Principal Digital Security Architect
at Encora10
- Seniority
- Staff Principal
- Location
- Kuala Lumpur
- Posted
- 5d ago
at Encora10
<p>Key Responsibilities <br>1. API & Ecosystem Architecture <br>● The API Fortress: Architect the security layer for our API Gateway (e.g., Kong, <br>Apigee, AWS Gateway). Define global policies for Rate Limiting, Throttling, and <br>Authorization (preventing BOLA/IDOR attacks). <br>● Supply Chain Security: Design secure integration patterns for our 3rd party partners <br>(Fintechs, Credit Bureaus, Payment Processors). Ensure their insecurities do not <br>become our breaches. <br>● Microservices Mesh: Define how our internal services trust each other. Move from <br>"Network Trust" to "Cryptographic Trust" using mTLS and Service-to-Service <br>authentication. </p> <p>2. Identity & Access Management (CIAM) <br>● Identity Strategy: Own the architecture for Customer Identity (CIAM). Design flows for <br>Biometric Binding, Adaptive MFA, and Step-Up Authentication for high-value <br>transactions. <br>● Token Lifecycle: Define the standards for OAuth 2.0 and OpenID Connect (OIDC). <br>Ensure we are using Financial-grade API (FAPI) standards for token issuance, <br>revocation, and storage. </p> <p>3. Secure Development Lifecycle (SDLC) <br>● Threat Modeling: Lead "Whiteboard Hacking" sessions with product owners. Identify <br>business logic flaws (e.g., race conditions in ledgers, bypassable KYC steps) before a <br>single line of code is written. <br>● Paved Roads: Work with DevOps to architect secure-by-default libraries. (Example: <br>Create a standard "Encryption Wrapper" library that all developers must use, so they <br>don't invent their own crypto). </p> <p>4. Data Privacy & Cryptography <br>● Data Defense: Define the architecture for Field-Level Encryption (FLE) in the <br>database for PII and Banking Secrets. <br>● Privacy Engineering: Architect systems that support "Right to be Forgotten" <br>(GDPR/CCPA) without breaking the immutability of the financial ledger. <br>Strategic Deliverables <br>● Identity Patterns: Deliver new security design patterns and components for <br>authentication, authorization, SSO, MFA, and Partner security to ensure seamless and <br>secure user access. <br>● Mobile & Edge: Deliver new security design patterns and components for Mobile <br>security, ensuring consistency between iOS, Android, and the backend. <br>● Modern Tech Stack: Deliver API, container, cloud, and AI security design patterns to <br>support the bank's move toward intelligent, cloud-native infrastructure. </p> <p>What We Are Looking For </p> <p>1. The Background <br>● 8+ Years Experience: A mix of Software Engineering and Security Architecture. <br>● Ex-Developer: You must be able to read code (Java, Kotlin, React or Node.js, ). <br>● Banking/Fintech Experience: Strong preference for candidates who have secured <br>payment gateways, ledgers, or wallets. </p> <p>2. The Technical Skills <br>● API Security: Deep mastery of REST and GraphQL security. <br>● Auth Protocols: You can draw the OAuth 2.0 Authorization Code Flow with PKCE <br>from memory. You understand JWT signing and JWKS key rotation. <br>● Mobile Security: Understanding of how mobile apps store secrets <br>(KeyStore/Keychain) and how to prevent API abuse from emulators/bots. </p> <p>3. The Mindset <br>● Business Aligned: You understand that a bank exists to process transactions. You <br>design security that reduces risk without destroying the User Experience (UX). <br>● Pragmatic: You know when to demand a "Blocker" fix and when to accept a "Risk <br>Acceptance" waiver.</p>