Role Purpose:
Design and govern the technical architecture of Phoenix's software platforms, including TAKYEEM, by setting engineering standards and guiding development teams and vendors, in order to deliver secure, scalable and reliable solutions that support business growth.
Accountability Area:
Solution Architecture & Governance:
Translate functional and non-functional requirements into solution architectures by running technical discovery workshops with business owners and modelling components, data flows and deployments using the C4 model to provide development teams with an approved, build-ready technical blueprint that reduces rework, design ambiguity and late-stage change requests.
Select the appropriate architectural pattern (microservices, modular monolith, event-driven, multi-tenant SaaS) by evaluating scalability, cost, complexity and team capability through a weighted trade-off analysis to ensure each solution is right-sized for its expected load, budget and growth path, avoiding both over-engineering and premature re-platforming.
Establish architecture principles, reference architectures, coding standards and approved technology stacks by benchmarking against industry frameworks and publishing them in a central engineering handbook to deliver a unified, predictable engineering approach across all applications and teams, reducing integration issues and onboarding time.
Control technical debt by logging, sizing and prioritizing debt items in the product backlog while reserving a fixed share of each sprint for remediation to keep technical debt visible, measured and continuously reduced, sustaining delivery speed and lowering long-term maintenance cost.
Application Security Architecture:
Design identity and access management by implementing OAuth 2.0, OpenID Connect, single sign-on, multi-factor authentication and role-based access control through a central identity provider to ensure only authenticated and authorized users access each platform function, eliminating shared credentials and reducing the risk of account compromise.
Enforce encryption of data in transit and at rest by mandating TLS 1.2 or higher, AES-256 storage encryption and managed key vaults with automated key rotation to safeguard candidate, client and assessment data against interception or disclosure, meeting contractual and regulatory confidentiality obligations.
Detect vulnerabilities early by conducting threat modelling (STRIDE) at design stage and integrating static, dynamic and dependency security testing into the delivery pipeline to release software with zero known critical or high-severity vulnerabilities, reducing exposure to breaches and the cost of fixing issues in production.
Align system design with ISO/IEC 27001 controls and data protection laws (GDPR, UAE PDPL, KSA PDPL) by mapping each control to architecture components while coordinating with legal and information security focal points to demonstrate auditable compliance with security and data protection requirements in every market served, enabling Phoenix to pass client security reviews and procurement qualifications.
Systems Integration & API Architecture:
Design RESTful and GraphQL APIs by applying an API-first approach, OpenAPI 3.0 specifications and standard versioning, pagination and error-handling conventions to offer stable, self-documented and backward-compatible interfaces that internal teams and partners can consume quickly without breaking existing integrations.
Architect integrations between TAKYEEM, the ERP, the CRM, assessment publisher platforms and client HR systems by defining canonical data models, field mappings and synchronization rules to achieve end-to-end automated data flow between business systems, eliminating manual re-entry, reconciliation errors and reporting delays.
Secure and control API traffic by deploying an API gateway with authentication, throttling, rate limiting and usage analytics policies to shield back-end services from misuse and traffic spikes while giving full visibility of API usage per client and partner.
Enable reliable asynchronous processing by designing message queues, publish-subscribe topics and webhook patterns on message brokers (RabbitMQ, Kafka, Azure Service Bus) with retry and dead-letter handling to guarantee reliable, ordered and recoverable processing of high-volume events, with zero data loss during peak assessment campaigns.
Cloud Infrastructure & DevOps Enablement:
Design cloud landing zones, network segmentation and separate development, staging and production environments on Microsoft Azure or AWS by applying the provider's well-architected framework and zero-trust network principle to establish a secure, compliant and scalable hosting foundation with fully isolated environments that prevent untested changes from reaching production.
Codify all infrastructure by writing reusable Infrastructure as Code modules stored and peer-reviewed in version control to provision any environment in a repeatable, version-controlled and auditable way, eliminating configuration drift and manual setup errors.
