702,472open jobs
41,481companies
101,716added this week
Browse all
Salary
$72k – $88k per year
Location
In office (Johannesburg)
Seniority
Senior · 10+ years exp
Employment
Contractor
Overview
Company
Impact
Profile match
HelloKindred is a talent company founded in 2009 that places marketing, creative and digital specialists with employers on a flexible basis, working across the United Kingdom, Europe, North America and South Africa. It concentrates deliberately on marketing and creative roles rather than general technology recruitment, supplying designers, content specialists, campaign managers, digital producers and marketing technologists on contract, project or fractional terms. Headquartered in London, it advertises client vacancies under its own name and pitches flexible senior talent as an alternative to permanent hires in a function where workload arrives in bursts.

Who is HelloKindred?

HelloKindred are specialists in staffing marketing, creative and technology roles, offering a range of talent solutions that can be delivered on-site, remotely or hybrid.

Our vision is to make work accessible and people’s lives better. We do this by disrupting traditional employment barriers - connecting ambitious talent to flexible opportunities with trusted brands.

Anticipated Contract End Date/Length: October 19th, 2026 - February 28th, 2026

Work set up: Onsite

Our client in the global professional services industry is looking for an experienced Senior Security Architect who will be accountable for the end-to-end security architecture of a large-scale, customer-facing mobile banking platform. The role defines, governs, and continuously evolves security across mobile applications, APIs, identity platforms, cloud infrastructure, backend services, shared platform capabilities, and DevSecOps delivery pipelines.

This role acts as the security design authority across platform teams and delivery squads, ensuring the mobile banking platform achieves world-class standards for customer trust, cyber resilience, regulatory compliance, privacy, fraud resistance, and secure customer experience.

What you will do:

  • Own the end-to-end security architecture for a large-scale, customer-facing mobile banking platform.
  • Define and govern security across mobile apps, APIs, identity platforms, cloud infrastructure, backend services, shared platforms, and DevSecOps pipelines.
  • Architect strong customer authentication using PIN, biometrics, device-bound cryptographic keys, risk context, and transaction-level authorization.
  • Design PIN-based authentication models where PINs unlock cryptographic keys and are never stored or transmitted.
  • Define biometric-first authentication using Face ID, Touch ID, and platform biometrics through secure enclave and hardware-backed mechanisms.
  • Govern secure use of mobile keystores and secure enclaves, including iOS Secure Enclave and Android Hardware Keystore.
  • Ensure biometrics are used only for local cryptographic key release and never treated as raw credentials.
  • Define integration with enterprise key vaults and HSMs for signing, encryption, certificate handling, and key lifecycle management.
  • Own OAuth 2.0, OpenID Connect, PKCE, secure token storage, token rotation, and device-bound session models for mobile and web channels.
  • Define API, Backend-for-Frontend, and service security patterns aligned to Zero Trust principles.
  • Lead threat modelling across onboarding, authentication, payments, card management, account servicing, and other sensitive customer journeys.
  • Translate threats into architecture patterns, security controls, non-functional requirements, and architecture decision records.
  • Embed Security-by-Design into HLDs, LLDs, architecture decision records, release governance, and delivery assurance forums.
  • Define DevSecOps guardrails including SAST, DAST, dependency scanning, secrets management, container scanning, IaC security, and secure release gates.
  • Support penetration testing, vulnerability remediation, incident readiness, forensic readiness, and cyber-resilience initiatives.
  • Embed Privacy-by-Design, consent management, secure data processing, secure data retention, and data lifecycle controls.
  • Act as a security design authority across delivery squads, platform teams, engineering teams, product stakeholders, risk, fraud, and compliance functions.
  • Provide clear architectural guidance to Engineering, Product, Operations, Fraud, Risk, and executive technology stakeholders.
  • Balance security, customer experience, operational resilience, and delivery velocity.
  • Ensure the mobile banking platform meets world-class standards for security, trust, resilience, and regulatory compliance.

