Search thousands of fresh jobs

×
This job is expired
GoldenRule

Senior Security Architect (Mobile Banking Platforms)

GoldenRule

  • R Undisclosed
  • Contract Senior position
  • Johannesburg
  • Posted 21 Sep 2026 by GoldenRule
  • Expires in 34 days
  • Job 2645322 - Ref GDR03836

About the position

ROLE


The Senior Security Architect is accountable for the end-to-end security architecture of a customer-facing mobile banking platform. The role defines, governs, and continuously evolves security across mobile applications, APIs, identity platforms, cloud infrastructure, backend services, shared platforms, and DevSecOps delivery pipelines.


KEY RESPONSIBILITIES



  • Own the end-to-end security architecture and define security across mobile apps, APIs, identity platforms, cloud infrastructure, backend services, shared platforms, and DevSecOps pipelines.

  • Architect customer authentication using PIN, biometrics, device-bound cryptographic keys, risk context, and transaction-level authorisation. Govern secure use of mobile keystores.

  • Own OAuth 2.0, OpenID Connect, PKCE, secure token storage, token rotation, and device-bound session models. Define API, Backend-for-Frontend, and service security patterns aligned to Zero Trust principles.

  • Lead threat modelling across onboarding, authentication, payments, card management, account servicing, and other sensitive customer journeys. Translate threats into architecture patterns, security controls, security requirements, and architecture decision records.

  • Embed Security-by-Design into architecture, release governance, and delivery assurance. Define DevSecOps guardrails including SAST, DAST, dependency scanning, secrets management, container scanning, IaC security, and secure release gates.

  • Support penetration testing, vulnerability remediation, incident readiness, and cyber-resilience initiatives. Embed Privacy-by-Design, consent management, secure data processing, retention, and data lifecycle controls.

  • Act as a security design authority across delivery squads, engineering, product, risk, and compliance functions. Balance security, customer experience, operational resilience, and delivery velocity.

  • Define mobile fraud prevention architecture, device binding, transaction risk scoring, adaptive authentication, API abuse prevention, and anomaly detection.

  • Define cloud-native security controls for containerized workloads, Kubernetes, service meshes, and cloud services. Establish cyber-resilience architecture covering disaster recovery, ransomware resilience, backup integrity, and business continuity.

  • Define security monitoring architecture integrating SIEM, SOAR, threat intelligence, fraud monitoring, audit logging, and incident response workflows.

  • Assess and govern third-party, fintech, SaaS, payment, and partner integrations. Define and govern AI and agentic platform security controls including model security, prompt injection prevention, data leakage protection, secure retrieval, authorisation, auditability, and responsible AI guardrails.

  • Lead security architecture reviews and risk assessments across Mobile, Web, Backend, Data, AI, Cloud, Infrastructure, DevOps, Testing, and Shared Platform domains. Act as the final security architecture authority for production releases and significant design changes.

EXPERIENCE CAPABILITY



  • Senior-level security architecture experience in digital banking, payments, fintech, financial services, or other regulated customer-facing digital platforms.

  • Strong hands-on understanding of mobile security, API security, identity, cryptography, cloud security, DevSecOps, platform security, fraud controls, and operational resilience.

  • Ability to translate business risks and threat scenarios into pragmatic architecture decisions, technical controls, delivery guardrails, and measurable security requirements.

  • Proven ability to work across engineering, product, architecture, cybersecurity, risk, compliance, fraud, privacy, operations, and executive stakeholders. Strong communication skills with technical and non-technical audiences.


CORE TECHNICAL REQUIREMENTS



  • Mobile security: iOS and Android application security, secure storage, platform security models, jailbreak/root detection, hardening, secure local data handling, mobile threat defence, and application shielding.

  • Authentication: PIN-based authentication, biometrics, device-bound credentials, step-up authentication, adaptive authentication, risk-based authentication, and transaction-level authorisation.

  • Identity and access: OAuth 2.0, OpenID Connect, PKCE, secure token handling, session management, token rotation, device-bound sessions, and delegated authorisation.

  • Cryptography: cryptographic key lifecycle management, HSM integration, enterprise key vaults, hardware-backed keystores, secure enclave usage, signing, encryption, certificate lifecycle, and cryptographic standards.

  • API and platform security: API gateway security, BFF security, Zero Trust, rate limiting, bot protection, API abuse prevention, schema validation, threat protection, mTLS, and certificate pinning.

  • Fraud and risk: device binding, device attestation, account takeover prevention, transaction risk scoring, behavioural analytics, fraud platform integration, and high-risk transaction controls.

