Education Qualification : Bachelors degree in computer science or related field or higher with minimum 5 years of relevant experience.
Your future duties and responsibilities:
Integration of security into software development during design and development
Analysis of IT systems architecture in terms of security and risk/threat modelling
Contribution to the definition of the different types of security tests to be performed
Supporting the development team in terms of secure development practices
Supporting the infrastructure/middleware teams in terms of securization
Performing or coordinating security code reviews and white box penetration testing during the development sprints
Automation of security testing process
Coordinating with the third party vendors and internal stakeholders for the penetration and black box testing
Review and assess the results of external penetration testing, and agree corrective action
Supporting the development teams to reproduce issues
Research and monitor current software security risk
Contributing Responsibilities
Work with development team to prioritize vulnerabilities, assist in resolving security related issues.
Technical & Behavioral Competencies
Functional knowledge Minimum Proficiency Level
General knowledge about private banking, asset management or corporate banking Medium (at least 5 years experience)
Experience of a secure software life cycle in a software house or large IT department Medium (at least 5 years experience)
Other skills Minimum Proficiency Level
Communication skills Excellent
Team player Excellent
Analytical skills Excellent
Required qualifications to be successful in this role:
Must to have Skills-
At least 5+ years of hands-on experience doing security code analysis or reviews
At least 5+ years of hands-on experience doing penetration and vulnerabilities tests
At least 5+ years of hands-on experience as a software developer
Any certification around security: GSSP-JAVA, GWEB, ECSP, CSSLP, CEH, CES etc.
Skills Referential (Required knowledge, skills and abilities)
Technical Skills
Technical skills Minimum Proficiency Level
Security Technical Skills Medium (At least 5-8 year experience)
Knowledge and experience of common security protocols (eg. TLS, OAuth 2.0, SAML, Open ID, Connect, LDAP, etc.) and crypto libraries )Open SSL, JWT, etc) Must Have
Knowledge and experience of server side security, authentication and authorizations mechanisms Must Have
Knowledge and experience of Web security (OWASP etc.) and Javascript/SPA security Must Have
Knowledge and experience of static code security analysis and security code reviews Must Have
Knowledge and experience of vulnerabilities/penetration testing Must Have
Good to have Skills-
Knowledge of Spring Security Good to have
Knowledge of encryption and key management Good to have
Awareness of security standards relevant to SaaS and experience with Cloud platforms Good to have
Technical Development Skills Medium (At least 15-year experience)
Experience of CI/CD and DevSecOps Valuable to have
Experience with hardening of middleware (Tomcat, Apache, NGINX, Mongo DB etc.) Good to have