Назад
Company hidden
обновлено 6 дней назад

Application Security Engineer (Purple Team)

Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Ireland
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Application Security Engineer (Purple Team): Enhancing the security of applications, APIs, and infrastructure through preventative controls, security testing, and automation with an accent on threat modelling, SAST/SCA, DAST, and penetration testing. Focus on identifying and remediating vulnerabilities, reviewing application architectures and third-party software, and integrating security controls into development workflows.

Location: Dublin, Ireland

Company

hirify.global provides asset servicing and operational solutions for public and private funds as part of Mitsubishi UFJ Financial Group.

What you will do

  • Promote secure-by-design practices as an application security champion.
  • Identify, analyze, and remediate web application, API, infrastructure, and third-party software vulnerabilities.
  • Manage application security platforms and implement SAST, SCA, and DAST tooling across application repositories.
  • Conduct threat modelling, architecture reviews, penetration testing, and security-focused code reviews.
  • Provide remediation guidance to engineering, IT, development, DevOps, and third-party teams.
  • Coordinate external penetration tests and validate remediation of identified issues.

Requirements

  • Experience in application security with red, blue, or purple team activities.
  • Experience with DAST tools such as Burp Suite or OWASP ZAP and SAST/SCA tools such as Snyk, Veracode, or Checkmarx.
  • Proficiency in Python, JavaScript, .NET, or Java.
  • Strong knowledge of REST and GraphQL API security, SDLC, agile methodologies, and open-source vulnerability analysis.
  • Experience with GitLab or GitHub, Datadog, Jira, Docker, IDEs, and collaboration with development and DevOps teams.
  • Experience creating custom security tooling, scripts, or CI/CD security jobs.

Nice to have

  • Experience in financial services or another heavily audited industry.
  • Experience with AWS services, Infrastructure as Code, Kubernetes, and containers.
  • Knowledge of OpenID Connect, OAuth, and identity providers.

Culture & Benefits

  • Connected and collaborative working environment.
  • Focus on innovation, client service, and learning and development.
  • Permanent full-time employment within a global financial group.

Hiring process

  • Only candidates progressing to the interview stage will be contacted.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →