Senior Security Architect - Mobile Banking Platforms
Company Description
Who is HelloKindred?
HelloKindred are specialists in staffing marketing, creative and technology roles, offering a range of talent solutions that can be delivered on-site, remotely or hybrid.
Our vision is to make work accessible and people’s lives better. We do this by disrupting traditional employment barriers – connecting ambitious talent to flexible opportunities with trusted brands.
Job Description
Anticipated Contract End Date/Length: October 19th, 2026 - February 28th, 2026
Work set up: Onsite
Our client in the global professional services industry is looking for an experienced Senior Security Architect who will be accountable for the end-to-end security architecture of a large-scale, customer-facing mobile banking platform. The role defines, governs, and continuously evolves security across mobile applications, APIs, identity platforms, cloud infrastructure, backend services, shared platform capabilities, and DevSecOps delivery pipelines.
This role acts as the security design authority across platform teams and delivery squads, ensuring the mobile banking platform achieves world-class standards for customer trust, cyber resilience, regulatory compliance, privacy, fraud resistance, and secure customer experience.
What you will do:
- Own the end-to-end security architecture for a large-scale, customer-facing mobile banking platform.
- Define and govern security across mobile apps, APIs, identity platforms, cloud infrastructure, backend services, shared platforms, and DevSecOps pipelines.
- Architect strong customer authentication using PIN, biometrics, device-bound cryptographic keys, risk context, and transaction-level authorization.
- Design PIN-based authentication models where PINs unlock cryptographic keys and are never stored or transmitted.
- Define biometric-first authentication using Face ID, Touch ID, and platform biometrics through secure enclave and hardware-backed mechanisms.
- Govern secure use of mobile keystores and secure enclaves, including iOS Secure Enclave and Android Hardware Keystore.
- Ensure biometrics are used only for local cryptographic key release and never treated as raw credentials.
- Define integration with enterprise key vaults and HSMs for signing, encryption, certificate handling, and key lifecycle management.
- Own OAuth 2.0, OpenID Connect, PKCE, secure token storage, token rotation, and device-bound session models for mobile and web channels.
- Define API, Backend-for-Frontend, and service security patterns aligned to Zero Trust principles.
- Lead threat modelling across onboarding, authentication, payments, card management, account servicing, and other sensitive customer journeys.
- Translate threats into architecture patterns, security controls, non-functional requirements, and architecture decision records.
- Embed Security-by-Design into HLDs, LLDs, architecture decision records, release governance, and delivery assurance forums.
- Define DevSecOps guardrails including SAST, DAST, dependency scanning, secrets management, container scanning, IaC security, and secure release gates.
- Support penetration testing, vulnerability remediation, incident readiness, forensic readiness, and cyber-resilience initiatives.
- Embed Privacy-by-Design, consent management, secure data processing, secure data retention, and data lifecycle controls.
- Act as a security design authority across delivery squads, platform teams, engineering teams, product stakeholders, risk, fraud, and compliance functions.
- Provide clear architectural guidance to Engineering, Product, Operations, Fraud, Risk, and executive technology stakeholders.
- Balance security, customer experience, operational resilience, and delivery velocity.
- Ensure the mobile banking platform meets world-class standards for security, trust, resilience, and regulatory compliance.
Additional Modern Digital Banking Security responsibilities
- Define mobile fraud prevention architecture, including device binding, account takeover prevention, mule account detection integration, and transaction risk scoring.
- Architect device binding and trusted device frameworks using hardware-backed cryptographic identities, secure key stores, and device attestation services.
- Define transaction signing and transaction verification patterns to support non-repudiation and customer protection for high-risk banking transactions.
- Govern certificate pinning, mutual TLS, secure channel enforcement, and secure API communication models.
- Define runtime application self-protection and mobile application shielding strategies to detect and prevent tampering, reverse engineering, instrumentation, rooting, and jailbreak attacks.
- Architect controls against mobile malware, overlays, screen scraping, session hijacking, credential theft, and application manipulation.
