevent tampering reverse engineering instrumentation rooting and jailbreak attacks.
- Architect controls against mobile malware overlays screen scraping session hijacking credential theft and application manipulation.
- Define mobile and API bot mitigation API abuse prevention anomaly detection and automated attack protection controls.
- Govern API security controls including rate limiting schema validation API gateways threat protection security testing and behavioural anomaly monitoring.
- Define secure customer onboarding patterns using device reputation identity verification fraud signals behavioural analytics and risk-based authentication.
- Architect adaptive authentication using device location network behavioural transactional and fraud intelligence signals.
- Establish security patterns for digital wallets tokenized payments QR payments card management open banking and real-time payment ecosystems.
- Define cloud-native security controls for containerized workloads Kubernetes platforms service meshes cloud services and platform engineering environments.
- Govern software supply chain security including signed artefacts SBOM dependency risk management secure build pipelines provenance verification and release integrity controls.
- Establish cyber-resilience architecture patterns covering denial-of-service protection disaster recovery ransomware resilience backup integrity and business continuity.
- Define security monitoring architecture integrating SIEM SOAR threat intelligence fraud monitoring application telemetry audit logging and incident response workflows.
- Govern security logging auditability evidentiary controls and forensic readiness for regulatory investigations and major incident response.
- Assess and govern third-party fintech SaaS martech payment and partner integrations from a security architecture perspective.
- Define and govern AI and agentic platform security controls including model security prompt injection prevention data leakage protection secure retrieval authorization auditability and responsible AI guardrails.
- Embed security architecture controls for AI-assisted customer journeys intelligent agents digital servicing capabilities and enterprise AI platforms.
- Lead security architecture reviews and risk assessments across Mobile Web Backend Data Martech AI Cloud Infrastructure DevOps Testing and Shared Platform domains.
- Act as the final security architecture authority for production releases significant design changes security waivers and exceptions impacting the digital banking platform.
Qualifications :
- 10 years of relevant Security Architecture experience ideally within banking payments fintech financial services or other regulated digital environments.
- Senior-level security architecture experience in digital banking payments fintech financial services or other regulated customer-facing digital platforms.
- Strong hands-on understanding of mobile security API security identity cryptography cloud security DevSecOps platform security fraud controls and operational resilience.
- Ability to translate business risks and threat scenarios into pragmatic architecture decisions technical controls delivery guardrails and measurable non-functional requirements.
- Proven ability to work across engineering product architecture cybersecurity risk compliance fraud privacy operations and executive stakeholders.
- Strong communication skills with the ability to explain complex security topics clearly to technical and non-technical audiences.
- Pragmatic delivery mindset with the ability to balance security assurance customer experience regulatory expectations and delivery timelines.
- CISSP CCSP CISM SABSA TOGAF Azure Security Engineer AWS Security Specialty or equivalent security architecture credentials.
- Knowledge of OWASP MASVS OWASP ASVS OWASP Mobile Top 10 OWASP API Security Top 10 NIST ISO 27001 PCI DSS POPIA and banking regulatory expectations.
- Exposure to mobile fraud prevention digital identity payment security hardware-backed cryptography cloud-native security DevSecOps and AI security governance.
- Candidates must have a clear background check (BGC) including an ITC (credit) check to be considered for the role.
Additional Information :
Candidates must be legally authorized to live and work in the country where the position is based without requiring employer sponsorship.
HelloKindred is committed to fair transparent and inclusive hiring practices. We assess candidates based on skills experience and role-related requirements.
We appreciate your interest in this opportunity. While we review every application carefully only candidates selected for an interview will be contacted.
HelloKindred is an equal opportunity employer. We welcome applicants of all backgrounds and do not discriminate on the basis of race colour religion sex gender identity or expression sexual orientation age national origin disability veteran status or any other protected characteristic under applicable law.
Remote Work :
No
Employment Type :
Contract
About Company
Who is HelloKindred?HelloKindred are specialists in staffing marketing, creative and technology roles, offering a range of talent solutions that can be delivered on-site, remotely or hybrid.Our vision is to make work accessible and people’s lives better. We do this by disrupting tradi ... View more