Additional Modern Digital Banking Security responsibilities

  • Define mobile fraud prevention architecture, including device binding, account takeover prevention, mule account detection integration, and transaction risk scoring.
  • Architect device binding and trusted device frameworks using hardware-backed cryptographic identities, secure key stores, and device attestation services.
  • Define transaction signing and transaction verification patterns to support non-repudiation and customer protection for high-risk banking transactions.
  • Govern certificate pinning, mutual TLS, secure channel enforcement, and secure API communication models.
  • Define runtime application self-protection and mobile application shielding strategies to detect and prevent tampering, reverse engineering, instrumentation, rooting, and jailbreak attacks.
  • Architect controls against mobile malware, overlays, screen scraping, session hijacking, credential theft, and application manipulation.
  • Define mobile and API bot mitigation, API abuse prevention, anomaly detection, and automated attack protection controls.
  • Govern API security controls including rate limiting, schema validation, API gateways, threat protection, security testing, and behavioural anomaly monitoring.
  • Define secure customer onboarding patterns using device reputation, identity verification, fraud signals, behavioural analytics, and risk-based authentication.
  • Architect adaptive authentication using device, location, network, behavioural, transactional, and fraud intelligence signals.
  • Establish security patterns for digital wallets, tokenized payments, QR payments, card management, open banking, and real-time payment ecosystems.
  • Define cloud-native security controls for containerized workloads, Kubernetes platforms, service meshes, cloud services, and platform engineering environments.
  • Govern software supply chain security including signed artefacts, SBOM, dependency risk management, secure build pipelines, provenance verification, and release integrity controls.
  • Establish cyber-resilience architecture patterns covering denial-of-service protection, disaster recovery, ransomware resilience, backup integrity, and business continuity.
  • Define security monitoring architecture integrating SIEM, SOAR, threat intelligence, fraud monitoring, application telemetry, audit logging, and incident response workflows.
  • Govern security logging, auditability, evidentiary controls, and forensic readiness for regulatory investigations and major incident response.
  • Assess and govern third-party, fintech, SaaS, martech, payment, and partner integrations from a security architecture perspective.
  • Define and govern AI and agentic platform security controls including model security, prompt injection prevention, data leakage protection, secure retrieval, authorization, auditability, and responsible AI guardrails.
  • Embed security architecture controls for AI-assisted customer journeys, intelligent agents, digital servicing capabilities, and enterprise AI platforms.
  • Lead security architecture reviews and risk assessments across Mobile, Web, Backend, Data, Martech, AI, Cloud, Infrastructure, DevOps, Testing, and Shared Platform domains.
  • Act as the final security architecture authority for production releases, significant design changes, security waivers, and exceptions impacting the digital banking platform.
  • 10+ years of relevant Security Architecture experience, ideally within banking, payments, fintech, financial services, or other regulated digital environments.
  • Senior-level security architecture experience in digital banking, payments, fintech, financial services, or other regulated customer-facing digital platforms.
  • Strong hands-on understanding of mobile security, API security, identity, cryptography, cloud security, DevSecOps, platform security, fraud controls, and operational resilience.
  • Ability to translate business risks and threat scenarios into pragmatic architecture decisions, technical controls, delivery guardrails, and measurable non-functional requirements.
  • Proven ability to work across engineering, product, architecture, cybersecurity, risk, compliance, fraud, privacy, operations, and executive stakeholders.
  • Strong communication skills with the ability to explain complex security topics clearly to technical and non-technical audiences.
  • Pragmatic delivery mindset with the ability to balance security assurance, customer experience, regulatory expectations, and delivery timelines.
  • CISSP, CCSP, CISM, SABSA, TOGAF, Azure Security Engineer, AWS Security Specialty, or equivalent security architecture credentials.
  • Knowledge of OWASP MASVS, OWASP ASVS, OWASP Mobile Top 10, OWASP API Security Top 10, NIST, ISO 27001, PCI DSS, POPIA, and banking regulatory expectations.
  • Exposure to mobile fraud prevention, digital identity, payment security, hardware-backed cryptography, cloud-native security, DevSecOps, and AI security governance.
  • Candidates must have a clear background check (BGC), including an ITC (credit) check, to be considered for the role.

Candidates must be legally authorized to live and work in the country where the position is based, without requiring employer sponsorship.