- Define mobile and API bot mitigation, API abuse prevention, anomaly detection, and automated attack protection controls.
- Govern API security controls including rate limiting, schema validation, API gateways, threat protection, security testing, and behavioural anomaly monitoring.
- Define secure customer onboarding patterns using device reputation, identity verification, fraud signals, behavioural analytics, and risk-based authentication.
- Architect adaptive authentication using device, location, network, behavioural, transactional, and fraud intelligence signals.
- Establish security patterns for digital wallets, tokenized payments, QR payments, card management, open banking, and real-time payment ecosystems.
- Define cloud-native security controls for containerized workloads, Kubernetes platforms, service meshes, cloud services, and platform engineering environments.
- Govern software supply chain security including signed artefacts, SBOM, dependency risk management, secure build pipelines, provenance verification, and release integrity controls.
- Establish cyber-resilience architecture patterns covering denial-of-service protection, disaster recovery, ransomware resilience, backup integrity, and business continuity.
- Define security monitoring architecture integrating SIEM, SOAR, threat intelligence, fraud monitoring, application telemetry, audit logging, and incident response workflows.
- Govern security logging, auditability, evidentiary controls, and forensic readiness for regulatory investigations and major incident response.
- Assess and govern third-party, fintech, SaaS, martech, payment, and partner integrations from a security architecture perspective.
- Define and govern AI and agentic platform security controls including model security, prompt injection prevention, data leakage protection, secure retrieval, authorization, auditability, and responsible AI guardrails.
- Embed security architecture controls for AI-assisted customer journeys, intelligent agents, digital servicing capabilities, and enterprise AI platforms.
- Lead security architecture reviews and risk assessments across Mobile, Web, Backend, Data, Martech, AI, Cloud, Infrastructure, DevOps, Testing, and Shared Platform domains.
- Act as the final security architecture authority for production releases, significant design changes, security waivers, and exceptions impacting the digital banking platform.
Qualifications
- 10+ years of relevant Security Architecture experience, ideally within banking, payments, fintech, financial services, or other regulated digital environments.
- Senior-level security architecture experience in digital banking, payments, fintech, financial services, or other regulated customer-facing digital platforms.
- Strong hands-on understanding of mobile security, API security, identity, cryptography, cloud security, DevSecOps, platform security, fraud controls, and operational resilience.
- Ability to translate business risks and threat scenarios into pragmatic architecture decisions, technical controls, delivery guardrails, and measurable non-functional requirements.
- Proven ability to work across engineering, product, architecture, cybersecurity, risk, compliance, fraud, privacy, operations, and executive stakeholders.
- Strong communication skills with the ability to explain complex security topics clearly to technical and non-technical audiences.
- Pragmatic delivery mindset with the ability to balance security assurance, customer experience, regulatory expectations, and delivery timelines.
- CISSP, CCSP, CISM, SABSA, TOGAF, Azure Security Engineer, AWS Security Specialty, or equivalent security architecture credentials.
- Knowledge of OWASP MASVS, OWASP ASVS, OWASP Mobile Top 10, OWASP API Security Top 10, NIST, ISO 27001, PCI DSS, POPIA, and banking regulatory expectations.
- Exposure to mobile fraud prevention, digital identity, payment security, hardware-backed cryptography, cloud-native security, DevSecOps, and AI security governance.
- Candidates must have a clear background check (BGC), including an ITC (credit) check, to be considered for the role.
Additional Information
Candidates must be legally authorized to live and work in the country where the position is based, without requiring employer sponsorship.
HelloKindred is committed to fair, transparent, and inclusive hiring practices. We assess candidates based on skills, experience, and role-related requirements.
We appreciate your interest in this opportunity. While we review every application carefully, only candidates selected for an interview will be contacted.
HelloKindred is an equal opportunity employer. We welcome applicants of all backgrounds and do not discriminate on the basis of race, colour, religion, sex, gender identity or expression, sexual orientation, age, national origin, disability, veteran status, or any other protected characteristic under applicable law.
Job Details
Experience
Senior · 10+ yrs