Senior Security Architect - Mobile Banking Platfor

Executive Placements · Kensington

Stop applying one at a time.

JobAlertsZA auto-applies to South African jobs like this one for you, overnight. Upload your CV once — we do the applying.

Start free — we apply for you →

Role Scope

  • Primary domain: Mobile banking platform security architecture across iOS, Android, web, APIs, BFF, cloud, identity, payments, data, DevSecOps, and platform services.
  • Accountability: Owns security architecture direction, patterns, architecture decisions, control requirements, and governance across critical customer journeys.
  • Stakeholders: Engineering, product, platform teams, cybersecurity, risk, fraud, compliance, privacy, operations, infrastructure, and executive technology leadership.
  • Delivery model: Works across agile delivery squads and architecture governance forums to balance security, customer experience, resilience, and delivery velocity.

Duties and Responsibilities

• Own the end-to-end security architecture for a large-scale, customer-facing mobile banking platform. • Define and govern security across mobile apps, APIs, identity platforms, cloud infrastructure, backend services, shared platforms, and DevSecOps pipelines. • Architect strong customer authentication using PIN, biometrics, device-bound cryptographic keys, risk context, and transaction-level authorization. • Design PIN-based authentication models where PINs unlock cryptographic keys and are never stored or transmitted. • Define biometric-first authentication using Face ID, Touch ID, and platform biometrics through secure enclave and hardware-backed mechanisms. • Govern secure use of mobile keystores and secure enclaves, including iOS Secure Enclave and Android Hardware Keystore. • Ensure biometrics are used only for local cryptographic key release and never treated as raw credentials. • Define integration with enterprise key vaults and HSMs for signing, encryption, certificate handling, and key lifecycle management. • Own OAuth 2.0, OpenID Connect, PKCE, secure token storage, token rotation, and device-bound session models for mobile and web channels. • Define API, Backend-for-Frontend, and service security patterns aligned to Zero Trust principles. • Lead threat modelling across onboarding, authentication, payments, card management, account servicing, and other sensitive customer retirement, and data lifecycle controls. Required Qualifications: TOGAF Skills: Mobile security, iOS and Android application security, secure storage, platform security models, jailbreak/root detection, hardening, secure local data handling, mobile threat defense, and mobile application, Authentication PIN-based authentication, biometrics, device-bound credentials, step-up authentication, adaptive authentication, risk-based authentication, and transaction-level authorization., Identity and access OAuth 2.0, OpenID Connect, PKCE, secure token handl

.special-hidden { display: none; }

Auto-apply to this jobView original posting ↗