HelloKindred is committed to fair, transparent, and inclusive hiring practices. We assess candidates based on skills, experience, and role-related requirements.

We appreciate your interest in this opportunity. While we review every application carefully, only candidates selected for an interview will be contacted.

HelloKindred is an equal opportunity employer. We welcome applicants of all backgrounds and do not discriminate on the basis of race, colour, religion, sex, gender identity or expression, sexual orientation, age, national origin, disability, veteran status, or any other protected characteristic under applicable law.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
702,472 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Johannesburg
In office • Full-Time • Lagos
Python
Go
Ruby
Python
Flask
Ruby
Ruby on Rails
RSpec
Sidekiq
Databases
MySQL
PostgreSQL
DynamoDB
Google BigQuery
Amazon Aurora
BigQuery
AI/ML
LLM
DevOps
GCP
GitHub Actions
CI/CD
AWS
Kubernetes
Amazon S3
Amazon Kinesis
Apply
$89k – $234k per year (Estimated) • In office • Full-Time • Lagos
Python
Go
Ruby
Python
Flask
Ruby
Ruby on Rails
RSpec
Sidekiq
Databases
MySQL
PostgreSQL
DynamoDB
Google BigQuery
Amazon Aurora
BigQuery
AI/ML
LLM
DevOps
GCP
GitHub Actions
CI/CD
AWS
Kubernetes
Amazon S3
Amazon Kinesis
Apply
$115k – $281k per year (Estimated) • In office • Lagos
Python
Go
Ruby
Python
Flask
Ruby
Ruby on Rails
RSpec
Sidekiq
Databases
MySQL
PostgreSQL
DynamoDB
Google BigQuery
Amazon Aurora
BigQuery
DevOps
GCP
GitHub Actions
CI/CD
AWS
Kubernetes
Amazon S3
Amazon Kinesis
Apply
$24k – $53k per year (Estimated) • In office • Full-Time • 10+ years exp • PhD • Hyderabad
Python
PowerShell
Databases
Snowflake
Databricks
AI/ML
Replicate
DevOps
Rest API
Terraform
Azure DevOps
Azure
CI/CD
AWS
Platform Engineering
Configuration Management
Incident Management
SLI/SLO/SLA
IAM
Cybersecurity
SOC 2
Analytics
Talend
Cryptography
Vault
Apply
$90k – $158k per year • Remote/Hybrid • Full-Time • 8+ years exp • Bachelor's Degree • Princeton • Boston
Python
Java
C#
C++
Java
Apache Tomcat
DevOps
Azure
AWS
GitHub
Unix
Management
Jira
Agile
Apply
$30k – $36k per year • In office • Contractor • 4+ years exp • Mexico City
Design
Adobe Photoshop
Adobe After Effects
Canva
Management
Asana
Marketing
HubSpot
Apply
up to $124k per year • Remote/Hybrid • Contractor • Sheffield
PowerShell
DevOps
Terraform
Azure DevOps
GitHub Actions
Packer
Azure
CI/CD
Platform Engineering
Bicep
DNS
Cybersecurity
Microsoft Entra ID
Apply
up to $64k per year • In office • Contractor • Johannesburg
DevOps
CI/CD
Management
Agile
Scrum
Kanban
Apply
Lead Data Engineer 1 day ago
up to $158k per year • In office • Confidential • Contractor • London
R
R
dplyr
data.table
DevOps
Git
GitHub
Apply
up to $55k per year • In office • Contractor • 8+ years exp • Johannesburg
Management
Asana
Monday.com
Apply
$21k – $42k per year (Estimated) • In office • Full-Time • 3+ years exp • Bachelor's Degree • Johannesburg
Apply
$33k – $80k per year (Estimated) • In office • Full-Time • Johannesburg
Apply
$36k – $79k per year (Estimated) • In office • Full-Time • 10+ years exp • Bachelor's Degree • Johannesburg
Apply
In office • Part-Time • Johannesburg
Apply
$33k – $41k per year (gross) • In office • Part-Time • Johannesburg
Apply
See all jobs
This is one of many
702,472 more open roles from verified company boards, updated every day.