Own the end-to-end security architecture for a large-scale, customer-facing mobile banking platform.
Define and govern security across mobile apps, APIs, identity platforms, cloud infrastructure, backend services, shared platforms, and DevSecOps pipelines.
Architect strong customer authentication using PIN, biometrics, device-bound cryptographic keys, risk context, and transaction-level authorization.
Design PIN-based authentication models where PINs unlock cryptographic keys and are never stored or transmitted.
Define biometric-first authentication using Face ID, Touch ID, and platform biometrics through secure enclave and hardware-backed mechanisms.
Govern secure use of mobile keystores and secure enclaves, including iOS Secure Enclave and Android Hardware Keystore.
Ensure biometrics are used only for local cryptographic key release and never treated as raw credentials.
Define integration with enterprise key vaults and HSMs for signing, encryption, certificate handling, and key lifecycle management.
Own OAuth 2.0, OpenID Connect, PKCE, secure token storage, token rotation, and device-bound session models for mobile and web channels.
Define API, Backend-for-Frontend, and service security patterns aligned to Zero Trust principles.
Lead threat modelling across onboarding, authentication, payments, card management, account servicing, and other sensitive customer journeys.
Translate threats into architecture patterns, security controls, non-functional requirements, and architecture decision records.
Embed Security-by-Design into HLDs, LLDs, architecture decision records, release governance, and delivery assurance forums.
Define DevSecOps guardrails including SAST, DAST, dependency scanning, secrets management, container scanning, IaC security, and secure release gates.
Requirements
Mobile security
Authentication
Identity and access
Cryptography
API and platform security
Fraud and risk
DevSecOps
Cloud and infrastructure
Threat and assurance
AI security
Senior-level security architecture experience in digital banking, payments, fintech, financial services, or other regulated customer-facing digital platforms.
Strong hands-on understanding of mobile security, API security, identity, cryptography, cloud security, DevSecOps, platform security, fraud controls, and operational resilience.
Ability to translate business risks and threat scenarios into pragmatic architecture decisions, technical controls, delivery guardrails, and measurable non-functional requirements
Interested in this role?
You'll apply on Sabenza IT's own site before 18 October 2026. Put your most relevant experience at the top of your CV first.