Rivonia, South Africa | Posted on 21/09/2026
Senior Security Architect — Mobile BankingPlatforms
Millions of people open a banking app andexpect it to just work. Fast. Simple. Safe. That last part is not a slogan. Itis the architecture.
This role owns the security design of alarge-scale, customer-facing mobile banking platform — iOS, Android, web, APIs,identity, cloud, payments, and the pipelines that ship change every sprint.
You are the person who decides how trustis built into the product before a line of code hits production.
Role Purpose
The Senior Security Architect isaccountable for the end-to-end security architecture of a large-scale,customer-facing mobile banking platform. The role defines, governs, andcontinuously evolves security across mobile applications, APIs, identityplatforms, cloud infrastructure, backend services, shared platformcapabilities, and DevSecOps delivery pipelines.
This role acts as the security designauthority across platform teams and delivery squads, ensuring the mobilebanking platform achieves world-class standards for customer trust, cyberresilience, regulatory compliance, privacy, fraud resistance, and securecustomer experience.
Key Responsibilities
- Own the end-to-end security architecturefor a large-scale, customer-facing mobile banking platform.
- Define and govern security across mobileapps, APIs, identity platforms, cloud infrastructure, backend services, sharedplatforms, and DevSecOps pipelines.
- Architect strong customer authenticationusing PIN, biometrics, device-bound cryptographic keys, risk context, andtransaction-level authorization.
- Design PIN-based authentication modelswhere PINs unlock cryptographic keys and are never stored or transmitted.
- Define biometric-first authenticationusing Face ID, Touch ID, and platform biometrics through secure enclave andhardware-backed mechanisms.
- Govern secure use of mobile keystores andsecure enclaves, including iOS Secure Enclave and Android Hardware Keystore.
- Ensure biometrics are used only for localcryptographic key release and never treated as raw credentials.
- Define integration with enterprise keyvaults and HSMs for signing, encryption, certificate handling, and keylifecycle management.
- Own OAuth 2.0, OpenID Connect, PKCE,secure token storage, token rotation, and device-bound session models formobile and web channels.
- Define API, Backend-for-Frontend, andservice security patterns aligned to Zero Trust principles.
- Lead threat modelling across onboarding,authentication, payments, card management, account servicing, and othersensitive customer journeys.
- Translate threats into architecturepatterns, security controls, non-functional requirements, and architecturedecision records.
- Embed Security-by-Design into HLDs, LLDs,architecture decision records, release governance, and delivery assuranceforums.
- Define DevSecOps guardrails includingSAST, DAST, dependency scanning, secrets management, container scanning, IaCsecurity, and secure release gates.
Requirements
- Identity and access
- Cryptography
- API and platform security
- Fraud and risk
- DevSecOps
- Cloud and infrastructure
- Threat and assurance
- AI security
- Senior-level security architectureexperience in digital banking, payments, fintech, financial services, or otherregulated customer-facing digital platforms.
- Strong hands-on understanding of mobilesecurity, API security, identity, cryptography, cloud security, DevSecOps,platform security, fraud controls, and operational resilience.
- Ability to translate business risks andthreat scenarios into pragmatic architecture decisions, technical controls,delivery guardrails, and measurable non-functional requirements