Design CI/CD pipelines by automating build, unit, integration and security test stages in Azure DevOps or GitHub Actions to shorten release cycles and deliver frequent, predictable and low-risk production deployments with minimal manual effort.
Prevent defective code from reaching production by configuring automated quality gates on code coverage, static analysis and vulnerability thresholds while blocking merges that fail them to stop defective or insecure code before it is merged, steadily reducing production defects and post-release incidents.
Data Architecture & Database Design:
Design relational and NoSQL data models by applying normalization, indexing and query-tuning techniques across SQL Server, PostgreSQL, MongoDB and Redis to maintain accurate, consistent data and fast response times as data volumes and user numbers grow.
Define multi-tenant data isolation by selecting the right model (separate database, separate schema or row-level security) and setting partitioning and retention policies to ensure strict segregation of each client's data, preventing cross-client exposure while supporting onboarding of new clients at scale.
Architect reporting and analytics data flows by designing ETL/ELT pipelines into a central data warehouse feeding Power BI dashboards to deliver accurate, timely and self-service assessment and business reporting that supports faster, evidence-based decisions by management and clients.
Protect data availability by configuring automated backups, geo-replication and point-in-time restore while testing restores on a scheduled basis to ensure data can be fully restored within the agreed Recovery Point Objective, with proven and documented recovery capability.
Performance & Reliability Engineering:
Set measurable reliability targets by defining service level objectives and indicators (SLOs, SLIs) for availability, latency and error rates in agreement with business owners to give every platform clear, measurable reliability targets that are monitored continuously and reported to management.
Design high-availability and disaster recovery architectures by deploying across multiple availability zones with automated failover and running recovery drills at least twice a year to maintain service continuity during infrastructure failures, meeting the agreed Recovery Time Objective and contractual uptime commitments.
Validate platform capacity by leading load, stress and soak tests with tools such as JMeter or k6 ahead of large assessment campaigns to confirm before each major campaign that platforms can sustain peak concurrent candidate volumes without slowdown or failure.
Monitor platform health in real time by implementing centralized logging, distributed tracing and threshold-based alerting (Azure Monitor, Prometheus, Grafana, ELK stack) to identify and contain incidents before they affect clients and candidates, minimizing service disruption and recovery time.
Technical Leadership & Vendor Oversight:
Raise software quality by conducting structured design and code reviews against agreed standards, design patterns and pull-request checklists to deliver clean, consistent and maintainable code across teams, reducing defect rates and dependency on individual developers.
Develop internal engineering capability by mentoring developers through pair programming, technical workshops and knowledge-sharing sessions on clean code, SOLID principles and secure coding to establish a self-sufficient engineering team with stronger technical skills, consistent best practices and less reliance on external vendors.
Evaluate emerging technologies, frameworks and third-party products by running time-boxed proofs of concept and weighted scoring against technical, security and cost criteria to provide management evidence-based, fit-for-purpose technology recommendations that balance capability, risk and total cost of ownership.
Accept vendor deliverables by reviewing source code, test results and technical documentation against contractual and architectural requirements while tracking defects to closure to accept only deliverables that fully meet contractual, quality and architectural standards, protecting Phoenix from defects and hidden costs.
Education:
- Bachelor's degree in Computer Science, Software Engineering, Computer Engineering or equivalent from a reputable university
- Master's degree is a plus
Experience:
- Minimum 3 years of experience as a Software Architect
- Proven experience designing and delivering cloud-native, multi-tenant web applications
- Hands-on experience with API integration, CI/CD and containerized deployments
Technical Skills:
- Software architecture patterns: microservices, event-driven, domain-driven design, multi-tenant SaaS
- Databases: SQL Server, PostgreSQL, MongoDB, Redis
- Application security: OAuth 2.0, OpenID Conne
- ct, encryption, OWASP, threat modelling
- Architecture modelling: C4 model, UML, Architecture Decision Records