Senior Security Architect - Mobile Banking Platforms

Recruitco · Rivonia

Stop applying one at a time.

JobAlertsZA auto-applies to South African jobs like this one for you, overnight. Upload your CV once — we do the applying.

Start free — we apply for you →

Introduction

Senior Security Architect - Mobile Banking Platforms

Location: JHB North - Rivonia

Type:  3-Months Contract (Short-term)

Resources Required: x2 People Required

Seniority Level: between 5+ to 10+ yrs experience

The Senior Security Architect is accountable for the end-to-end security architecture of a large-scale, customer-facing mobile banking platform. The role defines, governs, and continuously evolves security across mobile applications, APIs, identity platforms, cloud infrastructure, backend services, shared platform capabilities, and DevSecOps delivery pipelines. This role acts as the security design authority across platform teams and delivery squads, ensuring the mobile banking platform achieves world-class standards for customer trust, cyber resilience, regulatory compliance, privacy, fraud resistance, and secure customer experience.

Duties & Responsibilities

Role Scope

  • Primary domain: Mobile banking platform security architecture across iOS, Android, web, APIs, BFF, cloud, identity, payments, data, DevSecOps, and platform services.
  • Accountability: Owns security architecture direction, patterns, architecture decisions, control requirements, and governance across critical customer journeys.
  • Stakeholders: Engineering, product, platform teams, cybersecurity, risk, fraud, compliance, privacy, operations, infrastructure, and executive technology leadership.
  • Delivery model: Works across agile delivery squads and architecture governance forums to balance security, customer experience, resilience, and delivery velocity.

Duties and Responsibilities

  • Own the end-to-end security architecture for a large-scale, customer-facing mobile banking platform.
  • Define and govern security across mobile apps, APIs, identity platforms, cloud infrastructure, backend services, shared platforms, and DevSecOps pipelines.
  • Architect strong customer authentication using PIN, biometrics, device-bound cryptographic keys, risk context, and transaction-level authorization.
  • Design PIN-based authentication models where PINs unlock cryptographic keys and are never stored or transmitted.
  • Define biometric-first authentication using Face ID, Touch ID, and platform biometrics through secure enclave and hardware-backed mechanisms.
  • Govern secure use of mobile keystores and secure enclaves, including iOS Secure Enclave and Android Hardware Keystore.
  • Ensure biometrics are used only for local cryptographic key release and never treated as raw credentials.
  • Define integration with enterprise key vaults and HSMs for signing, encryption, certificate handling, and key lifecycle management.
  • Own OAuth 2.0, OpenID Connect, PKCE, secure token storage, token rotation, and device-bound session models for mobile and web channels.
  • Define API, Backend-for-Frontend, and service security patterns aligned to Zero Trust principles.
  • Lead threat modelling across onboarding, authentication, payments, card management, account servicing, and other sensitive customer retirement, and data lifecycle controls.

Desired Experience & Qualification

Required Qualifications: TOGAF

Skills: Mobile security, iOS and Android application security, secure storage, platform security models, jailbreak/root detection, hardening, secure local data handling, mobile threat defense, and mobile application, Authentication PIN-based authentication, biometrics, device-bound credentials, step-up authentication, adaptive authentication, risk-based authentication, and transaction-level authorization., Identity and access OAuth 2.0, OpenID Connect, PKCE, secure token handling, secure session management, token rotation, device-bound sessions, and delegated authorization patterns., Cryptography Cryptographic key lifecycle management, HSM integration, enterprise key vaults, hardware-backed keystores, secure enclave usage, signing, encryption, certificate lifecycle, and cryptography.

Fraud and Risk: Device binding, device attestation, account takeover prevention, transaction risk scoring, behavioral analytics, fraud platform integration, and high-risk transaction controls.

Package & Remuneration

R500 - R800 per hour

Interested?

Ready to Apply?

Interested candidates can send their CV to

\uD83D\uDCE7 kgomotso@osourceint.com

Subject: Senior Security Architect - Mobile Banking Platforms. Only shortlisted candidates will be contacted.

Auto-apply to this jobView original posting ↗
Senior Security Architect - Mobile Banking Platforms at Recruitco — Rivonia · JobAlertsZA