Banking & Fintech Software Engineering, Built for Regulated Environments

If you're building for a bank, a payments company, or a regulated fintech, you already know the frontend can't just look good — it has to survive a security review, a compliance audit, and a QA team with actual teeth. As part of Eurisko Mobility's engagement with Riyad Bank / JEEL in Saudi Arabia, I worked on three production banking applications end to end: requirements, architecture, implementation, and the CI/CD and documentation that let a regulated organization actually ship. That same rigor now extends to agentic AI platforms — LLM-driven tools built for regulated, executive-facing environments where the output has to be trustworthy, not just impressive. This page covers that work, the stack behind it, and how I work with teams that can't afford a shortcut.

What I've shipped for Riyad Bank / JEEL

Riyad Bank / JEEL — Kids E-Banking

A banking app built for minors, with biometric-grade auth

  • Owned authentication and biometrics for a React Native app aimed at a young, first-time-banking audience, where trust and security UX had to hold up without ever confusing the user.
  • Reworked the loading experience — lazy loading, optimistic UI, clearer loading states — to improve median time-to-interactive.
  • Cut mobile API calls by roughly 50% using client-side caching and request de-duplication, a direct latency and cost win on a mobile banking app.

~50%

fewer mobile API calls

Riyad Bank / JEEL — Online Mortgage

Multi-step, regulated financial flows — planned and documented, not improvised

  • Led requirements planning for the online mortgage product, a multi-step flow with the kind of financial calculations and compliance constraints that don't tolerate ambiguity.
  • Set the code review standards the rest of the team worked against.
  • Documented features and infrastructure thoroughly enough that new team members could onboard against them, then ran that onboarding.

Riyad Bank / JEEL — API Management Platform

The frontend layer for a bank's internal API platform

  • Defined the frontend architecture and implementation approach for a platform used internally to manage the bank's API layer — the tooling that sits behind everything else the bank ships.
  • Enforced testing and CI quality gates specifically so multiple teams could deliver against the platform in parallel without breaking each other.

Riyad Bank / JEEL — Internal Frontend & IAM Platform

Reusable IAM so new banking apps stop reinventing auth

  • Abstracted identity and access management/authentication logic into a reusable internal package, cutting new application setup time from roughly a sprint down to a few days.
  • Built and maintained a shared UI component library used to unify design patterns and reduce duplicated UI work across the bank's applications.
  • Defined and maintained logging, tracking, and crash-reporting standards using Dynatrace, Splunk, and Firebase — the observability layer a regulated org needs before anything ships.

1 sprint → days

new app setup time

Stack

Frontend

ReactReact NativeTypeScript

Backend & integration

Java (Spring Boot)Node.js (NestJS)REST APIs

Cloud

AWS Cloud Practitioner (2024)AWS Solutions Architect (2024)

Observability & quality

DynatraceSplunkFirebaseJestReact Testing LibrarySonarQubeGitLab CIJenkins

How I work with regulated clients

  1. 01

    Requirements & compliance framing first

    Multi-step regulated flows get scoped and documented before implementation starts, not discovered mid-build.

  2. 02

    Review standards, not vibes

    I set — and hold teams to — code review and testing gates, because regulated delivery depends on gates that don't get skipped under deadline pressure.

  3. 03

    Documentation that survives you

    Features and infrastructure get documented well enough that someone else can onboard against them, because banking teams have turnover and audits, and neither one waits for tribal knowledge.

  4. 04

    Observability from day one

    Logging, tracking, and crash-reporting standards (Dynatrace, Splunk, Firebase) get defined early, not bolted on after an incident.

Frequently Asked Questions

Have you worked under a bank's security or compliance review process?+

Yes — the Riyad Bank / JEEL engagements (mortgage platform, API management platform, kids' e-banking app, and the internal IAM platform) all shipped inside a regulated banking environment, including the review and documentation standards that come with it.

Can you work with an existing design system or a bank's internal component library?+

Yes, and I've built one — the shared UI component library I built and maintained at Riyad Bank / JEEL exists specifically to unify design patterns and cut duplicated UI work across the bank's applications. I'm just as comfortable working inside someone else's system.

Do you sign NDAs or work under a contractor vetting process?+

Yes. Banking and consulting engagements come with vetting and confidentiality requirements as standard, and I've operated under them for several years without issue.

What's your role on a banking engineering team — frontend only, or more?+

Primarily frontend architecture and implementation in React and React Native, but I've been involved end to end — requirements planning, CI/CD, documentation, and onboarding — not just shipping components.

Do you work on-site in KSA, or remotely?+

Both, depending on the engagement. The Riyad Bank work was delivered as part of a Lebanon/KSA engagement model; I'm set up to work remotely or travel for the right project.

Have a banking or fintech product that needs to ship right the first time?

Tell me the scope — I'll tell you honestly if I'm the right fit.