DevSecOps Engineer (Fintech)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
DevSecOps Engineer (Fintech): Enhancing the security of applications, APIs, and infrastructure through preventative controls and automated security testing with an accent on purple team collaboration and SDLC integration. Focus on implementing SAST/SCA/DAST tooling, conducting threat modeling, and fostering a secure-by-design culture within engineering teams.
Location: Must be based in Limassol, Cyprus (Hybrid)
Company
A global leader in asset servicing and operational solutions for alternative investments, operating as a division of the Mitsubishi UFJ Financial Group.
What you will do
- Act as a security champion to foster a secure-by-design approach across the business.
- Identify and analyze web application security vulnerabilities to reduce risk.
- Implement and manage SAST/SCA tooling to identify source code risks.
- Scale automated DAST solutions to maximize testing coverage and runtime visibility.
- Conduct threat modeling and review application architectures to identify risks early in the SDLC.
- Coordinate external penetration testing and validate remediation efforts.
Requirements
- Must be based in or able to work from Limassol, Cyprus.
- Experience in application security focusing on red, blue, or purple team activities.
- Proficiency in one or more languages: Python, JavaScript, .NET, or Java.
- Strong understanding of REST and GraphQL API security testing.
- Experience with DAST (Burp Suite, OWASP Zap) and SAST/SCA (Snyk, Veracode, Checkmarx) tools.
- Solid knowledge of SDLC and agile methodologies.
Nice to have
- Experience in the financial sector or heavily audited industries.
- Knowledge of cloud services, particularly AWS (WAF, Cognito).
- Experience with Infrastructure as Code, Kubernetes, and container security.
- Familiarity with auth mechanisms like Open ID Connect and OAuth.
Culture & Benefits
- Commitment to hybrid working models.
- Focus on innovation and client-centric solutions.
- Strong emphasis on professional learning and development.
- Opportunity to work within a large, stable global financial institution.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →