Job Description:
We are seeking an Open Banking Principal Architect to lead the enterprise architecture strategy, governance, and delivery of next-generation digital capabilities. This role will own the technology roadmap for Open Banking enablement (provider and consumer models), real-time data-sharing frameworks, and secure API ecosystems. The Principal Architect will guide solution teams across mobile, web, integration, security, and cloud, ensuring security-first design, data privacy, and regulatory compliance while balancing platform stability and modernization.
Required Skills & Experience
- 12 20+ years of experience in technology architecture, with strong experience in banking, Open Banking, or financial services.
- Deep expertise in Open Banking standards: FDX, data-sharing frameworks, consent architecture, customer identity.
- Strong experience building API ecosystems using Java/Spring Boot, API gateways, and API management platforms.
- Ability to architect solutions on modern cloud platforms (Azure AKS, AWS EKS, or similar).
- Experience with Apigee or similar integration modernization platforms.
- Broad knowledge of identity, fraud, cybersecurity, compliance, and risk controls.
- Experience with Kafka streaming, event-driven architecture, and real-time data processing.
- Proven track record architecting major technology transformation programs.
Strong executive communication and business-case development skills.
Programming Must Have: Java (advanced), Spring Boot (3.x, reactive patterns), API design; Good to Have: Node.js, React.js
Open Banking Standards Must Have: FDX (hands-on), Digital Banking APIs; Good to Have: BIAN, ISO 20022, PSD2
Open Banking Platforms Must Have: Ninth Wave (hands-on/exposure); Good to Have: Plaid, Tink, MX, Finicity
IDP & Security Must Have: OAuth2.0, OIDC, mTLS with Okta/Ping/Azure AD/ForgeRock; Good to Have: Advanced tokenization and FPE
Consent Management Must Have: Consent & data sharing flows; Good to Have: GDPR/CCPA preference management
Data Security Must Have: Mandatory data masking, logging compliance, secure coding practices; Good to Have: Tokenization, format-preserving encryption (FPE)