Senior Security Architect - Mobile Banking Platforms - 5 months Fixed Term Contract
Recruitco · Midrand, Gauteng
Stop applying one at a time.
JobAlertsZA auto-applies to South African jobs like this one for you, overnight. Upload your CV once — we do the applying.
Start free — we apply for you →Introduction
Location - Waterfall (On site)
The Senior Security Architect is accountable for the end-to-end security architecture of a large-scale, customer-facing mobile banking platform. The role defines, governs, and continuously evolves security across mobile applications, APIs, identity platforms, cloud infrastructure, backend services, shared platform capabilities, and DevSecOps delivery pipelines.
This role acts as the security design authority across platform teams and delivery squads, ensuring the mobile banking platform achieves world-class standards for customer trust, cyber resilience, regulatory compliance, privacy, fraud resistance, and secure customer experience.
Duties & Responsibilities
Primary Domain
Enterprise security architecture across digital banking channels, including mobile, web, API, cloud, identity, payments, data, and DevSecOps ecosystems.
Accountability
Drives the security architecture vision, establishing strategic direction, governance frameworks, control requirements, and architecture standards for critical customer journeys and digital products.
Stakeholders
Engages with cross-functional stakeholders spanning technology, cybersecurity, risk, fraud, compliance, privacy, operations, and executive leadership.
Delivery Model
Operates across agile product teams and architecture review forums to embed security by design while maintaining customer-centricity, platform resilience, and rapid delivery.
- Establish Zero Trust security patterns for applications and services.
- Drive threat modelling and translate risks into security controls and architecture standards.
- Embed Security-by-Design and Privacy-by-Design across the delivery lifecycle.
- Define and govern DevSecOps security controls and release guardrails.
- Oversee penetration testing, vulnerability management, and cyber resilience initiatives.
- Provide security architecture leadership to engineering, product, risk, fraud, and compliance teams.
- Act as the security authority for platform and delivery teams.
- Balance security, customer experience, resilience, and delivery speed.
- Ensure compliance with regulatory requirements and industry-leading security standards.
- Define mobile fraud prevention, device binding, and transaction risk controls.
- Architect trusted devices, cryptographic identities, and device attestation frameworks.
- Establish secure transaction signing and verification for high-risk payments.
- Govern API and communication security, including mTLS, certificate pinning, and secure channels.
- Implement mobile app protection against tampering, malware, reverse engineering, rooting, and jailbreak threats.
- Define controls for bot mitigation, API abuse prevention, and anomaly detection.
- Design secure customer onboarding and adaptive, risk-based authentication.
- Establish security standards for digital payments, wallets, open banking, and real-time payments.
- Govern cloud-native, Kubernetes, and container security architectures.
- Oversee software supply chain security, secure build pipelines, and release integrity.
- Define cyber-resilience strategies, including DDoS protection, disaster recovery, and ransomware resilience.
- Lead security monitoring, logging, auditability, and incident response architecture.
- Assess and govern third-party, fintech, SaaS, and partner integrations.
- Define security controls for AI platforms, intelligent agents, and AI-assisted customer journeys.
- Lead security reviews and risk assessments across digital, cloud, data, AI, and platform domains.
- Serve as the final security authority for production releases, design changes, and security exceptions.
Security Architecture Leadership
- Own mobile banking security architecture.
- Define security standards across mobile, cloud, APIs, and identity.
- Lead authentication, encryption, and key management.
- Drive Zero Trust, threat modelling, and security governance.
- Embed Security-by-Design, Privacy-by-Design, and DevSecOps.
- Oversee testing, vulnerability management, and cyber resilience.
- Provide security leadership across technology and business teams.
- Ensure regulatory compliance and industry best practices.
Mobile, Platform & Fraud Security
- Define fraud prevention, device trust, and transaction security.
- Govern secure APIs, communications, and authentication.
- Protect applications against malware, tampering, and account takeover.
- Implement bot mitigation, anomaly detection, and abuse prevention.
- Design secure onboarding and risk-based authentication.
- Establish security for payments, wallets, and open banking.
- Govern cloud, container, Kubernetes, and supply chain security.
- Lead cyber resilience, monitoring, logging, and incident response.
- Assess third-party and partner security risks.
- Define security controls for AI platforms and intelligent agents.
- Lead security reviews and serve as final release security authority.
Desired Experience & Qualification
- CISSP, CCSP, CISM, SABSA, TOGAF, Azure Security Engineer, AWS Security Specialty, or equivalent security architecture credentials.
- Knowledge of OWASP MASVS, OWASP ASVS, OWASP Mobile Top 10, OWASP API Security Top 10, NIST, ISO 27001, PCI DSS, POPIA, and banking regulatory expectations.
- Exposure to mobile fraud prevention, digital identity, payment security, hardware-backed cryptography, cloud-native security, DevSecOps, and AI security governance.