  • DevSecOps: SAST, DAST, dependency scanning, secret scanning, container scanning, IaC scanning, secure release gates, signed artefacts, SBOM, supply chain security, and secure build pipelines.

  • Cloud and infrastructure: cloud security architecture across Azure, AWS, or GCP, Kubernetes security, container security, service mesh security, workload identity, network security, and platform resilience.

  • Threat and assurance: threat modelling, secure design reviews, security NFRs, penetration testing support, vulnerability remediation, incident readiness, security monitoring, logging, and forensic readiness.

  • AI security: AI and agentic platform security, secure retrieval patterns, prompt injection controls, data leakage prevention, model access control, responsible AI guardrails, and AI auditability.

REGULATORY, STANDARDS GOVERNANCE



  • Ensure compliance with applicable banking, payments, cyber, and data protection regulations, including POPIA, PCI DSS, SARB, FSCA guidance, and related organisational security policies.

  • Align security architecture with recognised standards and frameworks including ISO 27001, NIST Cybersecurity Framework, OWASP MASVS, OWASP ASVS, OWASP API Security Top 10, CIS benchmarks, and Zero Trust architecture principles.

  • Define, review, and govern security architecture artefacts including HLDs, LLDs, architecture decision records, threat models, security NFRs, risk acceptances, and exception records.

  • Partner with risk, fraud, compliance, privacy, legal, and operational resilience teams to ensure governance, auditability, and regulatory assurance.


ARCHITECTURE ARTEFACTS



  • Security architecture vision, principles, patterns, and guardrails. Mobile authentication architecture, device binding models, session management, and transaction authorisation patterns.

  • Threat models for onboarding, login, payments, card servicing, profile changes, and sensitive journeys. Security NFRs, secure coding standards, secure integration patterns, and technical control requirements.

  • Cryptography and key management architecture, including keystores, HSMs, key vaults, certificates, and signing models. API security architecture, BFF security patterns, Zero Trust controls, and API abuse prevention models.

  • DevSecOps control architecture, secure pipeline guardrails, release assurance criteria, and supply chain security controls.

  • Operational security, monitoring, logging, incident readiness, and forensic readiness architecture. AI and agentic platform security architecture patterns for intelligent agents or AI-assisted capabilities.


DESIRED CERTIFICATIONS KNOWLEDGE



  • CISSP, CCSP, CISM, SABSA, TOGAF, Azure Security Engineer, AWS Security Specialty, or equivalent security architecture credentials.

  • Knowledge of OWASP MASVS, OWASP ASVS, OWASP Mobile Top 10, OWASP API Security Top 10, NIST, ISO 27001, PCI DSS, POPIA, and banking regulatory expectations.

  • Exposure to mobile fraud prevention, digital identity, payment security, hardware-backed cryptography, cloud-native security, DevSecOps, and AI security governance.


SUCCESS OUTCOMES



  • A governed, secure, scalable, and resilient mobile banking platform architecture that supports trusted digital banking at enterprise scale.

  • Authentication and authorisation models that protect customers while preserving a simple and reliable digital experience.

  • Security controls embedded early in solution design and automated through delivery pipelines wherever possible.

  • Clear security decision-making across squads, architecture forums, risk governance, and release assurance processes.

  • Reduced security, fraud, privacy, and resilience risk across critical customer journeys and platform services.

Desired Skills:

  • Systems Analysis
  • Complex Problem Solving
  • Programming/configuration
  • Critical Thinking
  • Time Management

GoldenRule

About the agency

GoldenRule is positioned as a Strategic Resourcing Partner. We are IT Services company with a Total solution offering around staffing issues. We currently offer the following services: * Contracting of GoldenRule fulltime staff to our clients for in-house or external projects. * Permanent placements * Temporary placements to permanent placements * Allowing our fulltime employees to accept job offers from our clients to add further value. * All candidates are technically evaluated for each position. (GoldenRule makes use of an In-house evaluation methodology and Teckcheck) * Hosting learnerships. We hold the risk in developing junior resources. Ideal for AA candidates. * We are able to provided local, AA and international skills. * With international resources meticulous attention is given to Work Permit issues and the relocation of our employees. GoldenRule has an attentive program for relocation and integration of our employees into South Africa. This includes accommodation in furnished guesthouses, transport to and from work, assistance with various forms of finance and obtaining banking products etc.

Receive a daily digest of all new jobs matching this job. Your information is safe with us and you can cancel any time.

Expires in 33 days

Email me jobs similar to: Senior Security Architect (Mobile Banking Platforms)

Receive a daily digest of all new jobs matching this job: Senior IT Auditor. Your information is safe with us and you can cancel at any time.