Overview
Lead Security Solution Architect for Banking project ========================================================
Security design authority for all eight CRs – designs Expleo-delivered controls, specifies security requirements for client-delivered components and reviews client designs before build.
Responsibilities
- Produce HLD/LLD for mobile security, PKI segregation, firewall/WAF clustering and traffic segregation
- Define security requirements and acceptance criteria for client-delivered Splunk, OBS and carrier work
- Write interface and security specifications for client-built backend APIs (telemetry, attestation, risk scoring)
- Lead the RASP / mobile threat defence vendor evaluation and recommendation
- Chair the fortnightly design authority and security design reviews
- Assess residual risk and author residual-risk statements for acceptance
- Ensure cross-CR dependencies are designed coherently
- Support threat modelling and security test scoping with the Test Lead
Essential skills
- Enterprise security architecture, zero trust and network segmentation
- Open Banking / Open Finance API security – mTLS, OAuth2, FAPI
- PKI, mobile application security (RASP, attestation) and WAF design
- Security design review of third-party / client-built solutions
Desired skills:* + - ### Good to have
- SIEM architecture (Splunk) and resilience design
- Operational-resilience and concentration-risk frameworks
- UAE PDPL / CBUAE security expectationsTools
---------
draw.io / Visio, Confluence, threat-modelling tools (OWASP Threat Dragon / IriusRisk)
Experience
- 8+ years of experience in software testing, preferably in Banking, Payments or FinTech.
- Experience in BFSI or other regulated-sector programmes
- Clear written and spoken English; Arabic an advantage
- Willingness to travel to the UAE when required
- Eligibility for client background screening and NDA